Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He mostly used social engineering. Not technical exploits. So that's how he succeeded. Call it crazy, but it worked.
 help



Why hack a password when you can get the employee to just tell you.

Because the employee now knows who might have done it.

The employee doesn’t know who you are. They met “Bob the support rep from Vendor xyz” who just needed access to fix an issue.

And now all that shitty KnowBe4 nonsense we have to sit through every couple of months is all "What do you do if your manager phones you up and says they're on a business trip and need you to use the company credit card to buy Amazon gift cards", over and over and over.

Bold of them to assume I'll answer the phone if I see my manager's number come up.


> What do you do if your manager phones you up and says they're on a business trip and need you to use the company credit card to buy Amazon gift cards"

If I've learned anything from the scambait people such as kitboga on youtube, if you're bored you play along with it, pretend to have acquired the gift cards, and then tell the "boss" you've scratched off and emailed their company address the codes, as the scammer on the phone wails "do not redeem! SIR DO NOT REDEEM!"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: