Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Most Common Hack Is Also The Most Successful. Here’s How To Fight It.
Articles

The Most Common Hack Is Also The Most Successful. Here’s How To Fight It.

ISBuzz TeamBy ISBuzz TeamAugust 19, 2019Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Despite what movies might show, most hacks don’t involve frantic typing or brute-force attacks. In fact, Verizon’s “2017 Data Breach Investigations” report revealed that 90 percent of successful hacks aren’t hacks at all: They’re social engineering.

Simply put, social engineering is about manipulating people rather than computers. Modern hackers have discovered that it is easier to ask for data than it is to take it by force. These manipulators continue to trick everyone from secretaries to CEOs into giving up passwords, network access, and everything else they want. To safeguard against hacking, cloud service providers don’t need stronger firewalls; they need to learn how to protect themselves from human-to-human deception.

What Do Hackers Want?

Social engineers have different goals, but these hackers generally have one of two motivations: Some do it for personal profit; others commit intellectual property theft as state-sponsored actors.

The first group of social engineering hackers gain access to personal data (like credit card and Social Security numbers) to sell on the dark web. Last year, NBC News reported that breaches for personal gain are on the rise, especially those targeting Social Security numbers, which means hackers are getting more comfortable using this type of strategy.

But don’t discount the second group: state-sponsored hackers. Private companies might not feel as threatened by social engineers working on behalf of other governments, but they should. The Equifax breach appears to be the work of state-sponsored Chinese professionals, according to the Chicago Tribune. And, of course, the social engineering activities of hackers sponsored by Russia are well-documented. In Verizon’s report, 94 percent of the 620 breaches in the manufacturing sector last year qualified as espionage. Any company with intellectual property that can be stolen or copied should be wary of attacks from foreign agents.

How to Stop Social Engineers

Companies in every industry should fear the ramifications of a successful breach. Hackers typically target companies in financial services, government, healthcare, and retail, but they’re opportunistic above all else. If a company doesn’t protect its data well, hackers will eventually discover the weaknesses and take what they want. Usually, though, they won’t bother trying to force their way in — they let their victims do the work for them.

Social engineering takes many forms. Hackers send mass emails to businesses, leave USB drives in parking lots, send physical media in the mail, and make phone calls pretending to be other people. Even if they fail 99 percent of the time, their occasional successes provide all the incentive they need to keep going.

To protect your company against social engineering, follow these tips:

  1. Inventory data assets, and restrict access appropriately.

If you don’t know where your information is, you can’t protect it. Start your protective measures by identifying and classifying all the data you store. Don’t forget the data your users store in spreadsheets and Word documents. This isn’t just about your production databases.

Start by asking yourself the same questions a hacker might ask: What happens to customer data after you receive it? Where do you store sensitive intellectual property, and who has access to that information? If hackers want to get your financial records or product designs, who would they need to trick into giving it to them?

Classify that data by tiers ranging from highly sensitive to totally public. Customer data and intellectual property deserve the strictest security. After you complete your review, set a schedule to reassess these data flows at regular intervals to plug potential leaks before they happen.

  1. Require multifactor authentication.

According to the Verizon report, 81 percent of hacks involve weak or stolen passwords. In fact, Deloitte suffered such a breach that could’ve been easily avoided. After hackers got the password to an administrator’s account, they logged in and stole data from an email server. If that administrator had implemented MFA, the hackers would have been stumped.

Require anyone with access to sensitive data to use MFA on all company accounts. Text messaging is the most common MFA technique, and while this method isn’t totally secure, it’s better than nothing. Soft tokens, like push notifications, are a stronger option. For administrators with the keys to the kingdom, require a hard token (like a USB drive) that guarantees that the person entering the password has the right to do so.

  1. Use communication media with end-to-end encryption.

Encrypt data both when it’s stored and as it transfers from one place to another. This end-to-end encryption ensures hackers can’t actually use any data they manage to grab.

Use end-to-end encryption on everything from customers’ credit cards to employee emails. Microsoft recently introduced end-to-end encryption into Outlook, allowing users to shield their emails from would-be attackers and prevent unintended parties from gaining access to sensitive information.

  1. Create a culture of security.

Ultimately, the most important line of defense in data protection comes down to the social engineers’ targets: employees. By now, most people know that those Nigerian princes aren’t real, but not everyone knows how to spot a well-crafted hacker persona. For example, UC Davis Health suffered a breach last year when a hacker impersonated an employee through email and proceeded to access to the university’s health data.

Regularly educate employees on evolving phishing tactics. Talk to employees in different roles about how people might approach them to ask for illegitimate access. Remind workers about the importance of internal security, and help them easily report suspicious requests.

These tips will help you safeguard your organization against social engineers. However, if someone still manages to access your data, don’t try to hide it — contact local FBI agents immediately. Your data can’t be “unhacked,” but you might be able to stop the hackers before they do any more damage.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}