Skip to main content
Security Assessment

Social Engineering News: Impersonation Attacks

By November 28, 2023No Comments

It’s 7:30pm and you’re finally leaving the office. On your way out, you notice an unknown person, in one of your company’s conference rooms with three laptops open. This is not a scenario that any CEO would wish to have. However, it’s exactly what happened to Dr. Samuel Straface, the CEO for Medrobotics. There is no record of the intruder, Dong Liu, in the Medrobotics visitor log. He apparently tailgated his way through the front door and blended in with the rest of the staff. It illustrates a point we often make, “looking the part,” whether it’s posing as an employee, vendor, or delivery service, is often all it takes for an intruder to blend in and gain unauthorized access. Impersonation attacks like the one we just mentioned are more common than you might think. Let’s look at a few that recently made the news.

Impersonation attacks in the news

A man in Poland robs multiple stores in a shopping mall after it closes for the night. How he gained access is quite unique. The accused man stood motionless in a storefront window posing as a mannequin, waiting for the mall to close. Police said,” mall staff and shoppers didn’t notice anything unusual at the time, claiming the man blended in with the other mannequins.”

Social Engineering News

Image: Fox News

A woman in Grand Rapids, Michigan has been federally indicted after allegedly posing as a registered nurse to defraud her employers. Letticia Gallarzo used the Michigan licensing number and the name of a person licensed as a nurse to get a job as a registered nurse at a Grand Rapids nursing home, and hospice facility. Despite not having a valid nursing license or a degree of any kind in nursing Ms. Gallarzo blended in and “As alleged in this case, the defendant recklessly and willingly put the lives of innocent patients at risk,” FBI Special Agent in Charge Cheyvoryea Gibson said in a statement.

In Coral Springs, Florida two young people pry open the doors of a Walmart store after closing hours. Wearing Walmart logo vests, they were hoping to blend in and “gather miscellaneous items.”

Social Engineering Security Assessments

To mitigate the threat of impersonation attacks, Social-Engineer provides security assessment services. We deploy professionally trained social engineers for onsite impersonation testing of your vendor/visitor access policies and physical perimeter security. We offer this service for either day or night testing. This is a full-scope program with multiple layers which may include badge cloning, credential harvesting, and network control. Or you can augment your internal red team with our trained and professional social engineers. We will work together with your internal team to test the human element of your network through remote consulting, feet-on-the-ground, and/or initial access testing through social engineering vectors.

Are you curious how our expert social engineers prepare for and execute an onsite security assessment? Listed below is an insightful behind-the-scenes experience from one of our expert social engineers.

Shelby Dacko, Human Risk Analyst for Social-Engineer describes her latest on-site security assessment assignment – Across A River.

Test. Educate. Protect.

Stay one step ahead of the criminals by educating and regularly testing your employees for possible physical security vulnerabilities. Contact us for a consultation today.

You May Also Like

Protecting Trade Secrets from Physical Intruders
Impersonation Attacks

Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.