Social engineering: hacking the person, not the computer
There's no software that stops a friendly stranger talking someone into handing over a password. This is the attack that works on good systems and clever people alike.
// overview
Why bother picking a lock?
Social engineering is manipulation aimed at getting someone to do something they shouldn't, hand over a password, approve a payment, install a program, let a stranger onto a machine. There's no technical exploit involved. The person is the exploit.
It persists because it works on everyone. Being clever is no protection; if anything, confident people are easier, because they're less likely to stop and check. The attacks work by borrowing something you already trust: your bank's name, your boss's name, the idea that someone from Telstra is trying to help.
We see the aftermath of this far more often than anything you'd call hacking. It's the single most common way homes and small businesses across the Downs actually lose money.
// how it shows up
The five we see most.
- 01
The support call
Someone rings claiming your computer is sending error reports, or your internet has a fault. They're patient and they sound like they're helping. By the end you've installed remote access software yourself and they're inside. No real company will ever ring you unprompted about a virus.
- 02
The boss email
A message that looks like it's from the owner or manager, usually saying they're stuck in a meeting and need a payment made or gift cards bought urgently. It works by making the junior person feel awkward about double-checking.
- 03
The changed invoice
A supplier's email account gets compromised. Their genuine invoice goes out with new bank details. Nothing about it looks wrong because almost nothing about it is wrong.
- 04
The helpful stranger
Someone turns up to "service the printer" or check the network. High-vis and a clipboard get people a very long way. Once they're at a desk, a USB stick takes seconds.
- 05
The account recovery
An attacker rings your phone provider pretending to be you, and moves your number to their SIM. Now they receive your text-message security codes. This is why an authenticator app beats SMS.
// what actually helps
The fix is permission, not software.
The most effective thing a business can do costs nothing: tell your staff explicitly that they are allowed to say "let me check that and call you back", to anyone, including you. Say it out loud, more than once.
Nearly every successful social engineering attack we've cleaned up had a moment where someone felt uneasy and pushed on anyway, because stopping felt rude or looked like they didn't trust the boss. Removing that social cost is the whole ballgame.
After that it's a handful of simple habits, none of which need a budget:
- Verify on a number you already had, never the one in the email or given by the caller
- Agree a rule for changing payment details: always confirmed by phone, no exceptions, no matter who asks
- Nobody rings you about a virus. Not Microsoft, not Telstra, not the ATO. Hang up
- Don't let anyone remote onto your machine unless you initiated the call to a number you looked up
- Use an authenticator app instead of SMS where you can, to blunt SIM-swap attacks
- Make reporting easy and blameless, the faster you hear about it, the less it costs
// for families
The version that targets parents and grandparents.
Older family members get a particularly nasty variant: a call claiming to be from the bank's fraud team, saying their account is compromised and money must be moved to a "safe account" immediately. It's urgent, it's frightening, and the person on the phone is reassuring and competent.
The defence that actually works is agreeing a family rule in advance, while nobody is under pressure: no money moves and no remote access is granted without ringing one nominated family member first. Not because the person can't be trusted to judge it, because the whole attack is built on not giving them time to think.
We've sat with more than a few Toowoomba families after one of these. The ones who got off lightly almost always had someone to ring.
// questions
Good questions, straight answers.
Someone rang saying they were from Microsoft. Is that ever real?
No. Microsoft does not ring people about viruses, and neither does Telstra, NBN Co or the ATO. If you're worried something genuine is going on, hang up and ring the organisation on a number you looked up yourself.
I let someone remote onto my computer. What now?
Disconnect it from the internet, then ring us. Don't do your banking on that machine until it's been checked. We'll look for remote access tools and anything left behind, and go through which accounts need passwords changed.
Is staff training actually worth it?
The short, practical kind, yes. Half an hour with real examples beats an hour-long compliance video nobody watches. The measurable benefit isn't that people spot every scam, it's that they feel able to stop and check.
Can technology stop any of this?
It helps at the edges. Good email filtering, MFA and locked-down remote access all reduce the surface. But the last line of defence is a person deciding to verify, which is why the habits matter more than the products.
$ inspyred --book-a-callout
Got a question about this?
Ask a human.
Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.