WeAreDevelopers LIVE Oct 12, 2020

Getting under the skin: The Social Engineering techniques

Mauro Verderosa

It is notoriously difficult to patch a human. Firewalls fail when employees willingly share keys. Discover how social engineers turn innocent social posts into corporate breaches.

Pause
Mute Enter Fullscreen
#1 about 6 min

How an insider staged a massive historical bank heist

A consultant exploited physical proximity to steal backup procedures and wire out millions before modern cybersecurity.

#2 about 5 min

Motivational categories behind modern cybercriminal activities

Threat actors target organizations for financial gain, corporate espionage, political manipulation, ideological terrorism, and recreational hacking.

#3 about 5 min

Defining social engineering and its monumental historical impact

Hackers leverage psychological manipulation rather than technical exploits to bypass defenses and execute monumental breaches.

#4 about 7 min

Standard attack vectors used in social engineering campaigns

Pretexting, spear phishing, baiting, and tailgating enable adversaries to sneak past digital perimeters without complex exploits.

#5 about 3 min

Weaponizing basic human psychological triggers for system access

Intruders bypass standard access controls by manufacturing artificial situations that elicit panic, guilt, or compliance.

#6 about 2 min

Evaluating phishing emails that leverage artificial time constraints

Email phishing campaigns fake authentic services and invent artificial deadlines to force immediate compliance from victims.

#7 about 3 min

Vishing techniques leveraging synthetic environments and human compassion

Attackers inject synthetic background noise to feign distress and manipulate customer support agents into unlocking critical accounts.

#8 about 2 min

Spear phishing IT administrators with malicious VoIP spoofing

Phone spoofing impersonates internal business lines to coerce privileged IT staff into executing unauthorized administrative payloads.

#9 about 4 min

Sequential lifecycle phases of complex social engineering attacks

A structured compromise advances systematically from open-source intelligence gathering through lateral movement toward footprint obfuscation.

#10 about 6 min

Aggregating disjointed personal details to execute identity theft

Patient mapping of a target's physical routine and social media history yields the requisite answers for password resets.

#11 about 6 min

Defending enterprise perimeters with continuous security awareness training

Combating manipulation requires continuously reshaping organizational culture because standard technological patches cannot adequately fix human vulnerabilities.

Matching moments

3:42 min

Understanding modern social engineering and fraud techniques

George Proorocu George Proorocu +1 · World Congress 2024

2:52 min

Analyzing social engineering exploits in decentralized finance platforms

Chris Heilmann +2 · LIVE

6:36 min

Defensive strategies against AI-driven social engineering

Wolfgang Ettlinger +1 · World Congress 2023

3:23 min

Mitigating social engineering and identifying technical security resources

Vandana Verma · LIVE

3:05 min

Enhancing social engineering and phishing with generative AI

Chris Wysopal Chris Wysopal +2 · World Congress 2024

58 sec

Future realities of AI in social engineering

Wolfgang Ettlinger +1 · World Congress 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 2

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Stage 4

Managing Abuse in the Era of AI Agents

Eli-Shaoul Khedouri

CEO, Intuition Machines

Eli-Shaoul Khedouri
Open session

World Congress 2026 North America

September 24, 2026 · 13:30–14:00

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer, Dokcer

Mark Lechner
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy