The human element is often the weakest link in any corporate security system. Social engineering refers to psychological manipulation to trick users into disclosing private credentials.
1. Phishing & Spear Phishing
Phishing is the sending of fraudulent emails designed to look like trusted sources (banks, utility companies, IT departments). Spear phishing targets specific high-value individuals using personalized information.
2. Pretexting & Baiting
Pretexting involves creating an invented scenario (a pretext) to persuade target victims to perform an action (e.g. pretending to be an auditor). Baiting leaves malware-infected USB drives in public locations, counting on curiosity to drive installation.
3. Preventive Actions
- Implement regular, interactive security awareness training campaigns.
- Enforce strict policies regarding verification of identity before resetting user credentials.