IT Security

What exactly is social engineering?

From a seemingly harmless text message to a sophisticated phishing campaign—how attackers exploit employees’ vulnerabilities and trust to achieve their goals.

Social engineering is an important concept not only in today’s digital world, but also in the home. It refers to how attackers exploit the vulnerabilities and trust of people—including employees—rather than relying on technical tricks and security vulnerabilities to achieve their goals.

New Challenges: Today, IT specialists must not only implement technical security measures but also develop a deep understanding of thepsychological aspects of social engineering. In this article, we will take a closer look at social engineering, explain exactly what it means, and why it is so important.

Definition of Social Engineering

To understand social engineering, it is essential to clearly define the term: Social engineering refers to the practice of persuading people to disclose confidential information, perform actions, or make decisions that are normally contrary to their own interests or those of their organization. This involves the use of various forms of social and psychological manipulation. In doing so, the attacker often seeks to exploit human traits such as fear, respect for authority figures, trust, and a willingness to help in their victims.

This type of manipulation can take many forms, ranging from seemingly harmless text messages or instant messages in which the attacker pretends to be a family member in order to beg the victim for money, to sophisticated infiltration of large corporations through methods such as phishing. Between these two extremes lies a wide range of tactics and techniques used by attackers to gain access to sensitive data.

Social engineering attacks

According to a 2023 survey by G Data CyberDefence AG, 48% of all companies surveyed have been targeted by social engineering attacks. These attacks were primarily carried out by phone or email. In addition, attempts are also made to access internal company data through personal contacts or professional networks. According to the Federal Ministry of Information and Security, 66% of all spam emails were attempted cyberattacks.1

As explained in the definition, social engineering attacks can take many different forms. Generally speaking, they can be divided into two main categories, although there is a third, less common category:

1. Human-based
Social engineering:

Without Technical Elements


2. Computer-based social engineering:

With Technical Elements


3. Reverse Social Engineering:

The victim approaches the attacker voluntarily

Nowadays, the two main categories—human-based and computer-based social engineering—are increasingly converging. The following section explains the categories most commonly encountered in the business world and outlines strategies for mitigating these attacks.

1. Phishing

Phishing is consideredthe most widespread form of social engineering, and virtually everyone has seen at least one phishing email in their inbox. In this technique, a malicious actor sends emails that contain harmful attachments or redirect recipients to dangerous websites.

There are now a wide variety of phishing variants, ranging from classic spam phishing to highly specialized forms such as whaling, spear phishing, or even quishing (QR code phishing), to name just a few. Despite its widespread prevalence, the threat posed by phishing should by no means be underestimated, as well-executed phishing campaigns are often highly successful for attackers. It is important to realize that it only takes a single person within a company to fall for a phishing email.

This technique targets individuals who are active on online dating platforms or social media, for example. The attacker creates fake identities by setting up fake profiles in order to befriend the target over an extended period of time. The attacker then exploits the “trust” built up in this way to trick the victim into installing malware, transferring money, or disclosing confidential company information.

To protect yourself from this tactic, it is crucial to foster a strong awareness of online security and privacy and to be careful not to disclose personal information and financial details carelessly.

Baiting is a type of social engineering attack in which the attacker makes false promises to trick the victim into revealing personal information or installing malware.

The phishing method is often initiated by enticing ads or emails, which frequently take the form of offers for free movie downloads, updates, games, and similar items. If the victim falls for this deception and, for example, enters their password for platforms like Amazon, the attacker gains access to this sensitive data and can misuse it for their own purposes.

Baiting isn't limited to the online world; there's also a physical version in which a malware-infected USB drive is handed to the victim. As soon as it's plugged into the computer, the malware stored on the drive is automatically installed.

To protect yourself from online baiting, it is strongly recommended that you always view advertisements and enticing offers with a critical eye. When it comes to offline baiting, it is particularly important never to connect USB flash drives from unknown sources in order to minimize the risk of a malware infection. Raising employee awareness and providing training on such fraudulent methods is also recommended.

Diversion theft is a multifaceted cyberattack that originally began offline but has since evolved to include online variants. This type of attack aims to distract or divert the victim’s attention while criminal activities are carried out.

In an offline diversion theft, the attacker manipulates physical events. For example, a thief might convince a courier to pick up a package from the wrong location, deliver the wrong package, or hand over a package to the wrong recipient. The diversion usually takes place in the real world, and the damage can be significant.

In the online version of Diversion Theft, the attacker uses tactics to steal confidential information from the victim. By skillfully employing distractions and misdirection, the attacker tricks the user into sending this information to the wrong recipient. The attacker often disguises themselves as a familiar or trustworthy source to deceive the victim. This is frequently done through spoofing.

To protect yourself from phishing, it is crucial to remain vigilant and skeptical, especially when faced with unexpected distractions or communications from supposedly trustworthy sources. Training employees on online security, implementing strong security policies, and raising awareness of the risks of spoofing are essential defenses against this threat.

Pretexting is a form of social engineering in which the attacker devises clever scenarios or pretexts to persuade the target to disclose sensitive information.

The attacker may impersonate an authority figure (such as a lawyer, law enforcement official, or tax advisor) or pretend to have an interest in the target (such as a talent scout or event organizer). In this context, the attacker would provide the victim with plausible reasons and ask targeted questions to gather additional information. This collected data is used to employ other techniques to obtain even more sensitive information or even gain access to the victim’s personal accounts.

To protect against pretexting attacks, heightened vigilance is essential. Above all, this means not carelessly disclosing personal or sensitive information and carefully verifying the identity of anyone who requests such information. Raising employee awareness and providing training on social engineering are crucial in this regard.

Business Email Compromise (BEC) is a sophisticated social engineering tactic in which the attacker cleverly impersonates a trusted executive who is authorized, for example, to issue instructions regarding a company’s financial affairs.

In this attack scenario, the fraudster closely monitors the executive’s behavior over an extended period and creates a fake email account using spoofing techniques. The attacker then uses this fake identity to send targeted emails to the executive’s staff. In these fake messages, recipients are instructed to make wire transfers, change bank details, and carry out other financial transactions.

BEC attacks can result in significant financial losses for companies. Unlike other cyber fraud methods, BEC attacks do not necessarily rely on malicious URLs or malware that can be intercepted by traditional cybersecurity tools such as firewalls or endpoint detection and response (EDR) systems. Instead, BEC attacks rely on a detailed understanding of the victims’ personal behavior. This makes them particularly insidious, as they are often harder to monitor and detect, especially in large organizations.

Therisk of BEC attacks underscores the need for employee training and awareness, as well as the implementation of effective monitoring and security policies, to minimize the impact of this type of fraud.

The quid pro quo attack is a social engineering tactic in which the attacker pretends to provide a service to the victim, often in connection with supposed IT issues that need to be resolved, such as poor internet connections or security updates.

If the victim responds to this supposedly helpful gesture, the attacker often requests the “necessary” login credentials to resolve the alleged issue. Once the victim has disclosed this information, the attacker uses it to intercept data or even infect the network with malware. There is also the possibility that the malicious actor will use this access to employ additional social engineering techniques with significantly higher chances of success.

To mitigate this threat, it is essential that all employees have a thorough understanding of social engineering. In addition, clear guidelines and policies should be established that prohibit the sharing of login credentials, even with purported IT support staff.

SMS phishing, also known as smishing, is a type of phishing attack in which the scammer attempts to trick the victim into clicking on a malicious link via text message. Since this is a specific type of phishing, the same precautions apply as with traditional phishing attacks, which were discussed earlier.

Tailgating, also known as “piggybacking,” is a physical method of gaining unauthorized access to corporate premises. In this scenario, the attacker often lurks near secured entrances, hoping that an employee will open the door using their access credentials and thereby, knowingly or unknowingly, let the intruder in. Common tactics include pretending to have forgotten their access card or similar credentials at home. Alternatively, the attacker may simply say, “Wait a second, I need to go in too!” in the hope of persuading the employee to briefly hold the door open for the intruder.

Once an attacker has successfully gained access, they have numerous opportunities not only to explore the building but also to steal sensitive documents, compromise the company network, attempt to install malware, and much more.

To prevent this type of intrusion, it is essential to provide all employees with an appropriate level of training and awareness programs that highlight the risks involved.

Social Engineering Example

Social engineering is not a new phenomenon; deceiving people by pretending to have good intentions in order to exploit their trust has existed since the dawn of civilization. In modern times, however, the acceleration of our communication—and especially the rise of impersonal communication—has brought this type of deception even more into the spotlight.

A vivid example of social engineering is Robin Sage, a fictional persona created in December 2009 by security expert Thomas Ryan. This experiment resembled a honeypot attack. Using this fictitious identity, Ryan created several profiles on social media platforms and deliberately established contacts, primarily with security experts, military personnel, and employees of intelligence agencies and defense organizations.

Despite his fake profile, Robin Sage received offers for consulting work from companies such as Google and Lockheed Martin. Over a two-month period, Thomas Ryan managed to obtain email addresses, bank details, and even location information for secret military bases.

New Developments in Social Engineering

In its report “The State of IT Security in Germany 2023,” the Federal Office for Information Security describes the potential forusing generative artificial intelligence (GAI) in the field of social engineering.1GAI models designed to generate human-like text or even voices enable attackers to create even more convincing and tailored deceptions.

With GKI, social engineering attacks can be taken to a whole new level. Malicious actors can create personalized phishing emails, fraudulent calls, or fake social media profiles based on the individual characteristics of their potential victims. This can make it harder to detect fraudulent activity and reduce the effectiveness of security training.

The implications of this technology for cybersecurity require heightened attention and proactive measures. Companies must keep their security infrastructures up to date at all times to be prepared for the evolving capabilities of GKI in social engineering scenarios. In addition, it is crucial to raise employee awareness of this specific threat to ensure a stronger defense against such deception attempts.

Precautions Against Social Engineering

In social engineering, attackers exploit human vulnerabilities—such as the desire to resolve issues quickly and easily—to achieve their goals. This makes this type of attack particularly difficult to reliably thwart.

To protect yourself as effectively as possible against this threat, you should implement the followingprotective measures:

  • Never share confidential information about your employer or your work, even in a private setting.
  • Reputable companies will never ask you to share your contact information, login credentials, or passwords.
  • Always treat strangers with caution and a sense of responsibility. Always consider whether your actions could be misused by others.
  • Be extremely cautious when dealing with emails. If you suspect that an email is not from a legitimate source, notify your internal or external security officer immediately.
  • If you need an urgent response or notice anything unusual, you should call your contact to verify that the email in question was actually sent by them.
  • Foster a shared understanding of how to combat social engineering. If an attack occurs, it must be reported immediately. There is no place for false modesty here, and management should make that clear. To err is human, but an unnoticed attack can be devastating.

Due to its complexity and the fact that it exploits human behavior, social engineering is generally considered by the IT security industry to be nearly impossible to prevent entirely. Nevertheless, by implementing the measures discussed in this article and providing thoroughawareness trainingfor all employees, the likelihood of a successful attack can be significantly reduced.

Frequently Asked Questions About Social Engineering

"My company isn't big enough for anyone to go to the trouble of doing that"

Social engineering attacks don't necessarily have to be elaborate; they can be launched in just a few minutes. Furthermore, a successful attack usually opens the door to even more serious attacks.

If you discover that your company has been the victim of a social engineering attack, swift action is crucial—time is of the essence. Report the incident immediately to your internal security incident response team and don’t hesitate to involve your internal and potential external experts to take appropriate action quickly.
If you need an outside perspective, our IT security experts are available for a free initial consultation . We are happy to assist you in assessing the situation and taking appropriate steps.

The first step involves exploring the topic of social engineering in collaboration with the audience. This involves discussing the various types of social engineering and raising awareness of the issue.

Once the groundwork for the topic has been laid, a brief description follows of the current social engineering threat landscape and how professionally attackers now operate.

Social engineering will then be illustrated using the specific example of a phishing attack. The following four stages of the “cyber kill chain” will be examined:

  • Reconnaissance (Reconnaissance)
  • Enumeration (Social Engineering Techniques)
  • Exploitation (execution of an attack)
  • Lateral Movement (Strengthening the Grip)

Finally, we will discuss countermeasures in detail and how to better protect yourself against social engineering attacks in the future.

Your journey with OHB Digital Services

Leverage space technology for your business. OHB Digital Services GmbH has been a trusted partner for secure and innovative IT solutions for many years. We are part of one of Europe’s most successful space and technology companies. With our products and services, we can help you digitize your business processes across the value chain and address all security-related issues.Feel free to contact us.

1 See“The State of IT Security in Germany 2023”: in: Federal Office for Information Security, n.d., https://www.bsi.bund.de/SharedDocs/
Downloads/DE/BSI/Publikationen/
Lageberichte/Lagebericht2023.pdf.

Recent magazine articles on IT security

RedTeaming32 1
IT Security
What is red teaming, and who can benefit from it?
In this article, we explain the benefits of red teaming and highlight which companies this specific type of penetration test is best suited for.
Read more
VULNERABILITY ANALYSIS32
IT Security
Why should vulnerability analysis be a concern for small and medium-sized businesses as well?
More than half of all small and medium-sized enterprises in Germany have already fallen victim to a cyberattack; depending on the scale of the attack, the financial losses have run into the millions.
Read more
phishing 32
IT Security
What exactly is phishing?
A well-crafted phishing email can look deceptively genuine at first glance. If an attacker succeeds in deceiving the victim, they can gain access to internal company data or login credentials, depending on the attack’s objective.
Read more

Learn more about our phishing simulations and awareness training.

Discover how your business can benefit

csm nicolas roesener e35f74755d
Nikolas Rösener
Security Expert