WeAreDevelopers LIVE Oct 12, 2020

Getting under the skin: The Social Engineering techniques

Mauro Verderosa

It is notoriously difficult to patch a human. Firewalls fail when employees willingly share keys. Discover how social engineers turn innocent social posts into corporate breaches.

Pause
Mute Enter Fullscreen
#1 about 6 min

How an insider staged a massive historical bank heist

A consultant exploited physical proximity to steal backup procedures and wire out millions before modern cybersecurity.

#2 about 5 min

Motivational categories behind modern cybercriminal activities

Threat actors target organizations for financial gain, corporate espionage, political manipulation, ideological terrorism, and recreational hacking.

#3 about 5 min

Defining social engineering and its monumental historical impact

Hackers leverage psychological manipulation rather than technical exploits to bypass defenses and execute monumental breaches.

#4 about 7 min

Standard attack vectors used in social engineering campaigns

Pretexting, spear phishing, baiting, and tailgating enable adversaries to sneak past digital perimeters without complex exploits.

#5 about 3 min

Weaponizing basic human psychological triggers for system access

Intruders bypass standard access controls by manufacturing artificial situations that elicit panic, guilt, or compliance.

#6 about 2 min

Evaluating phishing emails that leverage artificial time constraints

Email phishing campaigns fake authentic services and invent artificial deadlines to force immediate compliance from victims.

#7 about 3 min

Vishing techniques leveraging synthetic environments and human compassion

Attackers inject synthetic background noise to feign distress and manipulate customer support agents into unlocking critical accounts.

#8 about 2 min

Spear phishing IT administrators with malicious VoIP spoofing

Phone spoofing impersonates internal business lines to coerce privileged IT staff into executing unauthorized administrative payloads.

#9 about 4 min

Sequential lifecycle phases of complex social engineering attacks

A structured compromise advances systematically from open-source intelligence gathering through lateral movement toward footprint obfuscation.

#10 about 6 min

Aggregating disjointed personal details to execute identity theft

Patient mapping of a target's physical routine and social media history yields the requisite answers for password resets.

#11 about 6 min

Defending enterprise perimeters with continuous security awareness training

Combating manipulation requires continuously reshaping organizational culture because standard technological patches cannot adequately fix human vulnerabilities.

Matching moments

3:42 min

Understanding modern social engineering and fraud techniques

George Proorocu George Proorocu +1 · WWC 2024

2:52 min

Analyzing social engineering exploits in decentralized finance platforms

Chris Heilmann +2 · LIVE

6:36 min

Defensive strategies against AI-driven social engineering

Wolfgang Ettlinger +1 · WWC 2023

3:23 min

Mitigating social engineering and identifying technical security resources

Vandana Verma · LIVE

3:05 min

Enhancing social engineering and phishing with generative AI

Chris Wysopal Chris Wysopal +2 · WWC 2024

58 sec

Future realities of AI in social engineering

Wolfgang Ettlinger +1 · WWC 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed