BSI ID: G 0.42
Social engineering is a method of gaining unauthorised access to information or IT systems through social actions. Social engineering exploits human characteristics such as helpfulness, trust, fear or respect for authority. This allows employees to be manipulated into acting inappropriately. A typical case of social engineering attacks is the manipulation of employees via telephone calls, in which the attacker pretends to be, for example:
An assistant whose boss needs to do something quickly but has forgotten their password and needs it urgently.
An administrator calling because of a system error, as they need the user's password to fix the problem.
If critical questions arise, the curious person is supposedly ‘just a temp’ or an ‘important’ person.
Another strategy in systematic social engineering is to build a long-term relationship with the victim. Through many unimportant phone calls in advance, the attacker can gather knowledge and build trust that they can exploit later.
Such attacks can also be multi-stage, building on knowledge and techniques acquired in previous stages. Many users know that they must not disclose their passwords to anyone. Social engineers know this and must therefore find other ways to achieve their desired goal.
Examples of this include:
An attacker can ask the victim to execute unknown commands or applications, e.g. because this is supposed to help with an IT problem. This can be a hidden instruction to change access rights. This allows the attacker to gain access to sensitive information.
Although many users employ strong passwords, they tend to use them for multiple accounts. If an attacker operates a useful network service (such as an email address system) that requires users to authenticate themselves, they can obtain the desired passwords and logins. Many users will also use the login details they use for this service for other services.
When attackers obtain passwords or other authentication credentials without authorisation, for example through social engineering, this is often referred to as ‘phishing’ (a portmanteau of ‘password’ and ‘fishing’).
In social engineering, the attacker is not always visible. Often, the victim never knows that they have been exploited. If this is successful, the attacker does not have to fear prosecution and also has a source from which to obtain further information at a later date.