> Markdown version of [/videos/38-getting-under-the-skin-the-social-engineering-techniques?t=1693](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques?t=1693). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Getting under the skin: The Social Engineering techniques It is notoriously difficult to patch a human. Firewalls fail when employees willingly share keys. Discover how social engineers turn innocent social posts into corporate breaches. - **Speakers:** Mauro Verderosa - **Event:** WeAreDevelopers LIVE - **Published:** October 12, 2020 - **Duration:** 43:56 - **URL:** https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques ## Summary Social engineering exploits human psychology rather than software vulnerabilities, leaning on the reality that "it is really difficult to patch a human." From the 1978 wire transfer heist by Mark Rifkin at Security Pacific National Bank to modern corporate breaches involving RSA and Sony, threat actors continuously manipulate personnel to bypass traditional security perimeters. By understanding attacker motivations—ranging from financial theft to ideological disruption—security teams can better contextualize the specific tactics deployed against their organizations.\n\nThe narrative breaks down discrete attack methodologies including pretexting, diversion theft, spear-phishing, whaling, vishing (voice phishing), and baiting. Attackers manufacture urgency, leverage compassion, or exploit greed to compel targets into downloading trojans or openly sharing credentials. A successful attack routinely follows distinct phases: initial reconnaissance (scraping social networks for behavioral patterns), scanning, lateral movement, data exfiltration, and final obfuscation to erase digital footprints. Remarkably, attackers operate on the premise that a microscopic success rate (even 0.001%) on bulk phishing campaigns is sufficient to breach an organization.\n\nReal-world case studies demonstrate how seemingly innocuous details—a pet's name, a geo-tagged restaurant post, or background noise on a phone call—are aggregated to compromise high-value operational accounts. Technical firewalls cannot prevent unauthorized access if personnel willingly hand over administrative keys under emotional duress. Mitigating these risks requires organizations to pivot toward continuous, scenario-based security awareness training, transforming unaware employees from vulnerable targets into active defenders who instinctively verify anomalous requests. **Keywords:** social engineering techniques, psychological manipulation attacks, security awareness training, spear-phishing vulnerabilities, whaling attack vectors, vishing and smishing tactics, pretexting methodologies, lateral movement defense, data exfiltration mitigation, human attack surface, threat actor motivations, credential theft pathways, open source intelligence reconnaissance, social media privacy risks, multi-factor authentication bypass ## Chapters 1. **How an insider staged a massive historical bank heist** (00:19) — A consultant exploited physical proximity to steal backup procedures and wire out millions before modern cybersecurity. 1. **Motivational categories behind modern cybercriminal activities** (06:04) — Threat actors target organizations for financial gain, corporate espionage, political manipulation, ideological terrorism, and recreational hacking. 1. **Defining social engineering and its monumental historical impact** (10:38) — Hackers leverage psychological manipulation rather than technical exploits to bypass defenses and execute monumental breaches. 1. **Standard attack vectors used in social engineering campaigns** (15:14) — Pretexting, spear phishing, baiting, and tailgating enable adversaries to sneak past digital perimeters without complex exploits. 1. **Weaponizing basic human psychological triggers for system access** (21:54) — Intruders bypass standard access controls by manufacturing artificial situations that elicit panic, guilt, or compliance. 1. **Evaluating phishing emails that leverage artificial time constraints** (24:19) — Email phishing campaigns fake authentic services and invent artificial deadlines to force immediate compliance from victims. 1. **Vishing techniques leveraging synthetic environments and human compassion** (25:49) — Attackers inject synthetic background noise to feign distress and manipulate customer support agents into unlocking critical accounts. 1. **Spear phishing IT administrators with malicious VoIP spoofing** (28:13) — Phone spoofing impersonates internal business lines to coerce privileged IT staff into executing unauthorized administrative payloads. 1. **Sequential lifecycle phases of complex social engineering attacks** (29:39) — A structured compromise advances systematically from open-source intelligence gathering through lateral movement toward footprint obfuscation. 1. **Aggregating disjointed personal details to execute identity theft** (33:03) — Patient mapping of a target's physical routine and social media history yields the requisite answers for password resets. 1. **Defending enterprise perimeters with continuous security awareness training** (38:53) — Combating manipulation requires continuously reshaping organizational culture because standard technological patches cannot adequately fix human vulnerabilities. ## Related Moments - [Understanding modern social engineering and fraud techniques](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) (from "Deep Fakes: The Lies We Can’t See") - [Analyzing social engineering exploits in decentralized finance platforms](https://www.wearedevelopers.com/videos/1841-wearedevelopers-live-bitpanda-s-ai-first-approach) (from "WeAreDevelopers LIVE - Bitpanda’s AI First Approach") - [Defensive strategies against AI-driven social engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) (from "Skynet wants your Passwords! The Role of AI in Automating Social Engineering") - [Mitigating social engineering and identifying technical security resources](https://www.wearedevelopers.com/videos/376-walking-into-the-era-of-supply-chain-risks) (from "Walking into the era of Supply Chain Risks") - [Enhancing social engineering and phishing with generative AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) (from "WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI") - [Future realities of AI in social engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) (from "Skynet wants your Passwords! The Role of AI in Automating Social Engineering") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) ## Related Jobs - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/293774-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Senior Threat Intelligence Analyst](https://www.wearedevelopers.com/jobs/ext/1684162-senior-threat-intelligence-analyst) at **ZEISS Group** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Security Engineer](https://www.wearedevelopers.com/jobs/ext/1574416-security-engineer) at **Twilio** - [Senior Threat Intelligence Analyst](https://www.wearedevelopers.com/jobs/ext/2000909-senior-threat-intelligence-analyst) at **ZEISS Group**