CYS405 · Chapter 9

Hacking the Human OS:
Social Engineering

No firewall stops a friendly voice on the phone. This is the art of manipulating people — not computers — into handing over the keys.

Human-Based Attacks Phishing & SMiShing Insider Threats Impersonation Countermeasures Pen Testing
scroll ↓
01 / What Is It

What Is Social Engineering?

Social engineering is the art of manipulating people into divulging sensitive information or performing an action that helps an attacker — without ever touching a firewall or exploiting a piece of software. It targets the weakness of people, not systems.

Before the attack: information gathering

Attackers first research the target organization using open sources:

  • Official company websites — employee IDs, names, and email addresses are often published
  • Job ads / print media that reveal the tech stack ("Oracle DBA needed", "UNIX admin wanted")
  • Blogs and forums where employees casually share personal or organizational details

Only after this recon does the attacker execute the attack — via impersonation, piggybacking, tailgating, reverse social engineering, and more.

💡

Key insight

Most victims never even realize a security lapse occurred — they unwittingly answer a stranger's question or reply to a spam email, thinking nothing of it.

02 / Targets

Common Targets Inside an Organization

Social engineers exploit the fact that people naturally trust others and enjoy helping the needy. These roles are hit most often:

Receptionists / Help-Desk
Tricked into sharing a phone number or password after the attacker wins their trust — they think they're "helping a customer."
Technical Support
Attacker poses as senior management, a customer, or a vendor to pull sensitive info out of support staff.
System Administrators
Hold the crown jewels: OS versions, admin passwords — gold for planning further attacks.
Users & Clients
Approached by an attacker posing as "tech support" to extract sensitive personal or account data.
Vendors
Third-party suppliers targeted to gain a foothold that helps execute other attacks.
🧠

Mnemonic — Who Gets Played?

"R.T.S.U.V"Receptionists, Tech support, Sysadmins, Users/clients, Vendors. Picture a "RuSTy VaUlt" — every letter is a door into the organization the attacker tries to talk their way through.

03 / Impact

Impact on the Organization

Social engineering can look "soft" compared to a technical exploit, but the fallout is very real:

Economic Loss

Competitors steal development plans / marketing strategy via social engineering, directly costing revenue.

Damage to Goodwill

Leaked sensitive data erodes the trust customers place in the brand.

Loss of Privacy

Stakeholders lose faith and may cut ties with the organization entirely.

Terrorism Risk

Terrorists can use social engineering to build "blueprints" for infiltrating physical targets.

Lawsuits & Arbitration

Legal fallout brings negative publicity and hurts business performance.

Temporary/Permanent Closure

In the worst case, accumulated damage forces the business to shut down.

04 / Human Weaknesses

Behaviors Vulnerable to Attack

Every social engineering attack leans on one (or more) of these built-in human tendencies:

Human Trait How It's Exploited
Trusting nature People naturally believe others, making deception easy.
Lack of awareness Employees who don't understand social engineering can't spot it.
Fear / pressure "You'll lose your job" style threats force rushed, thoughtless decisions.
Greed / temptation Promise of free money or rewards ("something for nothing") lowers guard.
Willingness to help Moral duty to assist someone "in need" overrides caution.
🧠

Mnemonic — T.L.F.G.W

"Trusty Little Foxes Grab Wallets" = Trusting nature, Lack of awareness, Fear/pressure, Greed, Willingness to help. Five foxy human traits every social engineer preys on.

05 / Company-Level Weaknesses

Factors That Make Companies Vulnerable

Insufficient Security Training

Employees never learn to recognize social engineering tricks, so they fall for them.

Unregulated Access to Information

Giving everyone access to sensitive databases multiplies the attack surface.

Several Organizational Units

Geographically scattered units are harder to manage and easier to infiltrate.

Lack of Security Policies

No password-change policy, no info-sharing rules, no unique user IDs = an open door.

Why Is Social Engineering So Effective?

⚠️

Exam-favorite line

"No specific hardware or software can safeguard against social engineering." Technical controls stop technical attacks — only training and awareness stop social engineering.

06 / Attack Lifecycle

Phases of a Social Engineering Attack

Every successful attack follows this four-phase playbook:

1

Research the Target Company

Gather nature of business, location, employee count. Involves dumpster diving, browsing the website, and hunting for employee details.

2

Select a Target

Disgruntled employees are prime targets — they're easier to manipulate and extract information from.

3

Develop the Relationship

The attacker builds rapport/trust with the chosen employee.

4

Exploit the Relationship

Extract sensitive info about accounts, finances, technologies in use, and upcoming plans.

🧠

Mnemonic — R.S.D.E

"Real Spies Date Enemies" = Research → Select target → Develop relationship → Exploit relationship. A social engineer basically "dates" your employee to steal secrets.

07 / Attack Categories

The Three Categories of Social Engineering

All social engineering attacks fall into one of three buckets: human-based, computer-based, and mobile-based.

🧠

Mnemonic — H.C.M

"Humans Click Mobiles" = Human-based, Computer-based, Mobile-based — the three delivery channels for social engineering.

A. Human-Based Social Engineering

Involves direct human interaction — the attacker impersonates a legitimate person (e.g. an "IT support technician") to talk their way past employees.

Impersonation
Attacker pretends to be someone else (IT staff, executive, vendor) to gain trust and access.
Vishing
Voice/VoIP phishing — impersonation carried out over a phone call.
Eavesdropping
Secretly listening to private conversations to pick up confidential info.
Shoulder Surfing
Watching over someone's shoulder as they type a password or PIN.
Dumpster Diving
Digging through trash for discarded documents with sensitive data.
Reverse Social Engineering
Attacker manipulates the situation so the victim comes to them for help — then extracts info while "assisting."
Piggybacking
An unauthorized person enters a restricted area WITH the knowledge/consent of an authorized person (e.g., "can you let me in, I forgot my badge?").
Tailgating
An unauthorized person slips through a secure door right behind an authorized employee — WITHOUT their knowledge.
Piggybacking

Employee knowingly lets the attacker in — thinks they're being nice ("hold the door!").

Tailgating

Employee has no idea someone slipped in behind them through the secure door.

B. Computer-Based Social Engineering

Relies on computers and the internet to carry out the attack rather than face-to-face or voice interaction.

Phishing

Fake emails/websites mimicking a trusted source to steal credentials or install malware.

Spam Mail

Unsolicited bulk email, often carrying malicious links or attachments.

Instant Chat Messenger

Attacker builds rapport via chat apps to lure victims into revealing personal info.

Pop-Up Window Attacks

Fake "your session expired, log in again" pop-ups that harvest credentials.

C. Mobile-Based Social Engineering

Attackers exploit mobile apps and messaging to trick users on smartphones.

Publishing Malicious Apps

Fake apps with attractive features submitted to app stores under recognizable names.

Repackaging Legitimate Apps

A real app is cloned, injected with malware, and redistributed.

Fake Security Apps

Apps pretending to be antivirus/security tools that are actually malware.

SMiShing

SMS Phishing — malicious links sent via text message.

📘 Example — full attack chain

An attacker calls the help desk claiming to be "IT Support" (vishing, human-based), then follows up with an email containing a "password reset" link (phishing, computer-based), and finally texts the victim a link to a "security update" app (SMiShing, mobile-based). Three categories, one target.

08 / Insider Threats

Insider Threat / Insider Attack

An insider is any trusted employee with access to critical assets. An insider attack means using that privileged access to violate rules or intentionally harm the organization. About 60% of attacks occur from behind the firewall — insiders are hard to detect and their attacks are hard to prevent.

Privileged Users
Managers/sysadmins with confidential data access — may misuse it intentionally or by accident.
Disgruntled Employees
Unhappy staff or contractors who acquire info and wait for the right time to strike back.
Terminated Employees
Keep accessing data after leaving via backdoors, malware, or credentials that were never disabled.
Accident-Prone Employees
Lost devices, misdirected emails, unlocked sessions — unintentional data disclosure.
Third Parties
Remote employees, partners, dealers, vendors — their security posture is unpredictable.
Undertrained Staff
A trusted employee who becomes an unintentional insider due to lack of security training.

Industries hit hardest: credit-card companies, health-care providers, network service providers, and financial/exchange services.

Reasons for Insider Attacks

Motive Description
Financial Gain Sells sensitive data, steals colleague's financial details, or manipulates financial records.
Steal Confidential Data A competitor plants a hire who gets the job just to steal information.
Revenge One disgruntled employee is enough to compromise the whole company.
Become a Future Competitor Employee plans to start a rival business using stolen client lists.
Perform Competitor's Bidding Corporate espionage — bribery or blackmail forces even honest employees to leak data.
Public Announcement Leaking data to make a political or social statement.
🧠

Mnemonic — F.S.R.B.P.P

"Fat Squirrels Really Bury Precious Peanuts" = Financial gain, Steal confidential data, Revenge, Become future competitor, Perform competitor's bidding, Public announcement — the six reasons insiders turn against their own company.

09 / Defense

Countermeasures & Phishing Detection

Since social engineering targets people, defenses must combine awareness training, policy, and a bit of tooling.

Organizational Countermeasures

  • Ongoing security-awareness training for all staff
  • Strict access control / least-privilege policies
  • Strong password & information-sharing policies
  • Classify and label sensitive information
  • Background checks and monitoring of privileged users

Insider Threat Countermeasures

  • Enforce separation of duties and least privilege
  • Immediately disable access on termination
  • Monitor privileged account activity/logs
  • Regular security audits

How to Detect Phishing Emails

🛠️ Anti-Phishing Toolbar — Netcraft

Source: toolbar.netcraft.com

  • Protects savings from phishing attacks
  • Shows hosting location and risk rating of every visited site
  • Helps defend the internet community from fraudsters
  • Checks whether a site supports Perfect Forward Secrecy (PFS)
  • Flags sites affected by the aftermath of Heartbleed
🛠️ PhishTank

Source: phishtank.com — a collaborative clearinghouse of phishing data with an open API for developers/researchers.

10 / Testing

Social Engineering Penetration Testing

Ethical hackers simulate real social engineering attacks (with authorization) to test how employees respond, using the same techniques as attackers.

📞 Using the Phone

Pretexting calls to help desk / support staff to see if sensitive info can be extracted (vishing simulation).

🚶 In Person

Physical tests: tailgating into a building, impersonating a technician, or dumpster diving on-site.

🔎

Know What the Web Knows About You

People-search / OSINT platforms like Spokeo, Facebook, Intellius, Zabasearch, and People Search reveal how much personal data an attacker could gather about you before even starting an attack.

11 / Exam Prep

Exam Tips & Tricks

🎯

3 categories, memorize order

Human-based → Computer-based → Mobile-based. Exam loves asking you to classify a scenario into one of these three.

🎯

Piggybacking vs Tailgating

Piggybacking = victim KNOWS and consents. Tailgating = victim has NO IDEA. This exact distinction is a classic trick question.

🎯

60% rule

Remember: ~60% of attacks originate from BEHIND the firewall — i.e., insiders, not external hackers.

🎯

No tech fix exists

"No hardware or software can fully prevent social engineering" — a favorite true/false exam statement.

🎯

Vishing = voice phishing

Don't confuse Vishing (voice/VoIP) with SMiShing (SMS) — both are phishing variants but on different channels.

🎯

4 phases

Research → Select Target → Develop Relationship → Exploit Relationship. Attackers target disgruntled employees specifically because they're easier to turn.

12 / Cheat Sheet

Quick Reference — Everything at a Glance

Topic Key Point
Social Engineering Manipulating people (not systems) into divulging info or performing an action
Info gathering sources Company websites, job ads, blogs/forums
Common targets Receptionists, tech support, sysadmins, users/clients, vendors
Impact Economic loss, goodwill damage, privacy loss, terrorism risk, lawsuits, closure
Human vulnerabilities Trusting nature, lack of awareness, fear/pressure, greed, willingness to help
Company vulnerabilities Poor training, unregulated data access, scattered units, lack of policy
Why effective No hardware/software fix; hard to detect; humans are variable; cheap to run
Attack phases Research → Select Target → Develop Relationship → Exploit Relationship
3 attack categories Human-based, Computer-based, Mobile-based
Impersonation Pretending to be someone trusted (IT, exec, vendor)
Vishing Voice/VoIP phishing over the phone
Eavesdropping Secretly listening to private conversations
Shoulder surfing Watching someone type a password/PIN
Dumpster diving Searching trash for discarded sensitive documents
Reverse social engineering Attacker sets up a scenario so the victim comes to them for "help"
Piggybacking Unauthorized entry WITH the knowledge of an authorized person
Tailgating Unauthorized entry WITHOUT the knowledge of an authorized person
Phishing Fake emails/sites mimicking a trusted source (computer-based)
Pop-up attacks Fake "session expired" pop-ups harvesting credentials
SMiShing SMS-based phishing (mobile-based)
Malicious/repackaged apps Fake or cloned apps distributed via app stores (mobile-based)
Insider attack Trusted person misuses privileged access; ~60% of attacks are insider-driven
Insider types Privileged users, disgruntled/terminated employees, accident-prone staff, third parties, undertrained staff
Insider motives Financial gain, stealing data, revenge, future competition, corporate espionage, public statement
Netcraft toolbar Anti-phishing browser toolbar; checks PFS support and Heartbleed exposure
PhishTank Collaborative phishing data clearinghouse with an open API
SE pen testing Authorized simulated attacks via phone (vishing) or in person (tailgating, dumpster diving)
OSINT people-search tools Spokeo, Facebook, Intellius, Zabasearch, People Search