Social Engineering Basics
"There is no patch for human stupidity" - covers why social engineering works, its main forms, and the awareness habits that catch it in the moment.
Key Takeaways
- Social engineering is "the art of manipulating people so they share confidential information" - as Kevin Mitnick put it, "social engineering bypasses all technologies, including firewalls."
- Types covered: phishing, spamming, shoulder surfing, dumpster diving, pretexting, baiting, tailgating, quid pro quo, and social media reconnaissance.
- Why it still works: attackers prey on human weaknesses - fear, trust, greed, sympathy, ego, ignorance, laziness, and haste - not technical vulnerabilities.
- Real incidents cited in the talk: NotPetya/WannaCry/Locky ransomware (2017), IRS scam phone calls, a Vodafone help-desk scam, and a $100M+ loss at a US company from a single malicious email attachment (2016), plus a claim that 60% of enterprises reported being victims of social engineering in 2016. These stats are as presented in the original deck - treat them as illustrative of the scale of the problem rather than independently verified figures, since the deck doesn't cite its primary sources.
- Awareness checklist - be suspicious when someone is: asking/forcing unusual requirements, threatening negative consequences, offering something for nothing, creating false urgency or sympathy, being unusually friendly without cause, or tailgating you without notice.
Go Deeper
- OSINT & Social Engineering Study Plan for a structured, hands-on path through this topic
- Common Security Interview Questions covers phishing prevention as an interview topic
- Common Security Concepts