Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Social engineering poll reveals which scam works better

Sweet talking victims is the best approach for criminal success

Article comments

Which tactic works best for a scamming social engineer? Acting like an authority figure and requiring a victim to answer questions and give up sensitive information? Or acting like a nice, trustworthy person who strikes up a friendly conversation and just needs the victim to tell them a few things to help them out?

That was the question asked by the team behind the web site social-engineer.org. They have just released results of a several-months long poll that laid out two different scenarios of how a social engineer might try and elicit information from a victim.

The first showed how the principle of endearment and how it may be used by a malicious social engineer. The example given was a social engineer who attempts to get strangers to engage in very personal conversation with him with little effort. Dressed very casually he grabbed a prop that he felt would endear people to him, a small sign that had a funny slogan on it. As he walked around, looking like a tourist with his prop, he was able to engage people in conversation.

Belonging

"The fact is we like to deal with people who are like us, but even more powerfully we like to deal with those who LIKE us," said Christopher Hadnagy, founder of social-engineer.org and author of Social engineering: The art of human hacking. "Endearment makes a person feel liked and, in turn, like you. Endearment is used by getting on the same plane as the target, or giving them reasons to like you."

The second story involved a social engineer employing the authority principle. The social engineer walks into the office with IT tools and a clip board he mumbles how busy he is today. Then looking at the secretary he barks an order, "I was sent to check your network connectivity and I have no time as I have to do this on 25 other nodes. I need you to log in to your network share with your password as I watch to confirm you can connect."

"This works because people fear losing their jobs and there are no methods in place for an employee to port or reject without fear," explained Hadnagy. "Other methods, like carrying a clipboard, looking busy or in control, all of these give off the air of authority and few people will question it."

Rapport

The two scenarios were presented with a third option that neither of them would work.

Endearment came out as the winner among respondents. It was chosen by more than half of the several thousand who took the poll, said Hadnagy.

"We would have guessed that most would have chosen authority, but, in fact, we agree that endearment works in more cases over authority," said Hadnagy in a synopsis of the results. "A simple word or action that can make someone feel you care can go a long way into building rapport, trust and a relationship that will cause that person to want to give you the information you seek."

Women coerced

When the results are broken down by gender, endearment still took first place among both men and women, but authority was much further behind with the males. Many more women said they thought authority was a powerful social-engineering technique than men.

Hadnagy says the poll results further enforce that humans are naturally trusting creatures. But it is that trusting attitude that has lead many to being hacked.

"We are not saying to not be trusting, but just to become a critical thinker," said Hadnagy. "The requests that are being laid upon you, the questions being asked - do they make sense? Is it really needed to answer those questions to this individual? Critical thinking can go a long way. Secondly, get educated. Be aware of the attack vectors that are being used and learn how they are being facilitated. That can keep you aware."



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *