2022-11-03 00:00:00

Securitycrime|cyber|engineering|hacker|phishing|social

The most successful cyber attack method is triggered by victims themselves

The nasty thing with social engineering is that the victim falls for a scam, and ultimately helps cyber criminals to achieve their goal. Typically they want to break into a large computer system or simply access the victim's bank account. While computer systems are protected with advanced technology, social engineering has become the most successful method of breaking into mobile devices, computers, and networks.

Recently, Sans Institute and Bishop Fox conducted an insightful survey on cyber security from a fresh perspective. The researchers asked about 300 ethical hackers - security professionals who work as consultants, inspectors and security testers - about their favorite methods and tools for finding problems in clients' computer networks. 83.4% of respondents were based in the US.

I focus on a few key findings of the survey, but you can find the entire report here.

Which attack method is the most likely to succeed?

  • Two attack techniques are clear winners: 32.1% of social engineering attacks succeed and phishing 17.2%.
  • Zero day attacks get plenty of publicity but only 3.8% are successful, but man-in-the-middle attacks are even worse with only 1.4% success rate.
  • So, the easiest way to break into computer systems according to cybersecurity experts is social engineering (phishing is a social engineering technique, after all).
  • The high success rate of social engineering inevitably means that we are going to encounter ever more attempts that try to lure us to do something we shouldn't do. A consequence may be that quite soon we may have to stop clicking all links that we receive via email or a messaging app. Clicking links posted by users on social media services must be avoided as well. It really means that all links must be avoided. Only if we can verify that the content was published by a publication we trust we can follow the link.
  • Another consequence is that we may have stop downloading phone apps that come from sources we don't know or can't verify. Google Play Store and Apple App Store can include tested and verified apps that still feature malware. Recently, security experts discovered 16 apps featuring malware at Google Play that had been downloaded 20 million times.

How long does it take to break in to a target system?

  • About 25% of experts said they can enter a victim's system in 3 or 5 hours.
  • 57% said they can break in within 10 hours.
  • This is good news for individuals and small businesses who are not high profile targets. If your phone, PCs, and routers have solid basic protection up-to-date and active, hackers won't spend much time knocking on your door. They will quickly move on to the next target. Here are more tips for securing the basic things.
  • I have followed on a server console when hackers are trying to break in to our content management system where we publish our articles. A typical scenario is that they try to break in for a few minutes, maximum for an hour, and move on. Even though the attacks tend to be automated, they don't last long once they realize it won't be easy to get in.

64% of experts say they can quietly hoover data from the victim's system in less than five hours after they have managed to break in. 41% only need two hours or even shorter time to access the data.


In a fast attack scenario, cyber criminals may break in, copy the data, and perhaps lock it down for ransom in a couple of hours. Other type of attackers may choose to stay in a target system quietly, waiting for commands to be executed later. So, not to let anyone in is the objective for every organization and individual who is planning to protect data and devices.

The internet, email or social media is not going away because of serious cyber crime problems. What is going to end is our current careless behavior in the digital world. Too many cyber attacks succeed because victims help attackers to get in. Social engineering works. It has to end. We have to learn safer ways to behave in the digital world.

The Register reported about the research.

Header image by Gerd Altmann.

News

2025-05-14 16:03:00

Bordeaux is ready for hot summer days.#streetphotographyhttps://pixelfed.social/p/arihak/827854641319295061


Hochosterwitz castle

2025-05-10 15:23:05

Hochosterwitz castle


News

2025-05-07 14:39:00

A meeting in winter sun.#streetphotography #travelphotographyflic.kr/p/2qey2NHhttps://flic.kr/p/2qey2NH


News

2025-04-30 17:01:00

Shady character.#streetphotography #travelphotography #StreetPhotography


Not in space, but firmly on the ground in Valencia.

2025-04-25 17:47:30

arihak

Not in space, but firmly on the ground in Valencia.


News

2025-04-24 15:17:00

According to a survey, football (a sport where you are supposed to kick the ball instead touching the ball with a hand) is the most popular sports that fans want to follow live on site even if it means traveling overseas. #travelhttps://klaava.com/sports-events-are-trending-among-travelers/


News

2025-04-23 14:19:00

An unexpected recognition for analog #photography : UNESCO Cultural Heritage designation suggests a renewed appreciation for the craftsmanship and cultural significance of analog methods.https://www.diyphotography.net/analog-photography-recognized-as-intangible-cultural-heritage-by-unesco/


News

2025-04-17 13:18:00

New restriction on Flickr #photo sharing: Free #Flickr accounts will be restricted from downloading original and large-size images. While users will still be able to upload photos of all sizes, free account holders will only be able to download medium and small photos.https://petapixel.com/2025/04/16/flickr-restricting-download-sizes-for-free-accounts/


News

2025-04-16 10:54:00

Morning commute.#streetphotography#travelphotography


News

2025-04-12 09:17:00

The region in #Europe where you will get more #travel days for your euro (or whatever the local currency happens to be). The difference in the average cost is vast between the cheapest and the most expensive European countries.https://klaava.com/here-are-the-cheapest-countries-to-travel-in-europe/


Looks like a perfect spot for a cat to observe the street but no one was home when I passed the window.

2025-04-10 13:35:48

arihak

Looks like a perfect spot for a cat to observe the street but no one was home when I passed the window.


News

2025-04-07 08:50:00

When you take a #photo in RAW format the file is filled with extra data that allows for much richer post-processing, but the #camera world has never actually settled on one standardized RAW format.https://www.theverge.com/tech/640119/camera-raw-spec-format-explained-adobe-dng-canon-nikon-sony-fujifilm


News

2025-04-01 08:39:00

YouTube was the second-biggest media company in the world last year.And in 2025, #YouTube should eclipse #Disney, and become the biggest #media company in the world.https://www.businessinsider.nl/youtube-is-about-to-eclipse-disney-as-the-biggest-media-company-in-the-world/


News

2025-03-28 08:36:00

World Press Photo Contest 2025 ​have just been announced. This year, according to organizers, 59,320 images were submitted for judging, made by 3,778 photographers. #photographyhttps://www.theatlantic.com/photo/2025/03/winners-2025-world-press-photo-contest/682180/


Look around, and love your phone later

2025-03-22 10:17:39

arihak

Look around, and love your phone later


News

2025-03-21 12:50:00

An ancient football stadium?#streetphotography


News

2025-03-11 13:32:00

The World Photography Organisation has announced the category winners and shortlisted photographers for the Sony World #Photography Awards 2025 Open competition.https://www.dpreview.com/articles/0086546939/sony-world-photography-awards-2025-category-winners


News

2025-03-06 16:56:00

Coffee break.#streetphotography


News

2025-02-27 08:22:00

The Sony World #Photography Organisation unveiled the shortlisted entries and finalists in its annual competition’s 10 professional categories.https://edition.cnn.com/2025/02/25/style/sony-world-photography-awards-professional-2025/index.html


Summer heat.

2025-02-26 17:06:07

arihak

Summer heat.