Tips: Watch Out For Criminal Social Engineers

Halock Security Labs, an information security organization, warns all companies with a physical location and Internet presence to make sure security policies and procedures are strictly enforced during the holidays, because criminal social engineers are out shopping for others' confidential data. Offices are particularly vulnerable in times of increased social activity, like the holidays, because employees are accustomed to seeing new faces, new vendors, receiving many e-mail solicitations and disclosing personal financial information online while shopping.

Halock specializes in ethical hacking and social engineering -- at a client's request, to test a company's physical and Internet vulnerabilities. In one recent instance, a Halock employee was able to enter the corporate headquarters of one of the country's largest financial institutions and gain almost complete access to the company's sensitive data simply because he was carrying a cake.

"When asked what he was doing, our man simply said. 'I have cake,' and nobody wants to impede the progress of a nice looking cake -- right?!" said Jeremy Simon, Halock's CTO.

"Social engineering is typically defined as the skillful exploitation of the natural human tendency to trust. This engineering can come through an actual physical interaction, through an e-mail, as in phishing schemes or online, through falsified websites. The criminal social engineer is out to con someone into giving up credentials that can ultimately be used to generate or gain access to sensitive information," said Terry Kurzynski, CEO, Halock Security Labs. "And during the holidays companies are inundated with strange names and faces in the form of guests, delivery people, greeting cards, special offer Web sites -- the list is endless. Some of these guests are quite unwelcome," he adds.

What can a company do to make sure that they don't inadvertently let the Grinch spoil Christmas?

Here are a few techniques that Halock Security Labs recommends:

  • Stick to your policies and procedures. Carefully track visitors coming and going into your facility. If you don't recognize someone or they are not displaying the correct badge or ID, ask them their purpose and who they are working with. It will become clear if they belong within the walls of your organization.
  • If your organization has a clean desk policy and/or a system lock policy for unattended systems, be sure to enforce those policies. Shred documents that contain confidential or sensitive data. This goes for home and work. Identity thieves pray off of the garbage can. Criminals that have socially engineered their way into an organization will be looking for low hanging fruit including paper documents or systems left unattended. They may try to quickly install a malware program on systems left unlocked and potentially gain administrative rights remotely to that machine.
  • As for your online shopping this holiday season, be sure to locate the little picture of a lock the on bottom of Web pages whenever you provide private information, including credit card numbers, name and address. Be especially careful of phishing attempts to get your password, social security number, account number, or credit card number based on an e-mail that has arrived in your inbox. Never click on hyperlinks in e-mails unless the message comes from a trusted source (and even then, be careful.) And don't ever give out your password, credit card number or social security number via e-mail.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.