8.3 Social Engineering & Human Factors
Key Takeaways
- Social engineering attacks people and trust processes instead of (or before) exploiting technical vulnerabilities
- Phishing uses fraudulent messages (often email) to steal credentials or deliver malware; spear phishing is targeted; whaling aims at senior leaders
- Vishing is voice-based social engineering; pretexting builds a fabricated scenario to extract information or access
- Tailgating (piggybacking) is physical social engineering — following an authorized person into a controlled space without authenticating
- Defenses combine training, verification habits, technical controls (MFA, email filtering), and physical access discipline — humans remain part of the attack surface
The strongest firewall still fails if someone holds the door — digitally or physically. Social engineering manipulates people into breaking security procedures, revealing secrets, running malware, or granting access. For Cyber Test candidates and cyber operators, human factors are not soft skills fluff: they are a primary attack path against every network that employs humans.
Why Social Engineering Works
Attackers exploit predictable human tendencies:
- Authority — “This is Colonel Smith; reset my VPN now.”
- Urgency — “Your account will be locked in 15 minutes unless you click.”
- Helpfulness — “Can you hold the door? I forgot my badge.”
- Fear — “Payroll found a problem with your direct deposit — confirm your SSN.”
- Curiosity — unexpected USB labeled “Promotion Board Results.”
- Trust in familiar brands — fake Microsoft, DoD, or bank login pages
Technical vulnerabilities require scanning and exploits. Social engineering often needs only a phone, an email account, and a convincing story. It frequently delivers the initial access that later malware (trojans, ransomware, spyware) rides on.
Phishing and Related Email Attacks
Phishing is fraudulent communication — classically email, but also SMS (smishing) or messaging apps — that impersonates a trusted entity to steal credentials, payment data, or to get the victim to run malware / visit a malicious site.
Variants Worth Knowing
| Variant | Distinguishing trait |
|---|---|
| Phishing | Broad, volume-based lure |
| Spear phishing | Targeted at a specific person or small group using personal/organizational details |
| Whaling | Spear phishing aimed at high-value executives or commanders (“big fish”) |
| Business email compromise (BEC) | Often impersonates a leader or vendor to redirect funds or data — may have little/no malware |
Mission Example
A spear-phishing email mimics a base helpdesk notice: “Mandatory CAC PIN reset — verify at the link below.” The page looks official. An airman enters credentials. Attackers now have a foothold for mailbox theft, further phishing from a trusted address, or VPN access if passwords are reused. Confidentiality of mail and availability of accounts (lockouts, abuse) both suffer.
Red Flags (Exam and Real Life)
- Mismatched or lookalike domains (
airforce-helpdesk-support.comvs official domains) - Generic greetings with urgent threats
- Unexpected attachments (
.exe,.js, macro documents) or links to credential forms - Requests that bypass normal ticket/helpdesk procedures
- Slight anomalies in display names versus actual addresses
Technical defenses: email filtering, attachment sandboxing, multi-factor authentication (MFA) so a stolen password alone is insufficient, and browser isolation. Human defenses: pause, verify through a known-good channel, never use contact info supplied inside the suspicious message alone.
Vishing (Voice Phishing)
Vishing is social engineering conducted by voice — phone calls, VoIP, or voice messages. Attackers may spoof caller ID to look like a base operator, bank, or command post.
Common Vishing Patterns
- Pretending to be IT support needing a temporary password or MFA code “to fix your account”
- Claiming to be from security investigating “suspicious logins” and asking the user to read a one-time code (which actually completes the attacker’s login)
- Threatening administrative action unless the victim “confirms” PII immediately
Mission Example
A caller claims to be from the communications squadron and asks an operator to read the six-digit code that just appeared on their phone “so we can clear a false alarm.” That code is an MFA challenge the attacker triggered. Handing it over defeats MFA and yields session access — a confidentiality breach enabled entirely by voice social engineering.
Defense habit: Legitimate IT almost never asks you to read them your MFA codes or passwords. Hang up and call back using an official number from a directory or the back of your CAC/badge process — not the number the caller provides.
Pretexting
Pretexting is creating a fabricated scenario (the pretext) to persuade a target to disclose information or perform an action. Phishing and vishing often use a pretext; pretexting as a term emphasizes the crafted story and identity, which may unfold over multiple contacts and channels (email then phone then in-person).
Examples of Pretexts
- Researcher conducting a “security survey” that asks for internal IP schemes or tool names
- Vendor “verifying” invoice routing and banking details
- New teammate who “lost access” and needs a shared drive permission change
- Law-enforcement or inspector persona pressuring for quick cooperation without verification
Mission Example
An adversary emails a unit admin claiming to be from a higher headquarters staff office preparing an inspection. They request a current network diagram and a list of privileged accounts “by end of day.” The story (pretext) supplies urgency and authority. If the admin complies without verifying through known command channels, confidentiality of defensive architecture is compromised — gold for a later technical intrusion.
Defense habit: Verify unusual requests through a second channel you already trust. Procedures exist because social engineers invent emergencies that skip them.
Tailgating (Piggybacking)
Tailgating is physical social engineering: an unauthorized person follows an authorized person through a controlled entry point without presenting their own credentials. Closely related piggybacking sometimes emphasizes the authorized person knowingly allowing it; exam language often treats tailgating as the follow-through problem either way.
Why It Matters for Cyber
Cybersecurity is not only packets. A person who tailgates into a SCIF-adjacent space, server room, or open desk area can plant hardware keyloggers, steal badges, access unlocked workstations, or insert malicious USB devices. Physical access often bypasses months of network hardening.
Mission Example
At shift change, someone in a convincing uniform carries a stack of boxes and asks an airman to “get the door.” The airman complies to be polite. Inside, the intruder photographs badge boards or plugs a rogue device into a conference-room network jack. The initial failure was human and physical — the technical compromise follows.
Defense habits: One badge, one entry. Offer to escort visitors through official visitor control. Do not hold secure doors for unknown people. Challenge politely when policy requires it — courtesy does not override access control.
Human Factors as a System Layer
Treat people like any other control surface:
| Layer | Examples |
|---|---|
| Awareness | Continuous training, phishing simulations, reporting culture without humiliation |
| Process | Out-of-band verification, dual control for money/data transfers, visitor escorts |
| Technical | MFA, email authentication (SPF/DKIM/DMARC concepts at a high level), least privilege, screen locks, USB controls |
| Physical | Turnstiles, guards, anti-tailgate doors, clean desk, badge checks |
Attackers chain techniques: spear phish for credentials → vish for MFA code → use access to email a pretext to another office → eventually get a network map. Breaking any link helps.
CT Scenario Strategy
When a question describes an attack:
- Identify the channel — email (phishing), voice (vishing), story/identity play (pretexting), physical follow-through (tailgating).
- Identify the goal — credentials, malware execution, information disclosure, physical entry.
- Match the best defense named in the options — verify out-of-band, MFA, do not share codes, do not hold the door, report to security.
Do not overfit brand-new buzzwords. The four terms in this section — phishing, vishing, pretexting, tailgating — cover the vast majority of human-factor items at Cyber Test depth. Remember that social engineering often enables the malware families from the previous section; humans and code attacks reinforce each other.
An attacker calls an airman, claims to be base IT, and asks the airman to read aloud the one-time code that just appeared on the airman’s phone. This is best classified as:
Someone without a badge walks closely behind an authorized member through a badge-activated door into a controlled work area. Which social-engineering technique is this?
A highly personalized email to a squadron commander references a real upcoming inspection and asks for an immediate wire-transfer approval via a reply. This is best described as:
Which defensive action best counters a pretexting attempt that asks an admin for internal network diagrams “for a headquarters inspection”?