preview

Social Engineering: Persuasion Of A Person Into Divulging Sensitive Information

Decent Essays

Social Engineering is the persuasion of a person into divulging sensitive information which may include passwords, account numbers, names, dates, Etc. A person may call and ask to speak to a specific individual that no longer works in that position for the company and without thinking the employee may state that person no longer holds that position and then states the current name of the employee holding that position. This type of Social Engineering can be considered phishing because this person is leading someone on to acquire the correct information that they are looking for. This same person or someone else can then call later in the day and ask to speak to the individual name that was acquired earlier in the day, possibly finding out their schedule or other information that can be added together to get the big picture. …show more content…

An example of a physical approach may be following behind someone entering into a secure area and entering without using your credentials, this is known as tailgating. This allows someone unescorted access into an area where they are not authorized to be. Another way to collect information is by dumpster diving for documents in a company’s trash area allowing important information to be pieced together such as employee numbers, names, work sections, schedules. This and more information can be used to manipulate a person by sending spam or hoax e-mail to these individuals, that when opened can load a virus or Trojan which then can compromise the companies IT

Get Access