Hello, This Is Microsoft: A Social Engineering Staple


Cyber sleuthing is easier than you think.

Residing in the information age presents both blessings and challenges. Whether intentionally disclosed or not, your organization's information is easily accessible and can be located on numerous websites.

  • Organization’s formation information

    • Address

    • Contact information

    • Person(s) who formed the organization

  • Organization’s hierarchy and employment status

    • Employees

    • Employee titles

    • Employee salary ranges

    • Position Titles

    • Open Employment Positions

  • Organization’s Communication Channels

    • Domains

    • Emails

    • Phone Numbers

    • Chat Portals

    • Ticketing Solutions

Utilizing data effectively.

A solitary piece of information may often seem harmless, but the real danger arises when multiple data points can be assembled to create a comprehensive profile of a person or organization. This amalgamation of information can then be exploited for malicious purposes. The following are some combinations commonly employed by threat actors.

Social engineering is phishing’s best friend.

Successful phishing campaigns typically leverage a blend of contextual organizational knowledge, brand recognition, understanding systemic or social hierarchies, and strategically implemented calls to action. Whether it's convincing a support desk they’re a user at the organization that needs to reset a password and grant Multi-Factor Authentication (MFA) authority to regain access to a locked system, convincing a CFO to initiate a wire transfer to settle an organizational debt, or providing a malicious file titled “Proposal” to a finance team, threat actors skillfully incorporate fragments of information to enhance credibility and persuade the end user.


Learn more about phishing in a prior post here.

How realistic is this scenario?

Whether you're a large enterprise or an individual, chances are you've encountered situations where someone has called or emailed, posing as IT Support, Microsoft, the IRS, Bank of America, Amazon, Verizon, or any other entity—whether internal or a governing body. Below you will find a quick list of organizations that have fallen victim to social engineering attacks.

An uphill battle.

As long as there is financial gain to be had, threat actors will persist in deploying this highly effective attack vector. To proactively navigate this landscape, we've outlined steps that organizations or individuals can take to enhance their protection in our phishing post.

We are an email away.

If you have any more questions or seeking guidance, feel free to reach out and have a chat with the team. We are here to help!

Previous
Previous

The Road Ahead: Looking to 2024

Next
Next

Holiday Social at Brandywine Kitchen