Social Engineering Detection Moves Into the Live Conversation
Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering.
Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery.
Successful examples of social engineering include:
The Las Vegas casino breachesof 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs....
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE