Important Information about Social Engineering
I think you have probably heard about password attacks before. There’s a good chance you know that hackers try to get your password so that they can access your personal information and make a lot of money and ruin your whole life, etc. But this is not the only way that hackers can steal your information. Some hackers try to directly target the person to get there personal information. This is what is called social engineering.
What is Social Engineering?
Basically, social engineering is where hackers manipulate people to share their personal information. The hacker pretends to be someone that you know, or something trustworthy, like a tech support agent or a bank. Then, they try to talk to you and use tricks to get you to do something they want, such as giving you their password or clicking on a malicious link. This method actually works surprisingly frequently, because people usually like to trust authority and they also like to be helpful.
Common Social engineering techniques:
Social engineering can come in many different forms. Here are some of them:
- Pretexting The attacker makes up something believable to trick you. For example, they might say “Hi, this is technical support. We detected a problem with your account and we need your password to fix this super big issue.”
- Baiting The attacker offers something tempting, like a free gift card or a USB drive labeled “Salary Info,” hoping you take the bait.
- Impersonation They pretend to be someone you know or trust, sometimes using real details to seem convincing.
- Urgency and fear “Your account will be deleted in one hour unless you verify now.” Panic makes people skip their normal caution.
- Tailgating In person, they follow someone through a locked door by acting like they belong.
From all these strategies, you can tell that they are all related to manipulation. They want to get you to do something bad without thinking.
The effectiveness of social engineering
The main reason why social engineering works is because it causes you to have certain emotions that block your thoughts. Whenever you are tempted to do something because you are scared, or maybe you want to be helpful, usually what happens is that you lose your good judgement. Attackers have to create those feelings in order for you to give up your personal information.
Another thing that attackers do is that they basically kind of spy on you. They watch for messages that mention your real employer or your real bank. Then, they take that personal detail and add it to their message, which makes it sound more realistic, causing you to lower you guard.
How to protect yourself
Basically, in order to protect yourself, you have to adopt some habits and take some precautions whenever you are dealing with something sensitive. Here are a few habits:
- Slow down Urgency is a warning sign. Real organizations can wait while you verify.
- Verify independently If you get a call or message asking for information, hang up and contact the organization using a number or address you know is real.
- Never share passwords No legitimate company will ever ask for your password by phone or email.
- Be skeptical of unexpected requests even from people who seem to be authority figures.
- Do not let details fool you Knowing your name or a recent order does not prove someone is who they claim to be.
Where technology still helps
While social engineering targets people, good tools reduce the risk of you giving away your personal information. For example, a password manager helps because it only fills in logins on real sites, so a fake page cannot easily harvest your saved password. Two-factor authentication helps because even if you are tricked into giving up a password, the attacker still needs your second factor.
Even though social engineering is supposed to target people, there are certain tools that you can use to reduce the risk of getting your personal information stolen. For example, you can get a password manager with autofill, which only fills in logins on real websites, so fake website cannot easily take your passwords. Another thing you can do is set up two-factor authentication, which requires a second factor to login that the attacker does not necessarily have. We have another article discussing that if you would like to learn more.
With HatePassword storing your passwords in an encrypted vault, your credentials are not floating around in emails or sticky notes where they are vulnerable to being taken. However, the best way to deal with this is to be aware of the situation. When something feels rushed or too convenient, you should pause and think. That moment of pausing and thinking usually helps you spot the trick and shut it down.