Skip to main content
Principles of Influence

Validation as a Social Engineering Tool

By November 25, 2013No Comments

Validation as a Social Engineering ToolDo you remember a time when someone made you feel really good about yourself? Maybe they paid you a compliment or listened closely to what you had to say.  These are great examples of validation.

Validation is a powerful concept in which a person is made to feel valued, acknowledged, and connected with another.  As social creatures, humans crave validation, as it creates a sense of acceptance.

Manipulated Validation

Hope Jackson is currently serving five years of probation for scamming country music singer Brad Paisley and his wife Kimberly Williams-Paisley, as well as Kate Gosselin and others, by appealing to their sympathy over the Internet and phone. If you have seen the “Catfish” movie or television series, then you are familiar with the tactics Jackson employed to manipulate her targets and gain their trust. Interestingly, there doesn’t seem to be any financial motive and the scammer returned a check that a victim sent to her.

This scam was not designed to yield money, but its victims gave the scammer what she wanted. Paisley sang a song over the phone to what he thought was a terminally ill child. Kate Gosselin dedicated an episode of her reality series to a woman she believed had died of cancer. People were being kind to Jackson and building caring relationships with her. After her arrest, she said she was looking for “love” and “acceptance.”

In order to exploit the sympathy of her targets, Jackson would tell her victims that she or her imaginary daughter, or both, had cancer. She sent emails to her victims with photos of a sick child that had been lifted off the Internet. In some of her phone conversations with her victims, she would disguise her voice to sound like her “daughter” to strengthen her story and make people invest more in her life and “family.”

While we often tend to think of social engineering in the context of concrete gains for the perpetrator, in this case, the endgame was simply attention.  Imagine how validating it might be to someone to have the compassionate and undivided attention of another, especially a celebrity.  We discuss validation as an important part of building rapport in our 4-day Advanced Practical Social Engineering course.

Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.