Social Engineering Attacks
Social engineering attacks are based on the exploitation of someone's personality; they could be referred to as hacking the human. There are various types of social engineering attacks. Let's look at each of them in turn, starting with phishing/spear phishing:
- Phishing and Spear Phishing: Phishing attacks are carried out by emailing someone, requesting that they need to complete the attached form, perhaps as there is a problem with their bank account. Such forms ask for personal details that could later be used for identity fraud. Such emails often look as though they have come from a legitimate body, so users are fooled into carrying out the instructions they contain. Spear phishing is a phishing attack that targets a group of people:
Figure 9.2 – Phishing attack
- Credential Harvesting: This is an attack that is normally done using a phishing attack, where it states that some details on your account...