Follow Orion Security Solutions on Facebook Follow OrionSSolutions on Twitter Orion Security Solutions on LinkedIn Orion Security Solutions on YouTube
Tuesday, 03 January 2012 19:31

Social Engineering Part 2

Rate this item
(9 votes)

Social engineering professionals deploy many methods in their attempts to manipulate the people they target. Email scams, telephone contacts, posing as a trusted vendor or service provider, direct contact, and social integration are a few of the methods that are commonly used. Social engineering methods continuously evolve with communications technology advancements. Criminals will seek to take advantage of any method that allows them to communicate with as many people as possible. Finding susceptible targets requires contact methods that can reach the masses since the percentage of people that will fall for the tricks is relatively low. As people become educated about certain social engineering methods, the public is able to detect and prevent these attacks, but criminals unfortunately adapt.

Email scams are one of the most popular social engineering methods due to the amount of people that can be contacted with the click of a button. Email scams were very effective when they first emerged since many people were new to using email and were caught off guard. Social engineering criminals quickly devised schemes that seemed legitimate with the goal of extracting personal data including social security numbers, account numbers, birthdates, and passwords. Awareness of these scams flooded the public media and reduced the success rate of these attacks. However, email scam methods are still widely used by social engineering criminals and they are getting more sophisticated.

Social integration methods require more expertise to pull off, but are much more difficult to detect. When social engineers are able to gain the trust of their targets and use this confidence against them, they are more likely to gain access to sensitive and protected information. Elaborate social integration methods are deployed by trained professionals such as those involved in espionage. These methods are not likely used by common criminals, but yield significant results when successfully deployed.

Happy New Year to all! We will continue to explore social engineering in subsequent weeks here at The O including targets and the “theft from a distance” philosophy

 

Sean Crain

Sean Crain

Orion Security Solutions (OSS)
President/CEO

Add comment


Security code
Refresh