2022-11-03 00:00:00

Securitycrime|cyber|engineering|hacker|phishing|social

The most successful cyber attack method is triggered by victims themselves

The nasty thing with social engineering is that the victim falls for a scam, and ultimately helps cyber criminals to achieve their goal. Typically they want to break into a large computer system or simply access the victim's bank account. While computer systems are protected with advanced technology, social engineering has become the most successful method of breaking into mobile devices, computers, and networks.

Recently, Sans Institute and Bishop Fox conducted an insightful survey on cyber security from a fresh perspective. The researchers asked about 300 ethical hackers - security professionals who work as consultants, inspectors and security testers - about their favorite methods and tools for finding problems in clients' computer networks. 83.4% of respondents were based in the US.

I focus on a few key findings of the survey, but you can find the entire report here.

Which attack method is the most likely to succeed?

  • Two attack techniques are clear winners: 32.1% of social engineering attacks succeed and phishing 17.2%.
  • Zero day attacks get plenty of publicity but only 3.8% are successful, but man-in-the-middle attacks are even worse with only 1.4% success rate.
  • So, the easiest way to break into computer systems according to cybersecurity experts is social engineering (phishing is a social engineering technique, after all).
  • The high success rate of social engineering inevitably means that we are going to encounter ever more attempts that try to lure us to do something we shouldn't do. A consequence may be that quite soon we may have to stop clicking all links that we receive via email or a messaging app. Clicking links posted by users on social media services must be avoided as well. It really means that all links must be avoided. Only if we can verify that the content was published by a publication we trust we can follow the link.
  • Another consequence is that we may have stop downloading phone apps that come from sources we don't know or can't verify. Google Play Store and Apple App Store can include tested and verified apps that still feature malware. Recently, security experts discovered 16 apps featuring malware at Google Play that had been downloaded 20 million times.

How long does it take to break in to a target system?

  • About 25% of experts said they can enter a victim's system in 3 or 5 hours.
  • 57% said they can break in within 10 hours.
  • This is good news for individuals and small businesses who are not high profile targets. If your phone, PCs, and routers have solid basic protection up-to-date and active, hackers won't spend much time knocking on your door. They will quickly move on to the next target. Here are more tips for securing the basic things.
  • I have followed on a server console when hackers are trying to break in to our content management system where we publish our articles. A typical scenario is that they try to break in for a few minutes, maximum for an hour, and move on. Even though the attacks tend to be automated, they don't last long once they realize it won't be easy to get in.

64% of experts say they can quietly hoover data from the victim's system in less than five hours after they have managed to break in. 41% only need two hours or even shorter time to access the data.


In a fast attack scenario, cyber criminals may break in, copy the data, and perhaps lock it down for ransom in a couple of hours. Other type of attackers may choose to stay in a target system quietly, waiting for commands to be executed later. So, not to let anyone in is the objective for every organization and individual who is planning to protect data and devices.

The internet, email or social media is not going away because of serious cyber crime problems. What is going to end is our current careless behavior in the digital world. Too many cyber attacks succeed because victims help attackers to get in. Social engineering works. It has to end. We have to learn safer ways to behave in the digital world.

The Register reported about the research.

Header image by Gerd Altmann.

News

2025-07-01 16:15:00

Canyon road is a magnet for cyclists and motorists.#photography #travelphotography #europeflic.kr/p/2rdW4Mfhttps://flic.kr/p/2rdW4Mf


The historic center of Krakow in Poland features castles, churches, palaces ... and tourists.

2025-06-23 13:31:04

The historic center of Krakow in Poland features castles, churches, palaces ... and tourists.


A man with his donkey.

2025-06-19 15:54:21

arihak

A man with his donkey.


News

2025-06-19 15:11:00

An eye-catching place for a painting.#streetphotographyhttps://wordpress.org/photos/photo/9536554ee4/


News

2025-06-15 15:33:00

There are many ways to classify the best countries for road trips, and that is why we are going to take a look at a few different types of ways to select the best here. #roadtrip #Europehttps://klaava.com/which-countries-in-europe-are-the-best-for-road-trips/


News

2025-06-11 16:24:00

Let's go.#streetphotographyflic.kr/p/2r3EuJNhttps://flic.kr/p/2r3EuJN


News

2025-06-04 18:08:00

A #photographer has been using sunglasses with a camera and loudspeakers for 8 months: "I quite enjoy them, and they’ve quickly become my daily wear as far as sunglasses are concerned."https://fstoppers.com/artificial-intelligence/ray-ban-meta-glasses-photographers-perspective-701899


News

2025-06-02 14:42:00

Today, digital nomads recognize the benefits but also risks of their lifestyle. An extensive study among traveling workers reveals the highs and lows of the nomad life. #remotework #digitalnomadhttps://klaava.com/digital-nomads-feel-powered-by-their-lifestyle-but-recognise-inevitable-downsides-as-well/


Aland archipelago

2025-05-30 16:59:41

Aland archipelago


Highway across a swamp.

2025-05-30 11:14:51

arihak

Highway across a swamp.


News

2025-05-26 16:29:00

Flower market, but she is selling fruit trees.#streetphotographyhttps://unsplash.com/photos/TfQ6uYmI9QQ


News

2025-05-22 14:19:00

In Spain, the Balearic government asked influencers to help ease pressure on overcrowded hotspots by promoting less-visited areas. Instead, influencers have unintentionally drawn large crowds of tourists to remote, ecologically sensitive locations. #photography #selfiehttps://petapixel.com/2025/05/21/spanish-islands-ban-influencers-after-4000-tourists-flock-to-tiny-beach-for-selfies/


News

2025-05-18 18:23:00

Most travelers already knew that south Europe is the warm and sunny zone of #Europe, and this ranking confirms it. Spain and Italy have most cities in the top 30, followed by France and Portugal. #travelhttps://klaava.com/sunniest-cities-in-europe/


Popular sight in Sevilla

2025-05-16 17:51:34

Popular sight in Sevilla


News

2025-05-14 16:03:00

Bordeaux is ready for hot summer days.#streetphotographyhttps://pixelfed.social/p/arihak/827854641319295061


Cooling zone.

2025-05-13 12:38:47

arihak

Cooling zone.


Hochosterwitz castle

2025-05-10 15:23:05

Hochosterwitz castle


News

2025-05-07 14:39:00

A meeting in winter sun.#streetphotography #travelphotographyflic.kr/p/2qey2NHhttps://flic.kr/p/2qey2NH


News

2025-04-30 17:01:00

Shady character.#streetphotography #travelphotography #StreetPhotography


Not in space, but firmly on the ground in Valencia.

2025-04-25 17:47:30

arihak

Not in space, but firmly on the ground in Valencia.