{"id":41259,"date":"2020-08-20T16:38:14","date_gmt":"2020-08-20T23:38:14","guid":{"rendered":"https:\/\/www.enxmag.com\/twii\/?p=41259"},"modified":"2020-08-20T16:38:17","modified_gmt":"2020-08-20T23:38:17","slug":"the-most-effective-attacks-are-often-the-simplest","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/editors-blog\/2020\/08\/the-most-effective-attacks-are-often-the-simplest\/","title":{"rendered":"The Most Effective Attacks Are Often the Simplest"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img loading=\"lazy\" width=\"296\" height=\"202\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2020\/08\/KnowBe4.jpg\" alt=\"\" class=\"wp-image-41260\" srcset=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2020\/08\/KnowBe4.jpg 296w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2020\/08\/KnowBe4-160x110.jpg 160w\" sizes=\"(max-width: 296px) 100vw, 296px\" \/><\/figure><\/div>\n\n\n\n<p>The recent Twitter hack shows that devastating security breaches don\u2019t always involve sophisticated actors or methods, according to Rachel  Tobac, CEO of SocialProof Security. On the CyberWire\u2019s Hacking Humans podcast, Tobac explained that social engineering only requires an attacker to trick an employee into doing something.<\/p>\n\n\n\n<p>\u201cThat&#8217;s like a knee-jerk first reaction, is the word sophisticated is used in almost every press release \u2013 a sophisticated actor. I think we saw that in the case of the Twitter announcement as well \u2013 a  coordinated, sophisticated social engineering attack,\u201d Tobac said. \u201cAnd while it was coordinated \u2013 they did likely coordinate on Discord from what we&#8217;re seeing \u2013 it doesn&#8217;t necessarily mean it&#8217;s sophisticated. Social engineering somebody and calling to gain access to credentials while pretexting or pretending to be IT support, I wouldn&#8217;t call that sophisticated. The things that I do are interesting, but I wouldn&#8217;t say  they&#8217;re so hard that the average person couldn&#8217;t do them.\u201d<\/p>\n\n\n\n<p>Tobac also noted that the hack could have been much worse if the hacker hadn\u2019t simply been a teenager interested in running a Bitcoin scam.<\/p>\n\n\n\n<p>\u201cIf I were a real malicious person, I&#8217;d probably try and start World  War III,\u201d she said. \u201cI would take over accounts for, you know, leaders across the world and have them fight with each other and really escalate that. If I were really malicious, that&#8217;s probably what I would do. Now,  of course, it&#8217;s malicious to take over accounts, but it&#8217;s not that level of maliciousness where they&#8217;re trying to incite violence or war.  It&#8217;s just, I&#8217;m looking to get some money quick. That points to more  teenager behavior, and there were a couple other things that showed that  it was more in the teenager direction rather than the APT direction.\u201d<\/p>\n\n\n\n<p>Tobac concluded that the incident shows the importance of a  defense-in-depth strategy. Training is important, but organizations also need protocols and technical defenses to minimize the chances of a  successful attack.<\/p>\n\n\n\n<p>\u201cThere are so many things that we need,\u201d Tobac said. \u201cWe need to make sure that we have protocols in place &#8211; you know, maybe, like, two eyes or four eyes to make sure that two people are able to make that request before it goes through. Like, for instance, can you imagine if you had  to get two Twitter employees to say, sure, we&#8217;ll change the email on  former President Barack Obama&#8217;s account before actually having it go  through?\u201d<\/p>\n\n\n\n<p>Tobac added that the Twitter incident shows that organizations will never be in a place where they can relax when it comes to security.<\/p>\n\n\n\n<p>\u201cIt&#8217;s very possible that they were doing all of the suggestions that I  recommended, and it still didn&#8217;t work,\u201d she said. \u201cSo I can&#8217;t really comment to that, but I can say that we know many organizations out there do not take these steps. They might not have hardware MFA. They might not have social engineering training with up-to-date examples of how exactly it happens, not just over email but also over the phone, which is a big limitation of a lot of trainings now, and also making sure that  we have all of the technical tools to backup if a person inevitably makes a mistake, which is, of course, bound to happen. Twitter might have been doing this. They might not have. But we do know that it&#8217;s a  learning point for every organization, regardless of whether or not they&#8217;re currently doing it. So just keep it up.\u201d<\/p>\n\n\n\n<p>New-school <a rel=\"noreferrer noopener\" href=\"http:\/\/knowbe4.com\/security-awareness-training\" target=\"_blank\">security awareness training<\/a> can give your organization an essential layer of defense by teaching your employees about social engineering and instilling in them the importance of following security protocols.<\/p>\n\n\n\n<p><em>This blog originally appeared on <\/em><a href=\"http:\/\/knowbe4.com\"><em>KnowBe4<\/em><\/a><em>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recent Twitter hack shows that devastating security breaches don\u2019t always involve sophisticated actors or methods, according to Rachel Tobac, CEO of SocialProof Security. On the CyberWire\u2019s Hacking Humans podcast, Tobac explained that social engineering only requires an attacker to trick an employee into doing something. \u201cThat&#8217;s like a knee-jerk first reaction, is the word sophisticated is used in almost every press release \u2013 a sophisticated actor. I think we saw that in the case of the Twitter announcement as well \u2013 a coordinated, sophisticated social engineering attack,\u201d Tobac said. \u201cAnd while it was coordinated \u2013 they did likely coordinate on Discord from what we&#8217;re seeing \u2013 it doesn&#8217;t necessarily mean it&#8217;s sophisticated. Social engineering somebody and calling to gain access to credentials while pretexting or pretending to be IT support, I wouldn&#8217;t call that sophisticated. The things that I do are interesting, but I wouldn&#8217;t say they&#8217;re so hard that the average person couldn&#8217;t do them.\u201d Tobac also noted that the hack could have been much worse if the hacker hadn\u2019t simply been a teenager interested in running a Bitcoin scam. \u201cIf I were a real malicious person, I&#8217;d probably try and start World War III,\u201d she said. \u201cI would take over accounts for, you know, leaders across the world and have them fight with each other and really escalate that. If I were really malicious, that&#8217;s probably what I would do. Now, of course, it&#8217;s malicious to take over accounts, but it&#8217;s not that level of maliciousness where they&#8217;re trying to incite violence or war. It&#8217;s just, I&#8217;m looking to get some money quick. That points to more teenager behavior, and there were a couple other things that showed that it was more in the teenager direction rather than the APT direction.\u201d Tobac concluded that the incident shows the importance of a defense-in-depth strategy. Training is important, but organizations also need protocols and technical defenses to minimize the chances of a successful attack. \u201cThere are so many things that we need,\u201d Tobac said. \u201cWe need to make sure that we have protocols in place &#8211; you know, maybe, like, two eyes or four eyes to make sure that two people are able to make that request before it goes through. Like, for instance, can you imagine if you had to get two Twitter employees to say, sure, we&#8217;ll change the email on former President Barack Obama&#8217;s account before actually having it go through?\u201d Tobac added that the Twitter incident shows that organizations will never be in a place where they can relax when it comes to security. \u201cIt&#8217;s very possible that they were doing all of the suggestions that I recommended, and it still didn&#8217;t work,\u201d she said. \u201cSo I can&#8217;t really comment to that, but I can say that we know many organizations out there do not take these steps. They might not have hardware MFA. They might not have social engineering training with up-to-date examples of how exactly it happens, not just over email but also over the phone, which is a big limitation of a lot of trainings now, and also making sure that we have all of the technical tools to backup if a person inevitably makes a mistake, which is, of course, bound to happen. Twitter might have been doing this. They might not have. But we do know that it&#8217;s a learning point for every organization, regardless of whether or not they&#8217;re currently doing it. So just keep it up.\u201d New-school security awareness training can give your organization an essential layer of defense by teaching your employees about social engineering and instilling in them the importance of following security protocols. This blog originally appeared on KnowBe4.<\/p>\n","protected":false},"author":178,"featured_media":41260,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[80,1650,82,88,1638],"tags":[2832],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/41259"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=41259"}],"version-history":[{"count":1,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/41259\/revisions"}],"predecessor-version":[{"id":41261,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/41259\/revisions\/41261"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/41260"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=41259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=41259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=41259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}