GET GEPHARDT

Get Gephardt: How cybercriminals use social engineering to get us to hand over our sensitive info

Oct 3, 2022, 10:10 PM | Updated: Nov 18, 2022, 11:31 pm

SALT LAKE CITY — You can have the strongest, most secure password in the history of cybersecurity, but the bad guys know there is one weakness they can use to hack into your system — you!

Just recently, Uber got added to the ever-growing list of companies defeated by social engineering when a hacker tricked a contractor into granting them access to his Uber account. From there, they got into the rideshare giant’s internal data systems.

Oh, and the alleged hacker? Just 18 years old.

“I’m actually not too surprised,” said cybersecurity expert Zulfikar Ramzan, Aura Labs’ chief scientist and CEO. “There was nothing sophisticated. It was all fairly straightforward.”

Ramzan said that while Uber’s hacking may sound like something out of a heist film like Ocean’s Eleven, it isn’t.

“This is more like a 7-Eleven smash and grab,” he said. “The reality is in this day and age; those attacks tend to be quite effective. You don’t need to be very fancy.”

Ramzan said social engineering is classic con man stuff — faking legitimacy. The bad guy might pose as a government agency, your bank, a work colleague, someone in your IT department, a friend or others. And they will use emails, texts, social media, whatever they can to reach you.

“It’s just about being able to trick you into doing something that compromises your own security,” he said. “It only takes one person to let you in the front door, and from that point onward, you may have access to most rooms in the house.”

Often, the trick is to get you to follow a link, or they will get you to send them a code to defeat two-factor authentication or to get you to use your real login credentials on a fake website.

And it works well.

According to the FBI’s latest Internet Crimes Report, cybercrooks stole $6.9 billion last year, much of that is through social engineering.

New data from virtual private network company, NordVPN found that 84% of Americans have run into some kind of social engineering. Of those, 36% actually admitted to getting duped. Ramzan said it could happen to anyone at any level of tech savviness.

“We have these amazing street smarts and tell us when we go to the physical world – what a good neighborhood is or a bad neighborhood as we can tell something’s wrong because we’ve owned our physical street smarts in really deep ways,” he said. “Unfortunately, we haven’t grown our digital street smart, and so we don’t have that same level of intuition — those “spidey senses” that tell us that we’re potentially in danger.”

Ramzan said the explosion of remote work throughout the pandemic has dramatically accelerated social engineering attacks.

“Your IT department is incentivized to set up a world where anybody can access critical services from anywhere. Unfortunately, that also means hackers can access that same information potentially from anywhere,” he said.

So, how to keep the bad guys from getting their foot into our front door? Ramzan said anyone asking for login credentials is a huge, stinking red flag. Next, use multi-factor authentication everywhere you can. Then, watch what you post about yourself online.

“Even though you might think you’ve got a small role to play in whatever is out there, you might be one or two connections away from someone who could have a massive impact,” Ramzan said. “If somebody can get to you, they may be able to use you as the next step in a chain of events to get into something much more nefarious.”

Get Gephardt

(FILE) A man working on a car with the hood lifted up....

Matt Gephardt and Sloan Schrage, KSL TV

What you should know about extended car warranties and how to fight denials

One after another, the KSL Investigators heard from Utahns who paid monthly for an extended auto warranty but have not had a smooth ride in their repairs covered.

8 hours ago

After a Millcreek man was denied by his car warranty company for thousands in dollars of repairs to...

Matt Gephardt and Sloan Schrage

Get Gephardt: Car warranty company refuses to pay for repairs costing Millcreek man thousands of dollars

After a Millcreek man was denied by his car warranty company for thousands of dollars in repairs to his vehicle, he decided it was time to Get Gephardt.

1 day ago

The Black Magic Asphalt logo on documents that were exchanged with El Cholo’s Manuel Jacquez....

Matt Gephardt and Sloan Schrage, KSL TV

Get Gephardt helps man who says contractor turned his payment guarantee into a double payment

The El Cholo Restaurant hired a crew to reseal their parking lot, costing $4,600. Despite promises of a refund, the credit card charge remained, and interest accrued. Here's how the KSL Investigators resolved the issue.

2 days ago

hands taping up luggage - shipping your luggage...

Matt Gephardt

Can you save money by shipping your luggage instead of checking it?

KSL’s inflation buster Matt Gephardt tests whether shipping your luggage to your destination ahead of your trip can save you time and money.

3 days ago

A list of apps that have subscriptions....

Matt Gephardt

How to spot costly subscription creep and stop it

Subscriptions to streaming services and other apps can start draining the wallet, if you aren't paying attention to price increases.

7 days ago

You’ve likely noticed a growing number of businesses that have gone completely cashless. When it ...

Matt Gephardt

Businesses are passing their credit card fees onto customers, what can you do?

You’ve likely noticed a growing number of businesses that have gone completely cashless. When it comes time to pay, it’ll involve a tap, swipe or maybe a click on an app. It's a phenomenon that is contributing to the price we pay for goods and services.

8 days ago

Sponsored Articles

Side view at diverse group of children sitting in row at school classroom and using laptops...

PC Laptops

5 Internet Safety Tips for Kids

Read these tips about internet safety for kids so that your children can use this tool for learning and discovery in positive ways.

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Get Gephardt: How cybercriminals use social engineering to get us to hand over our sensitive info