{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/social-engineering","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/social-engineering/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/social-engineering/"},"term":{"en":"Social engineering","da":"Social engineering"},"aka":{"en":["social engineering attack","human hacking"],"da":["social manipulation"]},"domain":["security"],"cluster":"awareness","layer":"people","status":"current","summary":{"en":"Manipulating people into giving away information or access, instead of breaking into systems directly.","da":"Manipulation af mennesker, så de udleverer oplysninger eller adgang, i stedet for at bryde direkte ind i systemer."},"body":{"formal":{"en":"A family of attacks that play on human trust, respect for authority, helpfulness, curiosity or time pressure to make a person reveal information or grant access, getting around technical controls entirely.","da":"En gruppe af angreb, der udnytter menneskers tillid, respekt for autoritet, hjælpsomhed, nysgerrighed eller tidspres til at få en person til at afsløre oplysninger eller give adgang - helt uden om de tekniske kontroller."},"plain":{"en":"Like a con artist who does not pick the lock but simply talks the doorman into holding the door open.","da":"Som en svindler, der ikke dirker låsen op, men blot snakker dørmanden til at holde døren åben."},"inPractice":{"en":"A few USB sticks labelled “Salaries 2026” are left in the car park outside a town hall; an employee plugs one into a work PC to find out whose it is.","da":"Et par USB-stik mærket “Lønninger 2026” bliver efterladt på parkeringspladsen ved et rådhus; en medarbejder sætter et af dem i sin arbejds-pc for at finde ud af, hvem den tilhører."},"whyItMatters":{"en":"The strongest locks and walls do not help if a person can be talked into opening them, so people are a target in their own right and need defending as such.","da":"De stærkeste låse og mure hjælper ikke, hvis en person kan snakkes til at åbne dem, så mennesker er et mål i sig selv og skal beskyttes som sådan."}},"deepDive":{"en":"The psychological mechanics are well mapped. Robert Cialdini's principles of influence (1984) - reciprocity, commitment and consistency, social proof, authority, liking and scarcity, later extended with unity - describe the levers that almost every lure pulls: an executive's name (authority), a deadline (scarcity), \"your colleagues have already signed\" (social proof), a small favour before the real request (reciprocity). They work because they trigger fast, heuristic System 1 processing; the attacker's aim is to keep the victim from switching to deliberate System 2 thinking, which is why time pressure and emotional arousal (fear, curiosity, greed, helpfulness) appear in nearly every scenario.\n\nKevin Mitnick's The Art of Deception (2002) described the attack as a cycle: research, developing rapport and trust, exploiting that trust, and using the information gained, often as input to the next cycle against someone more senior. Reconnaissance draws on OSINT (company sites, LinkedIn, job adverts, public registers, breach dumps), and the output of one conversation - a name, a system, an internal phrase - becomes the credibility of the next. The main technique families are phishing and its channel variants (spear phishing, BEC, smishing, vishing), pretexting, baiting (infected media or tempting downloads), quid pro quo (fake support offering help in exchange for credentials), and physical techniques such as tailgating and impersonating contractors. Tischer et al. (IEEE S&P 2016) dropped about 300 USB sticks on a university campus and found that close to half were plugged in and had files opened.\n\nMITRE ATT&CK does not have a single social-engineering technique; the behaviour is spread across T1566 Phishing and T1598 Phishing for Information, T1204 User Execution, where the victim runs the payload, and T1091 Replication Through Removable Media. High-impact incidents illustrate the range: in July 2020 attackers phone-phished Twitter employees to reach internal admin tools and hijack high-profile accounts, and in 2023 a help-desk call was the reported entry point into MGM Resorts, followed by ransomware.\n\nBecause social engineering bypasses technical controls by definition, defence has to change the decision environment rather than only the user. Effective measures are verification procedures that do not depend on judging the caller (call-back to a known number, out-of-band approval, four-eyes rules), phishing-resistant MFA and hardened help-desk identity checks, least privilege so a manipulated user can hand over less, physical access controls such as turnstiles and escort rules, and a reporting culture in which staff who were fooled report quickly without fear. ISO/IEC 27002:2022 addresses the human side through control 6.3 (awareness, education and training) and the physical side through controls 7.1-7.4. Social engineering is the umbrella category; the human factor is the underlying weakness it exploits, and security awareness and security culture are the corresponding defences.","da":"Den psykologiske mekanik er godt kortlagt. Robert Cialdinis principper for påvirkning (1984) - gensidighed, forpligtelse og konsistens, social bevisførelse, autoritet, sympati og knaphed, senere udvidet med fællesskab (unity) - beskriver de håndtag, næsten alle lokkemidler trækker i: en direktørs navn (autoritet), en deadline (knaphed), \"dine kolleger har allerede skrevet under\" (social bevisførelse), en lille tjeneste før den egentlige anmodning (gensidighed). De virker, fordi de aktiverer den hurtige, heuristiske tænkning i System 1; angriberens mål er at forhindre offeret i at skifte til den overvejende tænkning i System 2, og derfor indgår tidspres og følelsesmæssig ophidselse (frygt, nysgerrighed, grådighed, hjælpsomhed) i næsten alle scenarier.\n\nKevin Mitnicks bog The Art of Deception (2002) beskrev angrebet som en cyklus: research, opbygning af relation og tillid, udnyttelse af tilliden og brug af de indhentede oplysninger, ofte som input til næste runde mod en person højere oppe. Rekognosceringen bygger på OSINT (virksomhedens hjemmeside, LinkedIn, jobopslag, offentlige registre, lækkede databaser), og resultatet af én samtale - et navn, et system, en intern vending - bliver troværdigheden i den næste. De vigtigste teknikfamilier er phishing og dens kanalvarianter (spear phishing, direktørsvindel, smishing, vishing), pretexting, baiting (inficerede medier eller fristende downloads), quid pro quo (falsk support, der tilbyder hjælp mod loginoplysninger) og fysiske teknikker som tailgating og at udgive sig for at være håndværker eller leverandør. Tischer m.fl. (IEEE S&P 2016) lagde omkring 300 USB-stik ud på et universitetsområde og fandt, at tæt på halvdelen blev sat i en computer, og at filer på dem blev åbnet.\n\nMITRE ATT&CK har ikke én samlet teknik for social engineering; adfærden er fordelt på T1566 Phishing og T1598 Phishing for Information, T1204 User Execution, hvor offeret selv kører nyttelasten, og T1091 Replication Through Removable Media. Alvorlige hændelser viser spændvidden: I juli 2020 ringede angribere til medarbejdere hos Twitter og snakkede sig adgang til interne administrationsværktøjer, som de brugte til at overtage kendte personers konti, og i 2023 var et opkald til servicedesken den rapporterede indgang til MGM Resorts, efterfulgt af ransomware.\n\nFordi social engineering pr. definition går uden om de tekniske kontroller, må forsvaret ændre rammerne for beslutningen og ikke kun brugeren. Effektive tiltag er verifikationsprocedurer, der ikke afhænger af at bedømme den, der ringer (ring tilbage på et kendt nummer, godkendelse via en anden kanal, fire-øjne-princippet), phishing-resistent MFA og skærpet identitetskontrol i servicedesken, mindste privilegium, så en manipuleret bruger kan udlevere mindre, fysisk adgangskontrol som drejekors og krav om ledsagelse og en meldekultur, hvor medarbejdere, der er blevet narret, melder det hurtigt uden frygt. ISO/IEC 27002:2022 dækker den menneskelige side med kontrol 6.3 (awareness, uddannelse og træning) og den fysiske side med kontrol 7.1-7.4. Social engineering er paraplykategorien; den menneskelige faktor er den underliggende svaghed, der udnyttes, og awareness og sikkerhedskultur er de tilsvarende forsvar."},"edges":[{"type":"kind-of","to":"security/threat","confidence":"high","strength":"normal"},{"type":"exploits","to":"security/vulnerability","why":{"en":"It treats human trust and helpfulness as the weakness to abuse, rather than a flaw in a machine.","da":"Det behandler menneskelig tillid og hjælpsomhed som den svaghed, der udnyttes, frem for en fejl i en maskine."},"confidence":"medium","strength":"primary"},{"type":"exploits","to":"security/human-factor","confidence":"high","strength":"normal"},{"type":"causes","to":"security/data-breach","why":{"en":"Information handed over to a manipulator is information that has left the organisation's control.","da":"Oplysninger, der udleveres til en manipulator, er oplysninger, som organisationen har mistet kontrollen over."},"confidence":"medium","strength":"normal"}],"depth":0,"sources":[{"title":"Cyber Security Fast Track - Ordliste","tier":"course-material"},{"title":"NIST Glossary - Social Engineering","url":"https://csrc.nist.gov/glossary/term/social_engineering","tier":"standard","publisher":"NIST"}],"draft":true}