How Social Engineers Use Social Media

Stu Sjouwerman | Aug 3, 2021

Social Engineers Use Social MediaPeople need to be aware of how their social media posts can be used against them, according to Darren Millar, senior vice president of operations at PiiQ Media. In an article for International Business Times, Millar explains that open-source intelligence is extremely valuable for launching social engineering attacks, particularly against executives.

“As PiiQ Media researchers found, most executives publicly list information on a regular basis,” Millar writes. “In general, identification of a personal email address for executives was found in 61% of the profiles, with a business email address for 98% of them. And more than 60% had three or more social media profiles that were easily discovered. All these pieces of information can be used to craft phishing emails that target executives.”

Millar adds that executives are also more likely to be targeted by sophisticated social engineering attacks.

“From the bad actor's perspective, company executives are an especially appealing target for attack for the simple reason that they likely have more access to more assets within a company,” Millar says. “That means the potential payoff is larger. And at the same time, there's too often a sense of invincibility when it comes to many executives – a feeling that social engineering attacks and data breaches are things that happen to other people but not them.”

Millar notes that since executives are such valuable targets for social engineering, they need to be trained in how to thwart these attacks.

“Executives are prime targets due to their level of network access, so they must be included in thorough training about proper social media use that doesn't give away anything criminals can use,” Millar concludes. “Executive participation will send a message to all employees that this is a serious matter worthy of their full attention and vigilance.”

New-school security awareness training can enable all of your employees to follow security best practices.

International Business Times has the story.

Stop Being a Target for Social Media Exploits

Social media is the new frontier for targeted spear phishing and credential theft. Use our Free Social Media Phishing Test to identify which users are likely to click malicious links or leak data on platforms like LinkedIn and X, and get your results in just 24 hours.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.