October is Cybersecurity Awareness Month! Read the following article written by Rowan College at Burlington County's Chief Information Officer Dr. Martin Hoffman and learn how understanding social engineering is a strong defense against cyber attacks.
By Dr. Martin Hoffman, Chief Information Officer at RCBC
--
You may have heard the phrase “it takes one to know one” or even “set a thief to catch a thief.” Both are in use today, but not new. The 3rd-century BC poet Callimachus wrote, "Being a thief myself, I recognized the tracks of a thief."
And if you take certain computer science or criminal justice courses, they’re likely to touch on the tactics of modern cyber criminals. You can count on a great education at RCBC! You can also be sure that the images of hackers in movies are almost completely false. It is highly unlikely that a modern cybercriminal is sitting at a terminal, typing their way through a firewall or coding complex decryption routines on the fly.
Just like a car thief or burglar is likely to try the door first before breaking out the lockpicks, cybercriminals will go for the straightforward approach before spending time or money on something complicated. This is where thinking like a cyber thief can help protect you from one, and it ties directly into the title of this blog post.
The number-one tool in the arsenal of today’s cybercriminals is social engineering. And that’s just a fancy term for lying. So why don’t they call it lying? If you take psychology courses in addition to computer science courses, you’ll learn about cognitive dissonance, which helps explain how cybercriminals reframe lying as social engineering to rationalize their behavior or make it sound like a legitimate profession.
So, how does lying get a cyber criminal into your bank account? It might start with “dumpster diving” – that is, going through the trash to find something with your personal info. Like, perhaps, a printout of your registration status or a tuition payment receipt from RCBC. Or perhaps you simply walked away from a computer logged into your BaronOne account, and the next person to sit down was a cybercriminal.
Once the attacker has your info, however they may have gotten it, the social engineering attack might go a little like this scenario (which I co-created using an AI writing assistant to model a realistic call):
Attacker: “Hi, my name is Barry Baron. I’m locked out of my online account and my phone was stolen, so I can't receive the SMS reset code. I need to update my email address so I can log in."
Customer Support: “I can help with that, Barry. For security, can you confirm your address and the last four digits of your card number?"
Attacker: “Sure, my address is 123 University Ave, and the account ends in 4821."
Customer Support: “Thank you. Can you also verify a recent transaction amount or disbursement date?"
Attacker: "Yes, I just paid my tuition at RCBC so there was a withdrawal of $1,250 on September 12th."
Customer Support: “Great, so what email address would you like to use for account access in the future?”
Attacker: “ImaHacker@cyberthreat.com”
Customer Support: “Ok, that will be your new username and we’ve reset the password to ‘ChangeMe123!’ Please change your password the first time you log in.”
No, it’s not really that simple, but to professional cyber criminals, it’s not that much harder, either.
Lying to the bank’s customer support staff is easier than hacking the bank’s computers. All the attackers need for a potentially successful social engineering attack are a few pieces of personally identifiable information (PII).
So, what can you do to protect yourself? Think like a thief. I’m not suggesting total paranoia; we all have enough stress in our lives without that, but heightened awareness is good practice.
Don’t walk away from a computer thinking “who cares, there’s nothing secret in my email,” instead think “what could a cyber criminal do if they had access to my email” and be sure to not only log out but also close the web browser when done. Don’t throw out a paper bill – for tuition or anything else – thinking “I don’t need this, I already paid it” instead think “what could a cyber criminal do if they had access to this information” and shred it, either with a cross-cut shredding machine, or with scissors, or even just by ripping it up into tiny little pieces. Sometimes, low-tech hacks only need low-tech defenses.
Don’t be a thief, that’s bad, but occasionally thinking like one? That might be a really good idea!
--
Welcome to RCBC’s new blog! Here, we’ll delve deep into the people, programs, events, student resources, and more that enrich the Rowan College at Burlington County experience. Keep up with the stories posted every other Friday at rcbc.edu/blog, and stay connected with RCBC institutional announcements and updates on the rcbc.edu/news page. Follow all the news at rcbc.edu/rcbc-newsroom.