87% Increase in Social Engineering Scams During the First Quarter of 2021 Compared to Q1 2020

Stu Sjouwerman | Jul 7, 2021

87% Increase in Social Engineering ScamsThere was an 87% increase in social engineering scams during the first quarter of 2021 compared to Q1 2020, according to Ayelet Biger-Levin from BioCatch. In an article for The Paypers, Biger-Levin explains that three-quarters of successful scams involved the attacker using information about the victim in order to lend credibility to the scheme.

“In the financial industry, there are two main types of social engineering attacks: harvesting online banking credentials and/or personal information and real-time scams such as authorised payment scams or remote access tool (RAT) scams,” Biger-Levin writes. “The second type of scam requires little technological sophistication, but scammers do need to prove to victims that they are ‘legit’ so they often spend time harvesting information and learning about their victim prior to committing a crime. In fact, 75% of victims claim that a scammer already had their personal information when coercing them into defrauding themselves, according to a report by the US Federal Trade Commission.”

Biger-Levin notes that a social engineering scam can bypass many technical defenses since it involves tricking a human.

“These scams are difficult to detect since the cybercriminal does not interact directly with the banking platform and instead convinces the victim to execute an authorised payment themselves,” she writes. “Standard fraud detection tools are unlikely to detect these scams since the device is a user’s trusted device, the network connection matches with the user profile, and any step-up authentication check would also be passed as the victim directly receives the OTP code.”

Biger-Levin adds that voice phishing (vishing) also increased last year.

“Due to global lockdowns, isolation of social distancing, and increased use of digital banking from the pandemic, most types of fraud hit record levels last year,” Biger-Levin says. “Specifically, social engineering was a favourite go-to method for cybercriminals. According to BioCatch data, one in four confirmed cases of account takeover last year involved some form of social engineering voice scam, such as authorised push payment (APP) fraud.”

New-school security awareness training can give your organization an essential layer of defense by teaching your employees how to recognize social engineering attacks.

The Paypers has the story.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.