People are (still) the biggest security risks

Social engineering and ‘download this attachment’ scams are back – as if they ever left – and working better than ever, unfortunately.

"We're battling thousands of years of evolution," says Kevin Epstein, vice president of the Threat Operations Center at Proofpoint. "It's natural to be curious about things. Unfortunately, with email scams, it's better to think before you click."

One more reason we – the collective “we,” that is – continue clicking on malicious links or downloading bogus attachments, despite being told not to: hackers have gotten much better at pretending to be someone they're not, using social engineering to slip past our guard by masquerading as someone else.

It's worked, too. An employees at Seagate was recently the victim of an email phishing scam that lead to the release of W-2s of past and current employees, W-2s that include Social Security numbers and salaries among other personal information. An employee at Snapchat was also just phished into sending out payroll information into the wrong hands.

"Criminals are getting a little bit more sophisticated," says Seth Hamman, assistant professor of computer science at Cedarville University. "The ones making the headlines now are probably not emails with bad grammar or infantile attempts to trick people."

Why it works

You'd think that, by 2016 we'd be smart enough to know not to download anything from anyone we don't know and not to click on links from unknown sources. And generally we are. But hackers are using social engineering to makes their true intentions - and even where those emails are coming from.

In its "The Human Factor 2016" report, Proofpoint found that last year, hackers were much more likely to use email scams to get at us, and that 99.7 percent of documents used in attachment-based campaigns relied on social engineering and macros to work. They also found that 98 percent of URLs in scam messages link to hosted malware. In both cases, criminals relyed on users to put the hack onto computers themselves.

[Related: Faux phishing scheme shows CIOs how hacks unfold]

"Attackers are leveraging what's been hard wired into our DNA," says Epstein. "Curiosity killed the cat. Curiosity also gets you malware."

Hackers also know when to go in for the kill. Proofpoint found that emails come in at from 9 to 10 a.m., and that Tuesdays are heaviest delivery days. These windows are chosen because that's a time when receivers of those emails may have their guard down: not on Monday when you're right back to work but Tuesday after you've caught up for the weekend, but at a time when you may not have had your coffee yet and are rushing to your first meeting.

Plus, the attachments tend to be what they say they are. "The attachment will claim to be a video file or a Word document and you open it and it will play a video or you will see a Word document. But it's also doing other things in the background," says Epstein.

Social engineering expertise

The survey also found that social engineering is being used in highly targeted attacks on key business players to masquerade as higher ups. Most often, the end result is money being transferred to fraudulent bank accounts.

That may sound unbelievable. Who would send money to a stranger? But the hacker doesn't look like a stranger. One kind of scam, which Epstein calls "low level sophistication," will involve 10-15 emails between the potential victim and the attacker.

"It's not an attacker opening with 'hey this is your CEO please transfer money.' They opened with a 'John this is Sally. I had some questions about a recent invoice,' and then John responded to 'Sally' and then some other things, and in the course of conversation it got down to a transfer situation."

A more sophisticated version of this kind of attack is that John would receive an attachment based email, and the attachment would modify John's email settings so that the next time John gets a message from CEO Sally, it wouldn't go back to Sally but to the attacker who would then forward it to Sally.

"At some point, the attacker would then insert into one of the CEO's emails an extra paragraph or two," he says. "These are not blunt, easily detectable things. These are emails that are written in the native language adopting the tone of the executive's email addresses that appear to be exactly the same, modifying very slight or using hidden settings that you don't see."

[Related: Security education on phishing can save companies millions]

It's a higher tech version of an old scam, Epstein adds. "2014 was the year of figuring out how to bypass the alarm system and sneak in," he says. "2015 was the year of showing up with a package under your front arm and knocking on the front door."

Your information is out there

Social engineering is what is making these kinds of scams possible and, says Hamman, not surprising given how much of our information there is to engineer. "So much of our personal identifying information is out there," he says. And he's not just talking that to what you post on twitter. In the last three years, he's been alerted that he's been a victim of a data breach four times.

"My information – who knows where it is and if my information ends up in the wrong hands, they know my birthday, social security number, may or may not know my credit card numbers," he says. When someone is targeted by a criminal who knows this information, the target is more likely to think that the person is who they say they are. "These are sophisticated attacks that people are falling for because the attacker has done their homework," he says.

Last year, Frank Abagnale, who was the real life con-man behind Catch Me If You Can (and has worked for the FBI for more than 40 years), said,“What I did 50 years ago as a teenage boy is 4,000 times easier to do today because of technology,” adding that “technology breeds crime. It always has, and always will.”

He hasn't been proven wrong yet.

Join the CSO newsletter!

Error: Please check your email address.

More about FBIProofpointSeagate

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Jen A. Miller

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts

Market Place