Anatomy of an Attack
PHASE 1: Profile
Research Targets
Organized cybercrime rings are highly sophisticated, mining marketing databases, social media profiles, online archives and corporate websites to identity and profile targets.
Research Targets
Organized cybercrime rings are highly sophisticated, mining marketing databases, social media profiles, online archives and corporate websites to identity and profile targets.
PHASE 2: Personalize
Tailor Attack
Through well-researched, expertly-crafted email messages backed by matching phishing sites, these thieves impersonate a trusted individual or brand.
Tailor Attack
Through well-researched, expertly-crafted email messages backed by matching phishing sites, these thieves impersonate a trusted individual or brand.
PHASE 3: Push
Deliver Emails
Some campaigns will score their first victims in under four minutes. Others will involve meticulous grooming over weeks or even months, as gain the trust of unsuspecting business or consumer targets.
Deliver Emails
Some campaigns will score their first victims in under four minutes. Others will involve meticulous grooming over weeks or even months, as gain the trust of unsuspecting business or consumer targets.
PHASE 4: Persuade
Manipulate Emotions
Through carefully-timed messages designed to maximize tension and exploit personal insecurities, victims rush to respond without carefully assessing the legitimacy of the sender or the message.
Manipulate Emotions
Through carefully-timed messages designed to maximize tension and exploit personal insecurities, victims rush to respond without carefully assessing the legitimacy of the sender or the message.
PHASE 5: Plunder
Reap Rewards
Criminals receive and launder funds before vanishing into thin air. Or they infiltrate compromised accounts and extract valuable data and information that can be monetized in future crimes.
Reap Rewards
Criminals receive and launder funds before vanishing into thin air. Or they infiltrate compromised accounts and extract valuable data and information that can be monetized in future crimes.
Social Engineering Techniques
Social engineering attacks rely on deception and manipulation to exploit human trust. Here are 12 common techniques every organization should know and defend against.
Phishing
2. Spear Phishing
3. Whaling
4. Tailgating and Piggybacking
5. Baiting
6. Pretexting
7. Vishing
8. Smishing
9. Quid Pro Quo
10. Business Email Compromise (BEC)
11. QR Code Phishing (Quishing)
12. Deepfake Social Engineering
The Fortra Advantage
Protection from Social Engineering Attacks
While many cyberattacks exploit technical vulnerabilities, social engineering attacks target people by using deception, trust, and urgency to manipulate behavior. Fortra goes beyond traditional email security by analyzing communication patterns, identities, and relationships behind every message to detect suspicious activity and stop attacks, regardless of the tactic.
Security Against Identity Deception
Identity deception is core to social engineering and the key to tricking people into downloading malware, logging into fake web pages, or giving up information.
Fortra's social engineering security detects threats and prevents identity deception tactics such as display name deception, spoofing, lookalike domains, and messages sent from hijacked sender accounts.
Automated Partner & Supplier Fraud Prevention
Many of today's most damaging email threats begin with an attacker impersonating a trusted vendor, supplier, or business partner. Fortra uses relationship and behavioral intelligence to understand how organizations normally communicate, enabling it to detect suspicious messages and prevent advanced social engineering attacks, even when they originate from seemingly trusted sources.
Solutions
Protect your organization from costly social engineering attacks