preview

Social Engineering Attack Essay

Decent Essays

When the term social engineering comes to mind, one thinks of movies and a complex scheme to bypass security, be it physical or Information Security. Mouton et al describe a social engineering as, “The “art” of influencing people to divulge sensitive information is known as social engineering” (2016). This deceptive form of trickery is used convince a target or victim to divulge information that will be useful to the attacker, this is also known as a social engineering attack (Mouton et al, 2016). We will examine the many of the popular forms of social engineering used today, along with their impacts on individuals and organizations as a whole. Lastly, we will examine techniques at the individual and organization level used today to mitigate the effects of social engineering. The first common form of social engineering that comes to mind is email phishing. Phishing (see supplementary material ) is described by Conteh and Schmick as a scam to pull …show more content…

Conteh and Schmick describe pretexting as a form of social engineering attack in which the fabricated scenario is designed to lure a victim into confirming or divulging Personally Identifiable Information(PII) to the attacker (2015). An example of this type of attack would be if an attacker called a victim at home and they showed up on caller ID as the Internal Revenue Service. The attacker knew your name and your spouse’s name, and claimed that the IRS owed you money due to an overpayment on last year’s tax return. All they asked for was for you to verify your current address and full social. Divulging this information would be devastating as the victims PII has been compromised. The attacker can sell this information or use it to open a bogus account for example. The potential damage to the victim’s credit rating could take time, effort, and the monetary costs associated with repairing the damage

Get Access