ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Putting the “social” into social engineering

Jack Chapman at Egress explores the psychology behind phishing

 

Despite originating from an external source, phishing is considered an insider threat. These types of attacks play on an individual’s emotions and as such, are human-activated and are unsuccessful if they fail to hook an unsuspecting employee.

 

There is no doubt that the looming threat of phishing takes a toll on employees and organizations with 99% of cyber-security leaders highlighting they are stressed about email security.

 

If an individual falls victim to a phishing attack, their stress levels are likely going to increase, as they might question their decision-making and ultimately, feel embarrassed or ashamed. The constant vigilance required to avoid these attacks may lead to increased anxiety and decreased productivity.

 

So, what are the key methods used and why do employees find themselves susceptible to them?

 

Psychological triggers in phishing

The purpose of a phishing attack is to engineer the way we intuitively query the email we have received. We may naturally question whether a message is valid and secure and take logical steps to confirm this. However, there are psychological triggers that scammers use to make us think emotionally, rather than logically, such as:

  • Urgency: a phishing email usually demands immediate action, as consideration leads to more questions regarding if it’s a legitimate request.
  • Plausibility: modern phishing attempts will be based on real-life, often mundane scenarios. E.g. an invoice that needs paying, or files that need sharing.
  • Familiarity and authority bias: in recent years, there’s been a marked rise in spear phishing, where the attack is at least partially tailored to an individual – including claiming to be from a figure of authority such as their CEO or head of security to add weight to the request.
  • Confidentiality: the action required is specific to you and needs to be done by you alone, as increased involvement raises the likelihood of the scam being uncovered.

Fear and anxiety are powerful motivators so it’s common for criminals to target new employees. These people are more likely to be anxious to impress a new manager and are unaware of the subtle signs that something is amiss with their communication style.

 

Similarly, certain senior roles within the company will be targeted because of their access to and authority over privileged information such as funds, systems, and data. 

 

Egress recently found that between January 1st and April 30th, 2023, Chief Finance Officers (CFOs) were the number one target, receiving almost one-third (31%) of phishing emails, followed by CEOs, who received 25%.

 

Overall, those leading functions related to security, risk, and compliance were least targeted, with cyber-criminals likely to anticipate lower success rates due to their greater security awareness.

 

Targeting specific employees based on their role within the organization can be an extremely lucrative method, if successful, with one recent example reporting that fraudsters had managed to steal €38,000,000 ($40.3M) within a few days.

 

Thinking with Type 1 and Type 2 brains

With awareness of cyber-threats increasingly prominent, most people know how to recognize the ‘classic’ warning signs of phishing (poor spelling and grammar, and unexpected hyperlinks and attachments). They’re diligent at work, and they don’t act recklessly.

 

However, cyber-criminals prey upon the times we are stressed, tired, or forced to rush – and, even if we’re not stressed to start with, they’ll try to engineer it to happen! It’s these times where we’re most error-prone and are susceptible targets for phishing.

 

’Working on autopilot’ is sometimes referred to as Type 1 thinking. This refers to a more natural state, we react intuitively to situations we commonly experience such as driving a car, getting dressed, or replying to emails.

 

Type 2 thinking is where we slow down and apply considered, analytical thought to something. In a Type 2 mindset, people are more likely to spot the more obvious signs of phishing or spend enough time thinking about an email to check it with a colleague - which is why attackers have social engineering techniques to shift us into fast, automatic Type 1 thinking. This includes putting pressurizing time limits in emails to switch someone into the panic mindset.

 

‘Mental shortcuts’ also known as heuristics, enable people to make decisions quickly and whilst useful, this can lead to cognitive bias and error. For example, it allows us to decide how likely it is for an object, such as a hyperlink, to be in a category based on what it looks like. SharePoint and OneDrive hyperlinks are frequently used by cyber-criminals, due to their status as popular business functionality platforms.

 

Cyber-criminals anticipate victims will automatically assume these links are safe and be less wary. Ultimately, familiarity leads to complacency.

 

Threat actors are not only aware of our automatic mindsets but also the specific times we are most vulnerable. After analyzing 200,000 inbound emails across forty days, Egress found that employees are most likely to receive phishing emails at the start of the day, as well as after lunch when they are often distracted.

 

This research revealed that employees receive the highest volume of phishing attempts during the first few minutes after starting work and after lunch when people have been away from their desks and there is often a pile-up of emails to answer. Cyber-criminals aim to target victims when they are most distracted and therefore more likely to make mistakes and overlook malicious emails.

 

Security and awareness training

Alongside, the stress of looming attacks is the pressure from internal security culture. Security protocols and training tread a precarious path. For example, if we consider instances where response to phishing has not gone well, many of these incidents undoubtedly had opportunities for individuals to come forward and report possible mistakes.

 

With only 54% of employees surveyed in our 2021 Insider Data Breach Survey reporting that they think their organization’s security culture trusts and empowers them, there is need for improvement. If you fire or discipline an employee because they made a mistake, the knock-on consequences to your security culture could be catastrophic.

 

Employees could stop reporting mistakes due to the fear of punishment. The attack methods may go unnoticed which is far more dangerous than ones you know about and can act to remediate.

 

An unwitting employer can easily cross an invisible sensitivity line. Cyber-security influencer, Graham Cluley recently analyzed dissatisfaction with phishing training when news broke that a UK law firm sent round emails offering higher bonuses/pay increases in a company initiated phishing test. A disappointing round of wage increases earlier in the year meant the test resulted in high levels of staff dissatisfaction.

 

Phishing is a tried-and-true method of attack, and we can expect much of the same from the cyber-threat in the coming years due to continued success. It’s important for employees to be alert to threats, but they must be supported with the tools and knowledge that will support them, especially if they are feeling tired or fatigued.

 

In particular, intelligent technology is available to detect the highly sophisticated attacks that leverage social engineering and other advanced phishing techniques that get through traditional detection technologies.

 

Employees should feel empowered to call their security team without fear of judgement. This will not only improve cyber-security culture but also positively contribute to employee wellbeing.

 


 

Jack Chapman is VP of Threat Intelligence at Egress

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543