Social engineering attacks are not as rare as you think. In fact, you might already be a victim “ you just don’t know it yet. Social engineering works because people are almost always the weakest link in information security. We sometimes do not think about the things we do, or are in a hurry to double check the links we click on. Other times, we become too confident. Then there are those times when we find ourselves too submissive to authority.
The most common types of social engineering attacks
Social engineering entails tricking people into giving their confidential information or manipulating them to do something. Social engineering is best understood by knowing the various forms it takes. What are the types of social engineering attacks?
Phishing
Have you ever gotten an e-mail from your bank asking you to log into their website and do something? Some people don’t even think twice and just click on the link included in the e-mail, enter their login credentials, and unwittingly fall victim to a phishing attack. In this scenario, the attackers have successfully obtained your login details, and they can now get into your online banking accounts.
Phishing is a widely known way to get information from an unsuspecting victim. However, there are still a lot of people who fall prey to this attack. The reason for that is because phishing e-mails are carefully crafted to look like the real thing, and the link takes you to a fake website that’s an exact replica of your bank’s official site “ or so close to it that victims don’t notice.
Another form of this attack is called spear phishing, which targets a particular person. For instance, attackers send an e-mail to a company‘s HR personnel, making it look like it’s coming from one of the executives. The “executive” would ask for employee details, such as W-2 data that includes social security numbers, addresses, names, and other personal information. Another known tactic is to spoof the boss’s e-mail address telling an employee to send this document or that file via e-mail. Most employees will not think twice about giving their superiors the organization‘s trade secrets, and sometimes they don’t even ask them why they need it.
Others
Not all social engineering attacks involve interaction via e-mail or phone. One alternative method is by typosquatting wherein the attacker registers a website address that is close to a brand’s name. For instance, registering Oogle.com and then creating a website at that address that closely resembles Google’s site. In the past, PayPaI.com (with the capital letter i ) was made to look like the real PayPal.com.
Other social engineering tactics involve the use of malicious updates and plugins, impersonation of customer support accounts on social media, or baiting users to download movies and videos using infected software. There are also those who bait you using other tactics, such as leaving an infected USB stick. Once you insert that stick into your computer, the malware will be able to infiltrate your network.
The figures you should know
Knowing the different kinds of attacks is one step. Knowing how often social engineering attacks occur and the potential impacts will help you gain a sense of urgency to do something about it. These attacks are far more prevalent than most people realize.
Prevalence
Common sense is not that common. This statement is particularly true when it comes to social engineering. In fact, you might be shocked by the number of people who have been victimized by social engineering attacks.
Social engineering has a high payoff for cybercriminals. CyberEdge reports that the number of successful attacks in 2017 was at 79 percent. That number follows an upward trend. In 2014, only 62 percent of social engineering attacks were successful. It rose to 71 percent in 2015 and then 76 percent a year later.
But how often do these hackers try to use social engineering? According to Wombat Security’s 2019 State of the Phish, around 83 percent of all companies report that they experienced phishing attacks in the previous year.
The same report also revealed that 49 percent experienced SMS and voice phishing, while four percent related that they had experienced social engineering attacks by way of infected thumb drives. More than six out of 10 (or 64 percent) of information security professionals also reported being spear phished in 2017.
According to a 2018 study, 17 percent of people fall victim to social engineering attacks. That means that close to two out of every ten employees you have will unwittingly compromise his or her workstation, or get the entire company’s network in trouble.
You might think that most people know about phishing and that they will be able to detect it when they see it. However, the same study shows that out of all the social engineering strategies employed, phishing was the most successful. Close to three out of 10 recipients, or 27 percent, clicked on a link that took them to a bogus website.
What’s more, employees were found to open unknown files and visit suspicious links. They even talk or chat to the attackers. If you think that this is because they are not techies or they do not know what social engineering is, think again. The study found that three percent of security professionals were guilty of not being cautious enough to check out the link or make sure files attached to emails are safe to download.
Another interesting set of statistics comes from Accenture. They say that in 2016 and 2017, 69 percent of companies experienced social engineering attacks. Furthermore, between targeted and mass attacks, cybercriminals are finding more success with targeted attacks.
Impact
How long does it take for organizations to detect a data breach that is due to email phishing? We’ll give you five seconds to guess. 5. 4. 3. 2. 1 ¦
The answer is 146 days!
Yes, it takes close to an average of five months before organizations become wise to phishing attacks. In that amount of time, attackers would have been able to get everything in your network, or in the victim’s computers. In fact, social engineering has overtaken malware as the preferred attack method in a data breach. Only three percent of attacks involve malware, while 97 percent use social engineering.
What are the dangers? According to Optimal Networks, phishing is the top method utilized by hackers who want to use ransomware. Around 4,000 ransomware attacks occurred daily in 2016, and that number has been increasing over the years.
Cost
The impact of social engineering attacks can be quantified. According to the Federal Bureau of Investigation, companies have paid $1.6 billion because of this type of hacking from 2013 to 2017. Accenture, on the other hand, released the 2017 Cost of Cyber Crime Study that revealed that there are 130 security breaches every year and companies pay an annualized average cost of $11.7 million for cybersecurity.
Juniper Research has predicted that rapid digitization of consumers’ records will increase the cost of global data breaches and cybercrime incidents to $2.1 trillion by 2019, up almost four times the estimated cost in 2015.
How to avoid being victimized by social engineering attacks
Digital Guardian interviewed close to three dozen infosec experts in this post and found that the best way to fight social engineering attacks is by a multifaceted approach. It includes:
- Training users to recognize social engineering attacks, allowing them to know when they are being hoodwinked. It also helps to make security a top of mind concern among your employees. Humans are the weakest link in your organization, so make sure that they are under credible training. It should be a recurring training to update them of the latest threats and new forms of social engineering.
- Put your employees to the test by having a penetration testing company do a social engineering test.
- Backup systems just in case you fall victim to ransomware and other malicious attacks.
- Set up new defense software that can help filter e-mails. Do not open e-mails that end up in the spam folder and come from somebody you do not know.
- Social engineering attacks can change very quickly, it is a good idea to be on top of the new scams that are going around and inform everyone in your organization about them.
- Educate employees on how to detect social engineering e-mails. For instance, how to hover over links to show the address of the site it takes you to. Sometimes, the appearance or message is a dead giveaway. Well-crafted emails that have a professional design, or those threatening ones coming from the IRS or FBI, often turn out to be scams.
- Monitor your personal accounts to make sure that there is no suspicious activity. Check your outbox to see if there are e-mails there that you did not send. One employee found out he has been compromised when he checked on his Facebook activity history.
- The old safeguards should be in place. Have the latest anti-virus, firewall, and other software installed.
However, the key takeaway from Digital Guardian is that every effective campaign or program against social engineering starts with education. You need to educate your employees about the latest threats and how to detect them, as well as the safe behaviors that they should exhibit online.
You should be able to communicate why social engineering is a real threat and how it impacts the organization. From there, you can formulate a policy that would help guide employees about the things they can do to avoid falling victim to social engineering, and what they should act if they do get hoodwinked.