Learning More on Social Engineering Tactics are the Key to Preventing Phishing Expeditions

Stu Sjouwerman | Dec 17, 2020

Understanding Social Engineering Tactics Prevent Phishing ExpeditionsUnderstanding social engineering attacks is the key to thwarting them, according to Juan Badell and Russell Petrich, content designers for Sophos’s phishing simulation service. Badell and Petrich mimic the way real cybercriminals think in order to craft convincing fake phishing emails, and they outline the four steps attackers go through when they create these emails.

First, the attackers choose their audience and design their phishing template accordingly.

“Different people fall for different tricks, so the more information you have about your target the easier it is to craft a convincing phishing lure,” Badell and Petrich write. ”The audience may be broad, for example users of a particular bank or people who need to do a tax return, or it may be very specific – such as a particular role within an organization or even a specific individual.”

Next, the criminals decide which type of emotional lure they’ll use. Fear is a common motivator, but attackers can play on other emotions as well:

  • “Curiosity. Humans are naturally inquisitive and phishers abuse this by making you want to know more. ‘Do you want to know what happened next?’ All you need to do is to click the link or open the attachment.
  • “Hope. The abuse of hope by phishers can range from general messages about unexpected prize wins and dating opportunities to specific emails referring to job offers, pay increases and more.
  • “Necessity. Phishers often use a cybersecurity lure – pretending that you’ve suffered a security breach – to make it sound as though you simply must act now.”

Third, the criminals build the phishing email, usually including links or malicious attachments. This process has become very easy with the wide availability of phishing kits for sale. Finally, the attackers send the emails, often from a spoofed domain or a hacked account.

Most phishing lures are easy to avoid once you know what to watch out for. New-school security awareness training can help your employees recognize these tactics in the real world.

Naked Security has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.