As cyber defenses rapidly improve across industries, hacking into systems is becoming much more difficult for criminals. Firewalls, intrusion prevention tools, and stringent access controls have hardened infrastructure and made traditional intrusions unlikely to succeed.
So what’s the weakest link that threat actors can exploit to continue their nefarious schemes? Humans.
While technology gaps are rapidly diminishing, human psychology remains just as vulnerable as ever to manipulation, urgency cues, reciprocity tendencies, and deception. As a result, criminals are doubling down on social engineering tactics that take advantage of our psychological predispositions to bypass technological protections.
In this blog, we will highlight five ingenious social engineering tricks that threat actors are leveraging more each day as traditional intrusions get stonewalled by cyber defenses. Understand how these schemes work so you can identify and stop them in their tracks.
1. Fake Hacking
Fake hacking is a clever scheme that works by tricking users into believing their devices have already been compromised by a cyber attack. The goal is to create a false sense of urgency that pressures victims into carelessly divulging sensitive information or installing malware.
For example, imagine receiving an email claiming to be from your company’s IT department. The message states that security protocols have detected unauthorized access to your work laptop. It claims malicious actors have already breached defenses and begun stealing corporate data.
Alarmed, you read on to learn that quick action is required to halt the attack, secure the stolen assets, and prevent wider damage across the network. Conveniently, the “IT team” has included a link to guide you through assessing the system intrusion.
In reality, there was no hack. By pushing urgency and preying on fears of breaches, this fake warning tricks users into clicking links or opening attachments without thinking critically. The content then deploys malware, captures credentials for data theft, or surveys the computer for further vulnerabilities to exploit.
How to Stop It
- Verify messages claiming security breaches with your IT team before taking any action. Real IT warnings should come through proper company channels.
- Look for poor grammar, spelling mistakes, or urgency cues which signal phishing attempts.
- Never click links or attachments in unsolicited emails, even if they appear to come from someone in your organization.
2. Rogue Support Scams
Rogue support scams start by tricking users into believing there is a technical problem with their computer. Cybergangs may compromise a website to display alarming security warnings when visitors load the page. Pop-up dialog boxes full of tech jargon sternly instruct users to call a support number for assistance removing viruses or other issues.
When concerned users dial the number, they are connected to a “support representative” who is actually a skilled social engineer posing as a security expert. The scammer confirms the computer is plagued by security threats, then offers expensive anti-virus tools or technical support plans to fix the phantom issues.
In reality, there is no infection at all. The goal is to scam frightened users into spending money on useless services. This predatory tactic specifically targets less tech-savvy people.
How to Stop It
- Close unexpected security warning pop ups instead of calling the number. Real alerts from trusted anti-virus tools look much different.
- Run a full scan using your existing security suite to check for actual infections, without installing new software.
- Use bookmarks instead of typing site addresses manually. Fake virus warnings often appear on compromised sites with altered URLs.
3. SMSishing
SMSishing uses text messaging to distribute social engineering scams on mobile devices. The name blends “SMS” (short message service) and “phishing.” These text messages contain links claiming to offer health advice, shipping notifications with tracking links, bank fraud alerts that redirect to fake sites, and much more.
The tricky part is that SMSishing texts come from valid phone numbers, not randomized strings. Attackers use spoofing technology to disguise their true number. Messages may even appear to come from banks, government agencies, or delivery companies you trust.
When unsuspecting users click the embedded links, they are prompted to enter credentials, download malware, or sign up for subscriptions under false pretenses.
How to Stop It
- Avoid clicking links in text messages, even if the source seems legitimate. Instead, open the official app or log into the real website.
- Hover over links to preview the true URL before you open. Often there are misspellings or odd domain extensions.
- Be skeptical of unexpected messages with alarming claims demanding quick action.
4. Quid Pro Quo Attacks
Quid pro quo means “something for something” in Latin. In social engineering, it refers to attacks offering a small gift or favor in exchange for data or access.
For example, an attacker may pose as an IT consultant offering corporate executives a free analysis of their cyber defenses. The report will identify high risk flaws, completely free…as long as the target grants temporary access to parts of the system.
Once inside, the attacker steals data or installs backdoors rather than providing any review. Or they may extend the engagement indefinitely using contrived threats.
Similarly, quiz pro quo schemes may involve:
- Free software or systems claiming to enhance security or performance
- Phone sanitization offering to erase viruses from mobile devices
- Fake anti-hacking services asking for access to plant malware instead
This technique exploits human reciprocity tendencies. We feel obligated to return gifts and favors. By offering free help, attackers lower defenses so targets voluntarily give access that would otherwise be denied.
How to Stop It
- Be wary of unsolicited offers that seem too good to be true. There is almost always an ulterior motive.
- Vet people and companies before accepting free products or services, no matter how appealing.
- Never grant an outsider access to systems or data without proper authorization, even for a seemingly small analysis.
5. Tailgating
Tailgating refers to physically piggybacking on authorized people to access restricted areas like office buildings or data centers.
For example, a social engineer may carry a stolen keycard and a bundle of fake documents. When an actual employee unlocks the door and enters, the attacker follows closely while flashing their props to blend in.
Done well, tailgaters perfectly mimic workplace rituals like badging in or opening secure doors with stolen keys. Security cameras capture their faces but they move too quickly to read badges. By mirroring others, they bypass physical access controls.
Once inside, tailgaters rifle through offices and databases for valuable assets using USB drives or cloud uploads. Their entry method makes them look like workers if questioned.
How to Stop It
- Politely verify credentials of anyone entering without using their own keycard, even if they look familiar.
- Report suspicious people mirroring access rituals instead of properly badging in themselves.
- Encourage security teams to monitor turnstiles and secured entry points.
In Summary
As human nature remains vulnerable to manipulation, expect schemes like these to increase in sophistication. Maintain a healthy skepticism when encountering unsolicited contacts, appealing offers, or anyone asking for sensitive data. And educate employees on common warning signs. Combining awareness with cybersecurity measures will keep you steps ahead of the latest threats.