Social Engineering on the Rise Threat Actors Are Targeting Your People
Summary
TL;DR:
- People, not technology, are the target: Cybercriminals like Scattered Spider, ShinyHunters, and Lapsus$ exploit employees via phishing, vishing, MFA fatigue, and help desk impersonation.
- All organizations are vulnerable: New hires and non-technical staff are especially at risk, as traditional defenses (firewalls, antivirus, MFA) can be bypassed through social manipulation.
- Common attack tactics: Phishing emails, fake login pages, SIM swapping, MFA fatigue, and help desk impersonation are the most frequent methods used.
- Employee best practices: Pause before acting, verify requests via official channels, control MFA approvals, avoid suspicious links, and report anomalies immediately.
- Organizational safeguards: Provide ongoing security training, enforce phishing-resistant MFA, strengthen help desk procedures, restrict admin and remote access, and follow least-privilege access principles.
A new wave of cyberattacks is exploiting people, not technology. Sophisticated groups like Scattered Spider, ShinyHunters, and Lapsus$ are using social engineering tactics such as phishing, voice phishing (vishing), multi-factor authentication (MFA) fatigue, and IT impersonation to trick employees into handing over access. These attacks are fast-moving, hard to detect, and increasingly successful against employees.
Why it matters
Organizations of all sizes are vulnerable because attackers don’t need advanced malware. They only need to fool one employee. New hires and non-technical staff are especially at risk, as they are eager to comply, less familiar with procedures, and more likely to trust “urgent” requests. Traditional defenses like firewalls, antivirus, and MFA are no longer enough when attackers can persuade employees to bypass them.
What happens
An attacker’s success often relies on manipulating trust and creating a sense of urgency. Below are the most common techniques currently used by the cybercriminal groups mentioned above:
- Phishing Emails: Attackers send emails that look like they come from your company, a vendor, or even a manager. These often include fake login links or urgent requests to “verify” credentials.
- Voice Phishing (Vishing): Criminals call employees pretending to be IT support, HR, or a vendor. They pressure staff into sharing passwords, MFA codes, or approving access requests.
- Multi-Factor Authentication (MFA) Fatigue Attacks: Attackers bombard an employee with repeated multi-factor authentication prompts, hoping the employee clicks “approve” just to stop the alerts.
- Help Desk Impersonation: Hackers pose as employees who “lost access” and convince your IT help desk to reset passwords or bypass security controls.
- SIM Swapping: Criminals trick a mobile carrier into transferring a victim’s phone number to their device, allowing them to intercept MFA codes sent via text.
- Credential Harvesting via Fake Login Pages: Emails or texts lead employees to convincing but fraudulent single sign-on (SSO) portals designed to steal usernames and passwords.
What employees can do
- Pause and Slow Down: Attackers rely on urgency. Taking 30 seconds to double-check an unexpected request can stop an attack.
- Think Before You Click: Hover over links in emails, check sender addresses, and never log in through a link you weren’t expecting.
- Verify by Calling Back: If you get a call from “IT” or a vendor asking for access, hang up and call back using the official company number.
- Control MFA: Only approve MFA prompts you initiated. Unexpected prompts should be reported immediately.
- Stick to Official Channels: Contact IT directly: Always reach out to your company’s designated help desk, ticketing system, or official IT email. Do not trust links in emails or instructions from unsolicited callers.
- Avoid Text-Based MFA: Use authenticator apps or security keys when available, since text-based MFA can be intercepted.
- Check Web Addresses: Always type the company URL directly into your browser. Look for https:// and the lock symbol before logging in.
- Report Quickly: If something feels wrong, don’t ignore it. Reporting suspicious activity early can stop a breach before it spreads.
What organizations can do
- Train Employees Regularly: Teach staff to spot phishing, vishing, and MFA fatigue attempts, and keep training updated.
- Onboard with Security Awareness: Integrate cybersecurity training into new employee onboarding to make them less susceptible to social engineering.
- Strengthen Help Desk Verification: Require multi-step validation before resetting passwords or approving access.
- Implement Phishing-Resistant MFA: Use hardware keys or authenticator apps with push notifications, and avoid SMS or email-based codes.
- Audit Remote Access Tools: Restrict use of tools like AnyDesk, TeamViewer, or ScreenConnect and enforce MFA on those that remain.
- Apply Least Privilege: Limit permissions so employees only have access to what they need for their jobs.
- Limit Admin Access: Reduce the number of admin accounts and watch for suspicious account creation or permission changes.

The SensCy Solution
We provide an affordable, easy-to-understand, sensible solution specifically tailored to each client. Our clients tell us that they are thrilled with the value that they derive for the price they pay. Schedule a consultation with one of our experts.

Your SensCy Score® is a good indication of your organization’s cyber hygiene and how prepared your organization is against cyber threats. We can generate your score in less than 30 minutes—at no cost to you!
Recent Posts
