GET GEPHARDT

Get Gephardt: How cybercriminals use social engineering to get us to hand over our sensitive info

Oct 3, 2022, 10:10 PM | Updated: Nov 18, 2022, 11:31 pm

SALT LAKE CITY — You can have the strongest, most secure password in the history of cybersecurity, but the bad guys know there is one weakness they can use to hack into your system — you!

Just recently, Uber got added to the ever-growing list of companies defeated by social engineering when a hacker tricked a contractor into granting them access to his Uber account. From there, they got into the rideshare giant’s internal data systems.

Oh, and the alleged hacker? Just 18 years old.

“I’m actually not too surprised,” said cybersecurity expert Zulfikar Ramzan, Aura Labs’ chief scientist and CEO. “There was nothing sophisticated. It was all fairly straightforward.”

Ramzan said that while Uber’s hacking may sound like something out of a heist film like Ocean’s Eleven, it isn’t.

“This is more like a 7-Eleven smash and grab,” he said. “The reality is in this day and age; those attacks tend to be quite effective. You don’t need to be very fancy.”

Ramzan said social engineering is classic con man stuff — faking legitimacy. The bad guy might pose as a government agency, your bank, a work colleague, someone in your IT department, a friend or others. And they will use emails, texts, social media, whatever they can to reach you.

“It’s just about being able to trick you into doing something that compromises your own security,” he said. “It only takes one person to let you in the front door, and from that point onward, you may have access to most rooms in the house.”

Often, the trick is to get you to follow a link, or they will get you to send them a code to defeat two-factor authentication or to get you to use your real login credentials on a fake website.

And it works well.

According to the FBI’s latest Internet Crimes Report, cybercrooks stole $6.9 billion last year, much of that is through social engineering.

New data from virtual private network company, NordVPN found that 84% of Americans have run into some kind of social engineering. Of those, 36% actually admitted to getting duped. Ramzan said it could happen to anyone at any level of tech savviness.

“We have these amazing street smarts and tell us when we go to the physical world – what a good neighborhood is or a bad neighborhood as we can tell something’s wrong because we’ve owned our physical street smarts in really deep ways,” he said. “Unfortunately, we haven’t grown our digital street smart, and so we don’t have that same level of intuition — those “spidey senses” that tell us that we’re potentially in danger.”

Ramzan said the explosion of remote work throughout the pandemic has dramatically accelerated social engineering attacks.

“Your IT department is incentivized to set up a world where anybody can access critical services from anywhere. Unfortunately, that also means hackers can access that same information potentially from anywhere,” he said.

So, how to keep the bad guys from getting their foot into our front door? Ramzan said anyone asking for login credentials is a huge, stinking red flag. Next, use multi-factor authentication everywhere you can. Then, watch what you post about yourself online.

“Even though you might think you’ve got a small role to play in whatever is out there, you might be one or two connections away from someone who could have a massive impact,” Ramzan said. “If somebody can get to you, they may be able to use you as the next step in a chain of events to get into something much more nefarious.”

KSL 5 TV Live

Get Gephardt

Matt Gephardt looking over the CarShield documents for Scott Dumas....

Matt Gephardt and Sloan Schrage, KSL TV

West Haven man says extended auto warranty refuses to cover costly engine repair

Many drivers buy an extended auto warranty to help keep their car on the road, but when the extended warranty a West Haven man bought refused to cover replacing an engine, he decided to Get Gephardt.

1 day ago

Follow @KSL5TVLike us on Facebook...

Matt Gephardt

How hoarding documents puts you at risk for identity theft

Someone who knows what they’re doing can do a whole lot of damage with the scraps of paper you’ve stashed in filing cabinets, drawers and other various hiding places around your house.

2 days ago

IOC excludes Russian and Belarusian athletes from Paris 2024 Olympics opening ceremonies....

Matt Gephardt

Get Gephardt: How to stay ahead of the 2024 Olympics scams

As Utahns know firsthand from 2002, the Olympics can be a bit chaotic with millions in an unfamiliar place. The situation is sure to entice opportunistic con men with Olympic scams.

3 days ago

FILE: construction zone...

Matt Gephardt

How to avoid hiring a bad contractor

Bobby Main investigates contractors for Utah's Division of Professional Licensing, here's his advice for avoiding bad contractors.

4 days ago

Dave Donegan showing Matt Gephardt the items that were broken in his move....

Matt Gephardt and Sloan Schrage, KSL TV

How liable is a moving company if your stuff gets damaged?

Dave Donegan’s home was just about to go into renovation, so he hired a moving and storage company to hold onto his household goods while work was underway.

8 days ago

FILE - The Amazon app is seen on a smartphone, Tuesday, Feb. 28, 2023, in Marple Township, Pa. (AP ...

Matt Gephardt and Sloan Schrage, KSL TV

Get Gephardt helps solve Amazon misdelivery mystery for Manti man

Most of us are ordering more and more things online, and it's sometimes frustrating with things like an Amazon misdelivery mystery.

17 days ago

Sponsored Articles

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Battery low message on mobile device screen. Internet and technology concept...

PC Laptops

9 Tips to Get More Power Out of Your Laptop Battery

Get more power out of your laptop battery and help it last longer by implementing some of these tips from our guide.

Get Gephardt: How cybercriminals use social engineering to get us to hand over our sensitive info