Social Engineering — News

More DDoS attacks will be application based: Gartner

By Hamish Barwick | 25 February, 2013 10:14

Hackers are adapting distributed denial of service (DDoS) attacks and combining these with social engineering tactics to try and infiltrate banks during 2013, warns Gartner.

Oz watchdog eyes whitelisting as “reasonable” privacy measure

By Liam Tung | 07 December, 2012 07:34

Enterprise information security in Australia could come under much greater scrutiny with the nation’s Information Commissioner looking to drill down deeply into the details of an organisation’s security practices after a breach.

Security threats explained: Social engineering

By Hamish Barwick | 20 June, 2012 08:58

In this series, Computerworld Australia examines some of the information security threats facing small businesses and larger enterprises today. We’ve looked at internal negligence and continue the series by speaking to experts about the problem of social engineering.

SaaS, APTs and asymmetric risk take spotlight at Security Threats 2012

By Bernard Golden | 03 February, 2012 09:40

I had the opportunity to speak at a new security conference last week, Security Threats 2012. I presented on the topic of balancing business benefits with risks in the cloud (more on that later), but the event touched on a wide range of pertinent IT topics, provoking stimulating discussions of some of the most pressing challenges business leaders are facing.

Government engineers actively plan for cyberwar

By George V. Hulme | 05 January, 2012 09:05

A decade ago, most viruses and worms were unleashed by curious students, pranksters and punks wanting to see what kind of damage they could inflict. That quickly evolved into criminals and thieves writing most of the malware once they realized money could be made.

The top three causes of security breaches: Part 1 of 2

By Jarrod Loidl | 13 December, 2011 13:50

It's been an interesting year for those following information security news. We started the year with the Vodafone breach, one of the largest privacy breaches ever experienced within Australia.

How to rob a bank: A social engineering walkthrough

By Jim Stickley | 27 October, 2011 05:20

If a company hires us for a social engineering engagement, typically they want us to get in and get to their back-up tapes, or into the data in their document room.

Social engineering: My career as a professional bank robber

By Joan Goodchild | 27 October, 2011 05:45

Jim Stickley got his first computer at age 12, and he was chatting with other computer "nerds" on bulletin board sites by the time he was 16. A wannabe hacker, Stickley said his first foray into playing the system was with free codes -- codes that would exclude his phone and computer time from racking up charges that would incur the wrath of his parents.

5 more dirty tricks: Social engineers' latest pick-up lines

By Joan Goodchild | 27 September, 2011 04:45 | 2 Comments

You may now be savvy enough to know that when a friend reaches out on Facebook and says they've been mugged in London and are in desperate need of cash, that it's a scam. But social engineers, the criminals that pull off these kinds of ploys by trying to trick you, are one step ahead.

Open this malware or I'll sue you

By Tim Greene | 22 September, 2011 05:31

The latest social engineering trick to get victims to open malicious email attachments accuses them of being spammers and threatens to sue them if they don't stop.

Bigger isn't better when it comes to social engineering attacks

By Tim Greene | 22 September, 2011 03:57

When it comes to social engineering attacks, larger companies attract more of them, and when they are victimized it costs more per incident, according to a survey sponsored by Check Point.

Social engineering attacks costly for business

By Joan Goodchild | 22 September, 2011 00:52

Social engineering attacks are widespread, frequent and cost organizations thousands of dollars annually according to new research from security firm Check Point Software Technologies.

Facebook Pwn tool takes profile info, helps social engineers

By Joan Goodchild | 14 September, 2011 04:28

A group of security researchers based in Egypt have created a tool that will make social engineering easier because it automates the collection of hidden Facebook profile data that is otherwise only accessible to friends in a user's network.

Hackers could reverse-engineer Microsoft patches to create DoS attacks

By Jon Brodkin | 25 August, 2011 04:36

The security company Qualys this week demonstrated how to reverse-engineer a Microsoft patch in order to launch a denial-of-service attack on Windows DNS Server.

Security, Hacker Conferences Have Tech Industry Buzzing

By Christina DesMarais | 07 August, 2011 10:43

Stories about lost wages aren't the only scary things being talked about in Sin City this week. The best security researchers and hackers from around the world have gathered in Las Vegas, and news about their work has been creeping out like a toxic flood.

Social engineering: 3 mobile malware techniques

By Joan Goodchild | 26 July, 2011 03:48

Social engineers have been using various dirty tricks to fool people for centuries. Social engineering, the art of gaining access to buildings, systems or data by exploiting human psychology, rather than by breaking in or using technical hacking techniques, is as old as crime itself and has been used in many ways for decades.

Night Dragon brings security vulnerabilities into the boardroom

By Georgina Swan | 11 February, 2011 10:06

A hacking operation dubbed ‘Night Dragon’ has targeted energy utilities, using tried-and-tested intrusion methods to steal intellectual property related to oil field exploration and bidding plans, according to security company McAfee.

Social engineering remains biggest cyber threat

By James Hutchinson | 24 March, 2011 11:58

Despite increases in the number and capability of botnets for distributed denial of service (DDoS) attacks, social engineering remains one of the largest cyber security threats to IT infrastructure according to the Australian Federal Police (AFP).

Malvertising continues to pound legitimate websites

By George V. Hulme | 09 March, 2011 02:19

In the last three months of 2010 attackers managed to serve 3 million malicious advertising, or malvertising, impressions every day. That's the headline figure from a report released today from Web security firm Dasient. According to Dasient, that's a 100 percent increase from the preceding quarter.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Email Malware Protection System

The FireEye Email Malware Protection System (MPS) secures against spear phishing email attacks that bypass anti-spam and reputation-based technologies.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.