Securing University Data

Where possible, University data should be stored securely and backed up to avoid loss. Devices no longer in use should be properly sanitised.

A social engineering attack is where an attacker changes our behaviour to do something that benefits them, through social means.

We have a natural tendency to trust people, and to help them by answering questions openly.

A social engineering attack takes advantage of this natural tendency.

What Is Social Engineering Attacks

A social engineering attack is generally after one of two things:

  • Data
  • Physical access to a location

The way they operate is to get us to willingly hand over information or access to something they want, even if it is not in our interests to do so.

What Attackers Are After

Recorded social engineering attacks have taken place through mail as far back as the 17th Century. There are as many ways for a social engineer to target us as there are means of communication.

Most common attacks take place over:

  • Email
  • Telephone
  • SMS Text Message
  • Social Media (Facebook, Twitter, LinkedIn)
  • Messaging Apps (Messenger, Skype, WhatsApp)
  • Forums and chat rooms
  • Dating sites
  • Face to face
How Attackers Contact Us

They could pretend to be a figure of authority, a friend or even just somebody in need.  They will appeal to our emotions in some way and ask us questions to collect important information. 

Common emotional triggers they use are:

  • Fear – by acting as somebody in authority, making threats or simply by pushing that something must be done to a tight time limit.
  • Compassion – by pretending to be poor, lonely or even a family member in financial need.
  • Loneliness – dating sites and social media are rife with fake accounts and bots trying to lure in the unwary, building trust, promising romance and then using the victim.
  • Greed – Get rich quick scams, fake jobs and interviews and false lotteries and prizes are all used.

Even if what we tell them is not enough information to let them "log in as us", or take advantage directly, social engineering attackers:

  • gradually build up a picture
  • learn our weak points
  • gain our confidence
  • combine what we tell them with information they have found elsewhere.
How Hackers Get Us To Do

Protecting ourself from social engineering is difficult as we all have emotional triggers and we all want to be helpful and friendly.

There are however, a few key things that will help make us a harder target for social engineers:

  • Be wary of unprompted contact from strangers. Cold callers, unknown contact on social media and dating sites can all be a potential first step for a social engineer.
  • If it sounds too good to be true, it may well be.
  • Be wary of unsolicited messages that aggressively push for you to take some kind of action within a tight timeframe.
  • Be aware of what you tell people, especially if it is about any kind of information that protects our security. 

If you think you are being targeted by social engineers you can contact Police Scotland for help.

What We Can Do