Phishing receives the overwhelming share of awareness training, and that is reasonable given its volume. But attackers use whichever channel works, and several of the most effective techniques never touch email at all. The help desk in particular has become a favoured route, because it is designed to be helpful to people who cannot access their accounts.
The channels in use
- Vishing (voice) — a phone call impersonating IT support, a supplier or an executive. Voice conveys urgency and authority far more effectively than text, and leaves no artefact to analyse afterwards.
- Smishing (SMS) — text messages carrying a link or a request, often exploiting the fact that mobile interfaces make it harder to inspect a destination.
- Pretexting — constructing a plausible scenario and identity in advance, then sustaining it across several interactions to build credibility before the actual request.
- Help-desk manipulation — persuading support staff to reset a password or register a new MFA device, which bypasses even strong authentication entirely.
- Physical entry — tailgating, or arriving as a contractor, delivery driver or auditor with enough props to look routine.
- Removable media — leaving devices where curiosity will do the rest.
- Multi-channel combinations — an email that mentions a follow-up call, then the call arriving as promised, which makes both far more credible than either alone.
Why the help desk is targeted
A help desk is measured on speed and satisfaction, staffed by people trained to be accommodating, and exists precisely to assist users who cannot authenticate. That combination is exactly what a social engineer needs.
The attacker typically has partial genuine information — a real name, job title, manager and start date, assembled from public sources — which makes the request feel legitimate. Where verification relies on details of that kind, it verifies nothing.
Verification that actually verifies
- Never accept knowledge-based answers that appear on professional networking profiles, company websites or public records.
- Use a callback to a number already held in the HR record, never a number supplied during the interaction.
- Require manager approval, initiated through a separate channel, for high-risk actions such as MFA re-registration.
- For sensitive resets, use an in-person or video check against a known photograph where practical.
- Introduce a deliberate delay for the highest-risk requests. Urgency is the attacker's primary tool, and a mandatory pause removes it.
- Give staff explicit authority to refuse and escalate without fear of a complaint — a policy that makes people afraid of being unhelpful is a policy that will be bypassed.
- Log and review resets and MFA registrations as security events rather than routine tickets.
Making training realistic
Annual slide-based awareness training has limited effect on these techniques. What helps is exposure to realistic scenarios in the relevant channel, aimed at the roles most likely to be targeted — help desk, finance, HR and executive assistants.
Simulated calls are far more instructive than simulated emails for this purpose, though they need careful design and clear internal authorisation. The objective is not to catch people out; a programme that humiliates staff produces concealment rather than reporting, which is the opposite of what you need.
Reporting is the real metric
The most useful measure is not how many people were fooled but how quickly an attempt gets reported, because a single report lets defenders warn everyone else while the campaign is still running.
That requires reporting to be effortless, acknowledged, and never punished — including when the person already clicked, answered, or approved. People who fear consequences delay reporting, and delay is what converts an attempted attack into a successful one.
Related from TechBiz Security
Sources & further reading
- CISA — Avoiding Social Engineering and Phishing Attacks
- CISA — Phishing Guidance: Stopping the Attack Cycle at Phase One
- NIST SP 800-50 — Building an Information Technology Security Awareness Program
- MITRE ATT&CK
0 comments
Leave a comment