Evolution of Social Engineering Scams: From Past to Present

Evolution of Social Engineering Scams: From Past to Present

Social engineering scams have undergone significant transformations over the years, adapting to technological advancements and exploiting the vulnerabilities of social networks. Understanding the evolution of these scams is crucial for staying vigilant and protecting oneself against modern-day threats. Let’s explore the changing landscape of social engineering scams on social networks, from their early days to the present:

1. The Fake Friend: Early Days
In the early days of social networks, Emily received a friend request from a seemingly familiar face. The profile claimed to be her childhood friend, but something felt off. Ignoring her instincts, Emily accepted the request. Over time, the “friend” started asking personal questions and eventually requested money due to an emergency. Emily, blinded by nostalgia, wired the funds only to realize she had fallen victim to a classic impersonation scam.

2. The Nigerian Prince: Transition Phase
John received an email claiming he was the beneficiary of a deceased Nigerian prince’s fortune. Intrigued, he replied, and the scammer requested a small fee to release the funds. In the transition to online scams, John sent the fee, only to receive more requests for money. The promise of riches remained elusive, and John learned a costly lesson in advance fee fraud.

3. The Clickbait Survey: Transitional Phase
Sophia received a message promising a lucrative reward for participating in an online survey. She eagerly clicked the link, which led to a seemingly legitimate website. After completing the survey, she was asked for personal information. Not long after, her inbox was flooded with spam emails, and her computer began behaving strangely—Sophia had fallen victim to a clickbait-driven malware attack.

Google and Its Chinese Hackers

In the beginning of 2010, Google made the headlines and revealed that Chinese hackers were able to breach a part of its system. Google claimed that some of its services were breached and that the perpetrators wanted to obtain access to Chinese human rights activists through their Gmail accounts.

Apart from Google, these social engineers also targeted other prominent companies, including Symantec, Adobe Systems, and Yahoo. The success of the social engineers was due to spending weeks and even months of scouting and targeting Google employees in order to obtain information. They began by using the information of employees found in social networks and other places.

Once they got the necessary information, the social engineers sent messages to the employees that appeared legitimate and coming from a friend or contact. Thinking that the message truly came from their friends, the employees clicked on the links embedded with malware, resulting to the installation of spyware on their computers. This attack on Google was planned and carried out for a considerable period.

The social engineers took their time in gathering information and winning the confidence of the employees so that they could interact and elicit information. Given that most companies make use of social networks as a part of the marketing strategy, social engineers find it easier to gather information about their targets. Apart from conveying their marketing tactics through social media, companies also expose their company structure, making the information needed by social engineers readily available.

4. The Bank Impersonator: Recent Past
Alex received an urgent email claiming to be from his bank, stating that his account had been compromised. The email contained a link to a login page where Alex was asked to provide his account details to “verify” his identity. Concerned, he complied, unknowingly handing over his credentials to a phishing scam. Soon after, his bank account was emptied.

5. The CEO’s Request: Recent Past
In the midst of a busy workday, Sarah received an email from her CEO requesting an urgent wire transfer to a new vendor. The email seemed legitimate, and Sarah, eager to please, initiated the transfer without confirming the request’s authenticity. Unbeknownst to her, the email was a result of a spear phishing attack, and the money ended up in the hands of scammers.

6. The Deepfake Influencer: Current Trends
Michelle, an aspiring content creator, received a message from her favorite social media influencer, offering her a chance to collaborate on a viral campaign. The influencer sent a video message discussing the project, but something felt off about their tone. Unbeknownst to Michelle, the video was a deepfake, and the subsequent partnership led to her sharing sensitive information and unknowingly promoting a scam.

Information Exposure on Wikileaks

Again, in 2010, highly classified government information was exposed on Wikileaks with the successful ploy of social engineers. Bradley Manning, a U.S. Army soldier who was then assigned to a support battalion in Iraq, was accused of providing classified information to the founder of Wikileaks, Julian Assange.

Having access to the Secret Internet Protocol Router Network, which was used by the U.S. Department of State and Department of Defense for transmitting classified information, Manning was able to obtain the material. Meanwhile, Adrian Lamo, a former hacker, reported Manning to the authorities, telling the officials that Manning downloaded the material from SIPRNet and saving it on CD-RWs.

Manning was allegedly successful in fooling his colleagues that he was merely listening to music instead of accessing and downloading classified information. Manning carried out his ploy by coming in with music on a CD-RW with a label, such as “Lady Gaga.” He erased the music, overwriting it with a compressed split file. Manning told Lamo in an online chat that nobody from his colleagues suspected anything as he listened and even lip-synched Lady Gaga’s song, Telephone.

While doing this, he “exfiltrated” probably the most magnanimous information spillage in the history of the United States. Manning was able to play on the trust of his colleagues while keeping his cool. A social engineer like Manning is ruthless as he knew his action may result in a court martial, yet still pushed through with it. Following the exposure of highly classified information on Wikileaks, other social engineers took advantage and sent out messages with a pickup line, “Do you want to read the file on Wikileaks? Click here.”

Once users clicked on the link, it led them to a pdf file that allowed the social engineers to search the computer through a Javascript, determine the Adobe reader version on the computer, and launched their exploitation for such version. The victims did not mind if the pdf took time to load as they were expecting a huge document. However, they also did not know that it was not the document that took time to load, but the malware, which the social engineers embedded.

7. The Emotional Blackmail: Current Trends
David received a distressing message claiming his account had been compromised and embarrassing photos would be leaked unless he paid a ransom. Fearful of the consequences, David complied, only to realize that the photos never existed. The scammer had preyed on his emotions, using fear as a powerful tool to manipulate him.

8. The Celebrity Endorsement: Current Trends
Ella received a direct message from a verified account belonging to a famous celebrity. The message claimed Ella had won a cash prize in a contest and needed to provide her banking details to claim the reward. Thrilled by the opportunity, Ella eagerly shared her information, only to later discover that the celebrity’s account had been hacked, and she had fallen for an impersonation scam.

9. The Online Romance: Ongoing Threat
Mike, a divorced middle-aged man, met Jane on a social networking site. They quickly formed a deep connection, sharing intimate details about their lives. Jane gradually revealed a financial crisis and asked Mike for a loan. Blinded by love, Mike sent the money, only to find out that “Jane” was a scammer who had used a fake profile and a carefully crafted persona to exploit his emotions.

10. The Infiltrated Group: Ongoing Threat
Lisa was a member of a popular online group that shared common interests. One day, a new member joined and began building relationships with group members. Over time, the new member gained trust and subtly introduced investment opportunities that promised high returns. Several members invested significant amounts of money, only to realize they had fallen victim to an elaborate Ponzi scheme.

These stories reflect the ever-evolving tactics employed by social engineering scammers on social networks. As technology advances, scammers continue to adapt their strategies, making it crucial for individuals to remain vigilant and informed to protect themselves from these manipulative schemes.

Total
0
Shares

Leave a Reply

Previous Post
Social Engineering: Exploiting Psychology for Manipulation and Intrusion

Social Engineering: Exploiting Psychology for Manipulation and Intrusion

Next Post
How to prepare Policy and Plans for Incident Management

How to prepare Policy and Plans for Incident Management

Related Posts