Social engineering: understanding threats beyond classic phishing
The human factor remains attackers' primary initial access vector. But the techniques have evolved: phishing capable of bypassing MFA, impersonation through legitimate services, vishing... Awareness must keep pace with attackers.
The human factor, still on the front line
Social engineering — and especially phishing in all its forms (email, SMS, phone call, QR code) — remains one of the main levers for gaining initial access to an information system. It is often faster and less costly for an attacker than exploiting a technical vulnerability.
What has changed is not the principle (manipulating human trust) but the means. Ready-to-use phishing kits, the democratization of cybercrime-as-a-service and generative artificial intelligence now enable even inexperienced attackers to run convincing campaigns, including against robust technical protections such as two-factor authentication.
Emerging techniques
Phishing AiTM
The attacker positions themselves as an intermediary (“Adversary-in-the-Middle”) between the victim and a legitimate service, capturing session tokens — and effectively bypassing traditional MFA.
Vishing and hybrid attacks
A fake call from “IT support” to obtain credentials, or an email asking the recipient to call back a trapped number (callback phishing).
Hijacking legitimate services
Attackers exploit trusted platforms (document sharing, messaging) to host or distribute malicious links — an approach known as LOTS.
Targeting SaaS identities
A compromised SSO account opens access to all associated applications: identity providers have become prime targets.
Who is exposed?
Any organization with email, SaaS applications or an internal support service is exposed — size or sector does not provide protection. New joiners, employees on leave or external contractors are often preferred targets because they are more isolated and less familiar with internal verification procedures. Business Email Compromise fraud, meanwhile, primarily targets roles with access to bank transfers or sensitive data.
Audit or simulate: two complementary approaches
An audit of social engineering primarily aims to raise your employees' awareness, generally through phishing simulation campaigns that measure their ability to detect and report an attempt. In a Red Team, social engineering is one lever among others for assessing the organization's overall security, through to exploitation of obtained access. The two approaches are complementary — the first for training, the second for testing under real-world conditions.
Reducing risk, step by step
Secure email authentication
Deploy SPF, DKIM and DMARC to prevent an attacker from sending messages while impersonating your own domain name.
Strengthen authentication
Roll out two-factor authentication broadly, and consider passkeys for the most sensitive accounts, as they are more resistant to AiTM phishing.
Raise awareness beyond email
Extend awareness to vishing, QR codes and urgent or unsolicited requests, whatever the channel.
Establish secondary-channel verification
Any sensitive request (bank transfer, access reset) must be confirmed through an independent channel before execution.
Monitor risky sign-ins
Enable your identity provider's conditional access policies to detect unusual sign-ins.
Prepare the response
Define in advance the steps to take in the event of compromise: session revocation, credential rotation, immediate alerting.
Why work with BCIT?
Realistic, up-to-date scenarios
Our awareness campaigns incorporate current techniques, not only the classic malicious email.
Red Team expertise
Our Red Team exercises combine social engineering and technical exploitation to assess your overall resilience.
From awareness to technical measures
Beyond training, we support you with technical measures (authentication, monitoring) and incident response in the event of compromise.
Are your teams ready to face modern social engineering? 🚀
Let's take 15 minutes to assess your exposure and build an awareness campaign tailored to your real-world usage.
Social engineering: understanding threats beyond classic phishing
The human factor remains attackers' primary initial access vector. But the techniques have evolved: phishing capable of bypassing MFA, impersonation through legitimate services, vishing... Awareness must keep pace with attackers.
The human factor, still on the front line
Social engineering — and especially phishing in all its forms (email, SMS, phone call, QR code) — remains one of the main levers for gaining initial access to an information system. It is often faster and less costly for an attacker than exploiting a technical vulnerability.
What has changed is not the principle (manipulating human trust) but the means. Ready-to-use phishing kits, the democratization of cybercrime-as-a-service and generative artificial intelligence now enable even inexperienced attackers to run convincing campaigns, including against robust technical protections such as two-factor authentication.
Emerging techniques
Phishing AiTM
The attacker positions themselves as an intermediary (“Adversary-in-the-Middle”) between the victim and a legitimate service, capturing session tokens — and effectively bypassing traditional MFA.
Vishing and hybrid attacks
A fake call from “IT support” to obtain credentials, or an email asking the recipient to call back a trapped number (callback phishing).
Hijacking legitimate services
Attackers exploit trusted platforms (document sharing, messaging) to host or distribute malicious links — an approach known as LOTS.
Targeting SaaS identities
A compromised SSO account opens access to all associated applications: identity providers have become prime targets.
Who is exposed?
Any organization with email, SaaS applications or an internal support service is exposed — size or sector does not provide protection. New joiners, employees on leave or external contractors are often preferred targets because they are more isolated and less familiar with internal verification procedures. Business Email Compromise fraud, meanwhile, primarily targets roles with access to bank transfers or sensitive data.
Audit or simulate: two complementary approaches
An audit of social engineering primarily aims to raise your employees' awareness, generally through phishing simulation campaigns that measure their ability to detect and report an attempt. In a Red Team, social engineering is one lever among others for assessing the organization's overall security, through to exploitation of obtained access. The two approaches are complementary — the first for training, the second for testing under real-world conditions.
Reducing risk, step by step
Secure email authentication
Deploy SPF, DKIM and DMARC to prevent an attacker from sending messages while impersonating your own domain name.
Strengthen authentication
Roll out two-factor authentication broadly, and consider passkeys for the most sensitive accounts, as they are more resistant to AiTM phishing.
Raise awareness beyond email
Extend awareness to vishing, QR codes and urgent or unsolicited requests, whatever the channel.
Establish secondary-channel verification
Any sensitive request (bank transfer, access reset) must be confirmed through an independent channel before execution.
Monitor risky sign-ins
Enable your identity provider's conditional access policies to detect unusual sign-ins.
Prepare the response
Define in advance the steps to take in the event of compromise: session revocation, credential rotation, immediate alerting.
Why work with BCIT?
Realistic, up-to-date scenarios
Our awareness campaigns incorporate current techniques, not only the classic malicious email.
Red Team expertise
Our Red Team exercises combine social engineering and technical exploitation to assess your overall resilience.
From awareness to technical measures
Beyond training, we support you with technical measures (authentication, monitoring) and incident response in the event of compromise.
Are your teams ready to face modern social engineering? 🚀
Let's take 15 minutes to assess your exposure and build an awareness campaign tailored to your real-world usage.