Social engineering: hacking the person, not the computer

There's no software that stops a friendly stranger talking someone into handing over a password. This is the attack that works on good systems and clever people alike.

// overview

Why bother picking a lock?

Social engineering is manipulation aimed at getting someone to do something they shouldn't, hand over a password, approve a payment, install a program, let a stranger onto a machine. There's no technical exploit involved. The person is the exploit.

It persists because it works on everyone. Being clever is no protection; if anything, confident people are easier, because they're less likely to stop and check. The attacks work by borrowing something you already trust: your bank's name, your boss's name, the idea that someone from Telstra is trying to help.

We see the aftermath of this far more often than anything you'd call hacking. It's the single most common way homes and small businesses across the Downs actually lose money.

// how it shows up

The five we see most.

// what actually helps

The fix is permission, not software.

The most effective thing a business can do costs nothing: tell your staff explicitly that they are allowed to say "let me check that and call you back", to anyone, including you. Say it out loud, more than once.

Nearly every successful social engineering attack we've cleaned up had a moment where someone felt uneasy and pushed on anyway, because stopping felt rude or looked like they didn't trust the boss. Removing that social cost is the whole ballgame.

After that it's a handful of simple habits, none of which need a budget:

// for families

The version that targets parents and grandparents.

Older family members get a particularly nasty variant: a call claiming to be from the bank's fraud team, saying their account is compromised and money must be moved to a "safe account" immediately. It's urgent, it's frightening, and the person on the phone is reassuring and competent.

The defence that actually works is agreeing a family rule in advance, while nobody is under pressure: no money moves and no remote access is granted without ringing one nominated family member first. Not because the person can't be trusted to judge it, because the whole attack is built on not giving them time to think.

We've sat with more than a few Toowoomba families after one of these. The ones who got off lightly almost always had someone to ring.

// questions

Good questions, straight answers.

Someone rang saying they were from Microsoft. Is that ever real?

No. Microsoft does not ring people about viruses, and neither does Telstra, NBN Co or the ATO. If you're worried something genuine is going on, hang up and ring the organisation on a number you looked up yourself.

I let someone remote onto my computer. What now?

Disconnect it from the internet, then ring us. Don't do your banking on that machine until it's been checked. We'll look for remote access tools and anything left behind, and go through which accounts need passwords changed.

Is staff training actually worth it?

The short, practical kind, yes. Half an hour with real examples beats an hour-long compliance video nobody watches. The measurable benefit isn't that people spot every scam, it's that they feel able to stop and check.

Can technology stop any of this?

It helps at the edges. Good email filtering, MFA and locked-down remote access all reduce the surface. But the last line of defence is a person deciding to verify, which is why the habits matter more than the products.

$ inspyred --book-a-callout

Got a question about this?
Ask a human.

Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.

Hours
By Appointment · 7 days
Service area
Toowoomba & the Darling Downs
Service style
Mobile: we come to you