Social Engineering Techniques

Scenario

You are a security support specialist for a large shipping and logistics company. Review each helpdesk ticket, then choose the best classification, tactic, and mitigation from the dropdowns.

Ticket 1

A user received a convincing email from a supposed business partner referencing the CEO, urging them to review and respond to an attached document. The user opened the attachment and submitted sensitive financial details. The email was later flagged as suspicious, originating from stuart@s3curec0nsultants.com. However the name of the vendor is SecureConsultants.

Explanation: In ticket 1, the user received a convincing email from a supposed business partner referencing the CEO. This is a classic phishing attack, as the attacker tricked the user into opening an attachment and submitting sensitive financial details. The adversary used familiarity tactics by referencing the CEO and urgency by asking the user to act quickly. IT later identified the email as suspicious, coming from stuart@s3curec0nsultants.com. Mitigation should focus on email filtering to reduce the risk of personnel responding to phishing attempts in the future.

Ticket 2

The CFO received an email from the IT department. This email claimed that the CFO's laptop was triggering alerts suggesting malware was trying to steal company data. They were given a link to immediately update their antivirus; however, later the computer started redirecting their browser to strange websites and showing popups.

Ticket 3

A new employee received a call from someone claiming to be an executive, frustrated over a missing fax. They asked the employee to send an internal document immediately and provided their details

Explanation: In ticket 3, a new employee received a call from someone claiming to be an executive. The caller instructed the employee to send a document immediately, creating a sense of authority and urgency. The employee complied and system issues occurred afterward. This is a Vishing attack. IT noted that the attack could have been prevented by verifying the caller’s identity. Mitigation includes caller ID verification to ensure personnel are trained to validate requests before taking action.