Skip to content
CBT Nuggets
DemoBook a Demo

Protect Yourself from Social Engineering and Email Phishing

This skill, led by Keith Barker, focuses on protecting against social engineering and phishing attacks. It covers various techniques used by attackers, such as phishing, vishing, and impersonation, and provides practical examples and strategies to identify and avoid these threats. The content is beneficial for all roles and emphasizes the importance of security awareness and proactive measures to safeguard personal and organizational information.

Full skill from Cybersecurity Awareness Online Training. Preview the IT training 23,000+ organizations trust.

28m

Skill 1 of 6 in Cybersecurity Awareness Online Training

Overview

Join Keith Barker as he teaches you how to protect yourself against social engineering phases and techniques, such as phishing attacks.

What is Social Engineering?

Keith describes, and provides examples of, social engineering, as well as common methods used to trick users into actions that can compromise security.

Knowledge Check

Based on the video, which of the following behaviors are reasons why social engineering is successful against a victim? (Choose four)

Social Engineering Phases and Techniques

Keith talks about the strategic phases and techniques a social engineer may use to compromise a company.

Knowledge Check

Place the following social engineering phases in the correct order:

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

What is Email Phishing?

In this Nugget, Keith answers the question, "What is phishing?"

Knowledge Check

Which of the following are true? (Choose two)

Protecting Yourself From Phishing Attacks

Keith describes the concept of phishing, as well as the techniques you can use to protect yourself and your company from these types of attacks.

Knowledge Check

Hovering over a link without clicking it may reveal the URL or location that a user would be taken to if they clicked on that link. True or false?

Want to answer questions like this yourself?
with no purchase required. Already have an account?

Knowledge Check

What is the likelihood of the Internal Revenue Service contacting you with an email, encouraging you to click a link to claim your tax refund?

Knowledge Check

Which of the following are guidelines for staying safe were presented in this Nugget? (Choose four)

Hacker and Attacker Motives

Keith talks about some of the motivations behind the activities of hackers and attackers. A better understanding of their motives can help you be more aware of potential security breaches.

Knowledge Check

Which of the following has amazing computer hacking skills but does nothing unlawful?

An ounce of prevention is worth a pound of cure.
An ounce of prevention is worth a pound of cure.

Conclusion

I hope this has been informative for you and I would like to thank you for consuming.

View Transcript

What is Social Engineering?

0:00The concept and the idea of bamboozling--

0:03of tricking a user into doing some action or behavior that

0:06they otherwise wouldn't-- is one of the easiest ways

0:09to compromise a system.

0:11And it's referred to as social engineering.

0:13To begin, let's you and I take a look

0:15at some examples of social engineering.

0:17Here on the left, I got an email message that, from my inbox,

0:20appeared to come from my daughter.

0:21But upon closer inspection of the email,

0:23it was not my daughter's email address.

0:25And in the email, it was attempting

0:27to have me click on some link.

0:29And that's an example of phishing, where the attacker is

0:32attempting to bamboozle the user into doing something

0:35that they normally wouldn't do, or shouldn't do.

0:37Another example that recently happened

0:39was a text message I got from a friend.

0:41And in this text message, it had a link.

0:42And right before the link it said, hey,

0:44get on this so we can chat.

0:45And then it had a link.

0:46And it had my name embedded as part of that link.

0:49So although it's possible that I could have a friend who

0:51created the link and wanted me to go ahead and jump

0:53on it to chat, it's probably not likely, especially in the event

0:56that there's so many other ways of traditionally communicating

0:59with another user, or another person.

1:01So I responded back, and I said, are you OK?

1:03And then she responded back.

1:04And she said, my phone has been hacked.

1:06Now the other thing we could do possibly too,

1:08is with these URLs that we have in the links,

1:10we could go up to virustotal.com,

1:12put in those URLs, and just get an opinion of the website.

1:15But what we would never want to do is click on these links

1:18directly to see, hey, I wonder what's there.

1:20So the old saying that curiosity killed the cat--

1:23that's a pretty good saying.

1:24Because curiosity also is what can kill

1:26the security of an end user.

1:28And then another example is a piece of paper

1:30that showed up on one of my relative's doorsteps.

1:33And it had the information up here-- sorry we missed you.

1:35It looked like a delivery had been attempted.

1:37So they're asking us to go ahead and call this number,

1:40and then provide a confirmation ID.

1:42And it says, oh, please see the important notice on the back.

1:44Well on the back, it says that if you call that number,

1:47you're giving them permission to go ahead and do marketing

1:49to you at that number.

1:50There was no package involved ever.

1:53And one of the questions that we may ask is why.

1:56Why is social engineering and the human factor

1:59such a huge risk in organizations today?

2:01And there are some fundamental behaviors

2:03that makes individuals like you and I vulnerable to attacks

2:07with social engineering.

2:08And those behaviors include trust.

2:11Because at some level, most people

2:13want to trust other people.

2:15Another factor is ignorance.

2:17Specifically I don't mean ignorance in general,

2:20but ignorance regarding social engineering.

2:22There also could be ignorance regarding

2:24how devastating the result could be if a social engineering

2:27attack is successful.

2:28Another factor is fear.

2:30For example, if there's a Vishing attack which involves

2:34a telephone-- and the V in Vishing is for voice--

2:38the attacker, possibly using hypnotic language,

2:40could convince the other person on the line

2:42that something really bad is going to happen unless they

2:45comply-- for example, the IRS is auditing you,

2:48and you need to pay this money, and do it right now,

2:50or some other activity that the user would normally never do.

2:53Fear also comes into play if somebody's system

2:55has been encrypted, and ransom is being requested.

2:59The fear of losing that important data may

3:01lead that user into doing something that otherwise they

3:04wouldn't, including paying ransom in an attempt to get

3:06the keys to unlock the data.

3:08There also could be greed involved.

3:10Perhaps a user at a company has been there for a long time.

3:13They feel they've been taken advantage of,

3:15and as a result might comply and do

3:16something illegal or unethical to get

3:18personal gain at the cost or expense of the company.

3:21And what I also like the list here

3:22is moral obligation, where the victim or the target

3:26feels that they're morally obligated to help

3:28another individual.

3:29They may not realize they are helping an attacker,

3:31but they feel like they're just doing the right thing.

3:33For example, there's a few people on a smoke break.

3:36They're all coming in.

3:37And one of them comes in, has a box that they're carrying,

3:39so some other person holds the door for them.

3:41And unknowingly, it's an attacker with a fake badge--

3:44he's dressed like the other workers--

3:46who has now entered the physical premises

3:48and is one step closer to compromising the company.

3:51I hope this has been informative for you.

3:54And I'd like to thank you for viewing.

Social Engineering Phases and Techniques

0:00There are people whose sole purpose

0:03is to compromise a company.

0:04In this Nugget, you and I get to talk about some

0:06of the techniques that we can be aware of and look out for

0:09as well as the stages that a social engineer can go through

0:13to compromise a company.

0:14Let's begin.

0:15So here are the four basic phases in a social engineering

0:18attack.

0:19Number one, there's going to be research on the target company.

0:21And then once the research has been done,

0:23a victim is selected.

0:24It could be a frustrated individual or simply

0:26an easy target.

0:28Then the hacker could develop a relationship or a friendship

0:31with that selected target.

0:32And that relationship could be built physically

0:35by going to common places, such as restaurants

0:37or bars or other activities that the victim has interest in,

0:41or it certainly could be done digitally,

0:42by the attacker identifying what the user is interested in,

0:45creating a bogus social media page,

0:48and then slowly and comfortably building

0:50a relationship that way with the intended target.

0:53Then the final goal is for the attacker

0:55to exploit that relationship to collect sensitive information

0:58or get access to details that they otherwise shouldn't

1:01have through the victim.

1:02One of the techniques the social engineer may use

1:05is impersonation, where they are pretending

1:07to be someone legitimate or an authorized person

1:09when they're not really that person.

1:11And the communication method could be one of many things.

1:13It could be email.

1:15It can be a telephone call.

1:16It could be through social media or it

1:18could be physically in person.

1:20And the goal of that impersonation

1:21is to try to trick the user into revealing sensitive information

1:25and/or doing some type of activity that's

1:28going to benefit the attacker.

1:30Some examples of impersonation may

1:31be the attacker calling the desk and saying something

1:34like, hi, this is Bob from human resources,

1:37I forgot my password, I can't get in, can you help me,

1:40or posing as an important user.

1:42And that may go something like this, oh my gosh,

1:45JJ Abrams is on the set.

1:46I'm the executive assistant for him.

1:48He cannot get into email.

1:49He's got 10 minutes before he has to go ahead and go

1:51to another meeting.

1:52He needs help.

1:53And he needs it right now.

1:54And I don't know JJ Abrams.

1:55But when I worked at Paramount Pictures,

1:57we had some very important individuals on the lot.

1:59And whenever their name was called out,

2:01people got an additional pump of adrenaline to get the job done.

2:05So that could be used as part of impersonation as well.

2:07Other techniques include eavesdropping, just listening

2:10in on conversations that otherwise shouldn't be public,

2:13or shoulder surfing, which is looking over another person's

2:15shoulder as you're typing or you're seeing information

2:18on their screen.

2:19There's dumpster diving, where the attacker

2:21is going into the trash receptacle at the place

2:24of business, looking for information

2:25that's been thrown away.

2:26It hasn't been disposed of or destroyed properly.

2:29There's also the concept of tailgating or piggybacking.

2:32And that's when we have a secure access into a facility.

2:35That secure access might be a door

2:37or it could be a mantrap, which is

2:39intended to only let the authorized individual through.

2:42And through social engineering, the attacker

2:44attempts to have that bypassed by either carrying a box

2:48or getting some other method to have an authorized user allow

2:51the unauthorized user into the physical premises.

2:53And on the computer side of social engineering,

2:56we have techniques like pop-up windows or hoax letters

2:58or chain letters or messages that pop

3:01up on screens or instant messenger

3:03type of communications or spam or fake websites

3:07or redirection of the customers to fake websites, all of which

3:10could encourage that user to click or do something that

3:13would compromise their system.

3:14And the difference between a phishing attack,

3:16which is email-based-- trying to get the user

3:18to click or do or install something

3:19based on an email that was sent to them-- versus a spear

3:22phishing attack is that a spear phishing attack

3:24is directed at specific individuals,

3:26for example, in the company.

3:28So when the attacker discovers that Bob really loves cars,

3:31perhaps a .PDF is created that's malicious.

3:34But the PDF is all about the type of cars

3:37that Bob is interested in.

3:38So the email is sent to Bob appearing

3:40to come from someone else that's non-malicious with the hopes

3:43that Bob will click on that link or open that PDF, which

3:46then leads to the compromise.

3:48I hope this has been informative for you.

3:50And I'd like to thank you for viewing.

What is Email Phishing?

0:00So let's begin with the interesting spelling

0:02of phishing.

0:02They swap out the f-- as in normal fishing,

0:05like fishing for trout, or bass, or what have you--

0:07with a ph for the f.

0:09That's a hacker thing that goes way back.

0:11And that's why it's called phishing,

0:12with a ph instead of f.

0:15And what the attacker or hacker is trying to do

0:17is to bait a user, to tempt user to do some activity in order

0:21to compromise that user, for example,

0:24to reveal their username and password,

0:26or perhaps reveal information that otherwise shouldn't

0:28be available to the attacker.

0:30And phishing is done primarily through bogus e-mails that are

0:33being sent to an individual.

0:35And that email that's being received by the victim

0:38is made to look as official or authoritative as possible.

0:42And that email that the victim receives

0:44is going to have either an enticing, or some kind

0:46of urgent request, that the attacker is

0:49hoping the victim will act on.

0:51So let's consider together for a few moments

0:53some of the e-mails that we would

0:54get that would entices to, for example, click on something,

0:57or do some activity.

0:58Several things come to mind.

0:59Maybe there's a security alert.

1:01That could come from a bank, or from our company,

1:03or some other organization that we trust.

1:06But instead of actually being a legitimate e-mail

1:08from that source, it's a bogus e-mail

1:10made to look like it came from an official source.

1:12Another one is vacation time, or vacation policy at work.

1:15So if we're at work, and we just got an e-mail saying

1:17we've just revised the vacation policy.

1:20And to see that new policy, they give us a link to click on.

1:23The link in that email, although it may look innocent,

1:25if it's sent from the attacker, that link

1:27is going to lead to something malicious, which could include

1:30a fake web site completely made by the attacker,

1:33which looks legit.

1:34So to see the vacation policy, we

1:36need to put in our username and password.

1:38And once we supply that information

1:39at that fake website, it's over.

1:42The attacker now has the username and password,

1:44because we just supplied it through the fake website.

1:47Another type of e-mail that we're used to getting

1:49is for deliveries-- for example, the United States Postal

1:52Service, or UPS, or FedEx.

1:55And a lot of times, they'll have links in those emails

1:58to track a package.

2:00If the attacker has sent us that fake e-mail, and the link

2:03in that e-mail-- although it may look good--

2:05leads us to a malicious site.

2:07That's one step closer to the attacker

2:09compromising us-- the individual who's reading and acting

2:12on that email.

2:14And the list goes on.

2:15And while phishing is email based,

2:17there's also specific types of phishing

2:19that an attacker or a hacker can do.

2:21There is something referred to as spear phishing.

2:24So instead of just casting the bait

2:26and sending it out to millions of people, with spear phishing,

2:29it's actually targeting specific individuals, for example,

2:32specific individuals at a department at a company,

2:35or members of a group.

2:36And there's also another option called whaling, where

2:38we're going for a big phish.

2:40And that would be at, for example,

2:41senior executives, senior management,

2:43in an attempt to have those individuals do something

2:46that they otherwise normally would not do.

2:48An example would be an email requesting authorization

2:51for a wire transfer of money.

2:53And perhaps a big transfer, like, millions of dollars,

2:55does have to be approved by multiple people.

2:58But if all those people can be phished

3:00in a very timely manner, where each

3:02of the victims in the attack believes

3:03that the appropriate approvals have been done--

3:06a coordinated e-mail attack like that

3:08could result in not only a monetary loss

3:10based on a wire transfer that's being

3:12sent to the wrong individuals, but also public humiliation

3:15based on a corporation losing millions of dollars

3:18and having that information being publicly known.

3:21That company is going to lose some trust

3:22as a result of falling for the phishing attacks.

3:25There's also an option called vishing,

3:27which instead of using e-mail, it uses the telephone.

3:30And that's why there's a v there for vishing.

3:32A quick example of that would be getting a phone

3:34call from someone claiming to be the IRS, or the sheriff,

3:37or some other authoritative figure,

3:39indicating that there's some urgent need,

3:41there's some cause for action.

3:43A quick example of that-- my son moved out

3:45of state a few months ago.

3:47And in doing so, he rented a moving truck.

3:50And while he was traveling, my father--

3:52my son's grandfather-- got a call.

3:55And the call when something like this.

3:56Your grandson, Paul, was in a motor vehicle accident

4:00as he was traveling to Oregon.

4:02And he's not in critical condition.

4:04He's going to be OK.

4:05He has a few stitches.

4:06He's recovering.

4:07And this is going to lead eventually

4:09to the attacker eliciting money from my father on behalf

4:13of his grandson.

4:14Now fortunately, this has a pretty happy ending

4:17on two counts.

4:18Number one, my son was not involved in any accident.

4:22This was a total scam-- a vishing scam.

4:24The second good part of this story

4:25is that my father, although well in his 80s,

4:28is very aware of scams of many types.

4:31So my dad, he just come off the caller and said,

4:34you know what, you should call his parents-- click.

4:37And so the thing that blows me away

4:39about that type of an attack is the timing.

4:42That means the rental company that was renting the truck--

4:45those records were not secure.

4:46That information was being leaked out somewhere.

4:48And the attacker had that information.

4:51And then the attacker, furthermore,

4:52after having that knowledge, also probably knew

4:55that the parents of that person, in this day and age,

4:57have cell phones, and get contacted all the time,

5:00and could reach out directly if there

5:02was a problem or an incident to their son,

5:04where a grandfather might be a little bit further removed,

5:08and possibly a better victim.

5:10So in this idea of tricking an individual to divulging

5:13or providing something that they otherwise wouldn't, the attack

5:16could come from e-mail, or from social networking.

5:19I mean, maybe it looks like a greeting card.

5:22And it says, click here to open your birthday greeting.

5:24Now in a phishing attack, there's very likely

5:26going to be a link or attachment in that e-mail

5:30that the attacker hopes that the user will

5:32click on or open-- if it's an attachment--

5:34to compromise the user.

5:35In the past, many of these phishing e-mails

5:38have had poor grammar and bad spelling.

5:40But as technology gets better, and the attackers get better,

5:44the e-mails oftentimes look very, very authentic and very,

5:47very legit.

5:48I hope this has been informative for you.

5:51And I'd like to thank you for viewing.

Protecting Yourself From Phishing Attacks

0:00In this Nugget, I'd like to chat with you

0:01for a few minutes about how we can both identify

0:04a malicious email.

0:05And then secondly, and more importantly,

0:08how to avoid being tricked by one.

0:10So I thought it would be fun and effective for both of us

0:12to take a look at some examples of phishing emails.

0:15So I'm just going to do a quick search for phishing examples

0:18in a browser.

0:20Next let's click on the images link right here.

0:22So let's go up and grab this one from PayPal right here.

0:24So here in the subject of this email,

0:26it specifies that your account has been limited.

0:29It's also got here a call to action to log into your account

0:32now.

0:33Now oftentimes, if you hover over a link,

0:36it will reveal the details regarding

0:38that URL or that link.

0:39So a well-crafted email could put anything here

0:42as far as the thing that you click on,

0:43and then behind the scenes, what it's

0:45going to could be completely different.

0:46And that's how the attacker could

0:48trick an otherwise unknowing individual to click on

0:51that link go to a fake website, which may appear

0:54to be a legitimate website.

0:56At which point, the user is very likely

0:57going to be prompted to provide their username and password.

1:00The attacker slash hacker has compromised the user,

1:03because he or she now has the username and password

1:06of that user for PayPal.

1:08If we look at some other examples

1:09here in this email, which is intended to look like it

1:12came from the IRS.

1:13It's about claiming your tax refund online.

1:16There's a link here to get started,

1:18and then the user, when they click on that link,

1:20it's very likely that on the website they land on,

1:22it's going to ask them for information regarding,

1:24for example, what is your social security number?

1:27What is your date of birth, which will allow the attacker

1:29slash hacker to then collect that information

1:32and then use it later anyway they see fit.

1:34And there's no shortage of examples.

1:36If you just want to do a quick search on phishing

1:39email examples or phishing examples,

1:41there's tons, and tons, and tons that are out there.

1:43So let's minimize that.

1:45And let's take a look at what we can do, in measurable terms,

1:48to stay safe.

1:49That will protect, not only us, but also our companies as we

1:52work with emails.

1:54Number one, don't trust links that come in an email.

1:58If the bank, or the financial institution, or your company

2:02is sending you an email with a link in it, don't use it.

2:06It's really that simple.

2:07And the question may come up, well,

2:09what if it really is an alert from the bank

2:11and I need to go verify it?

2:12Well, the solution to that is, go ahead

2:14and open your own browser, put in the URL yourself

2:18to go to the bank.

2:19Log in, as you normally would, through your separate browser,

2:22not using any links from the email, and do it that way.

2:26Number two, never, did I say never?

2:28Never give out personal or sensitive information

2:31based on an email request.

2:34Just don't do it.

2:35Number three, carefully look at the addresses.

2:38That includes the sender email address, as well as the links

2:41that are in the email.

2:42If you want to know where they're going, hover over them.

2:44Do not click on them if you want to see where they lead to.

2:48And look for typos.

2:49For example, if an email came from Payple.com,

2:55versus Paypal.com, versus Paypla.com.

3:00If we're doing a quick glance, they all

3:01may look like they're coming from PayPal,

3:03when indeed, only one is really representing PayPal.com.

3:06Also, if there's links to a financial institution,

3:10they are very likely going to have an "https" in front

3:14of them, which implies it's going

3:15to be using secure communications to connect

3:18to that resource.

3:19However, because we're not going to trust links in an email,

3:22we're never going to find out.

3:23Because we are not going to click on those links.

3:26We're just not going to do it.

3:27We're also not going to open any executables, or programs,

3:31or attachments if there's any suspicion that that email isn't

3:35authentic.

3:36So if we got an email from Microsoft.com,

3:38that kind of looks like Microsoft.com,

3:39but if that second character is a lowercase L, and not an I,

3:44that would be coming from a domain that's not Microsoft.

3:47So, continuing on our list of how you and I can be safe,

3:50here's number four.

3:51And that is to type the real address of where

3:53you want to go in a browser.

3:55Or you can do a search.

3:57And that way, if you want to go to a BankofAmerica.com

3:59you can type that in.

4:01Or if you want to go to Microsoft.com,

4:02you can type that in in a separate browser window.

4:05And again, never trust the links that are given in an email.

4:08Number five, don't use the phone numbers

4:10that are provided in an email.

4:12Because if they're bogus, you could

4:14be calling a phone number that isn't going to the destination

4:17that you think it is.

4:18And for the entity receiving that call,

4:20that would now be a vishing attack,

4:22with a "V," where their intent is to get the user, the victim,

4:26to reveal or disclose information that otherwise they

4:29shouldn't be disclosing or revealing to the attacker.

4:33Number six, now this sounds a little strong.

4:34But I'm going to go out there and say

4:36we don't want to open any attachments in email whenever

4:40possible.

4:40Because what an attacker may do is put

4:42something that looks innocent.

4:44For example, a text file, or a .PDF.

4:47When behind the scenes, when the user actually

4:50opens that attachment, it's malicious.

4:52So if you get an email from within the company

4:54or without the company, and it's got an attachment

4:57and you have any concern about, OK, why did this come in?

4:59Why am I getting this?

5:01Make a phone call.

5:02Use a method outside of that email

5:04to verify what that is that you've just been sent.

5:07And in most companies, there's an IT supplied method

5:10for sharing resources.

5:12For example, maybe it's SharePoint, or file services

5:15that are on the network.

5:16Or other methods that are provided by the IT team that

5:19facilitate the sharing of information and documents

5:21within your company.

5:22So if you have any question about, OK,

5:24what is the authorized method that I

5:25should be using to share a file, for example with a coworker?

5:29Talk to your manager, talk to the IT team,

5:31and ask them about what's supported,

5:33and the official ways of doing it.

5:34And then anything that's outside of those realms,

5:37you'd want to avoid.

5:38And if you get any email or messages that

5:40say to do otherwise, you should be very, very suspicious

5:43of that.

5:44And then number seven, I'm going to put over here,

5:46is we need to go ahead and follow our company's

5:48guidelines on reporting any types of attacks.

5:51Including phishing attacks.

5:53I hope this has been informative for you.

5:56And I'd like to thank you for viewing.

Hacker and Attacker Motives

0:00The concept of hacking refers to taking advantage

0:03of some type of system vulnerability

0:05and usually to compromise security.

0:07And oftentimes, that's accomplished

0:09by manipulating or modifying a system or an application

0:13to have it respond in a non-expected way

0:15or a non-intentional way.

0:17For example, having a network topology that's

0:19willing to advertise itself to the hacker, who

0:22is now discovering how your topology looks.

0:25Or perhaps discovering the exact version of the operating system

0:29that you're running on your server or on your desktops

0:31with the intent to further exploit or take

0:33advantage of vulnerabilities in that specific operating system.

0:37And you, like me, know that there's not just

0:40a black and white with everything in this world today.

0:43And that's also true for the various classifications

0:45or classes of hackers.

0:47For example, a black hat is a person

0:49who has some really amazing computer skills,

0:52but unfortunately, is resorting to malicious or destructive

0:55activities that are not lawful.

0:57Another classification is a white hat,

1:00and a white hat would also have some really amazing skills.

1:03However, instead of using those skills

1:04for unauthorized or illegal activities,

1:07they're using them for defensive purposes.

1:09So for example, a security consultant

1:12who does penetration testing for huge companies who gets

1:15signed authorization before he or she starts, also has

1:18identified the scope of what's allowed to be tested

1:21and has that in writing, and also signs

1:24a non-disclosure agreement before going in.

1:26That type of security consultant would be considered

1:29to be a white hat, a good guy.

1:31The next classification is a gray hat,

1:33and that would be a person who works offensively

1:35as well as defensively in the security arena.

1:38And because they may cross the line occasionally,

1:42they would not be considered a black hat or a white hat,

1:44because they go both ways.

1:46Another classification is a suicide hacker.

1:49For example, let's say that Bob discovers, through some means,

1:52that the company is downsizing in a few weeks

1:55and his job is going to be terminated

1:56and Bob is upset, disgruntled.

1:59So before Bob leaves the company,

2:01he is going to plant some logic bombs that

2:03are going to cause disruption of service at some future point.

2:06Maybe he's going to plant some Trojan horses and some malware,

2:09maybe some back doors that would provide access later

2:12after he's fired.

2:13And to top it off, he's so upset in the heat of the moment

2:17that he just doesn't care if he gets caught.

2:19That would be an example of a suicide hacker,

2:22where they're throwing caution to the wind

2:24and don't care if they get caught.

2:26They're not worried about jail time

2:27or other kind of punishment.

2:29They're just going to go ahead and do it.

2:30Another classification for hackers

2:32is called a script kiddie, which is effectively

2:34an unskilled hacker who takes advantage of a system

2:37by running scripts or tools or software that were developed

2:41by somebody else.

2:42However, the scary thing is is that virtually anybody

2:45can download a tool, click a button,

2:47and have that tool launch an attack.

2:49And that would include an experienced analyst as well

2:51somebody who's brand new.

2:52And generally speaking, when somebody

2:54calls somebody else a script kiddie,

2:56it's usually not a compliment.

2:57It usually implies an unskilled hacker.

3:00Another hacker class is a cyber terrorist,

3:02which represent people with a huge range of abilities

3:05and skills, and they can be motivated

3:07by religious or political beliefs

3:09to create fear by huge disruption of service

3:12of computers and systems of networks.

3:14Another classification would be a state-sponsored hacker.

3:18This would be an individual or group

3:19of individuals who are employed by a government or an entity

3:22such as a government to break into, to penetrate and gain

3:26top secret info, or perhaps just to damage or place

3:29bad information in other types of systems,

3:32usually in other governments.

3:34And as cyber warfare heats up and increases,

3:37the number of state-sponsored hackers is also increasing.

3:39And then the last one I wanted to chat about

3:41with you for a moment is a hacktivist,

3:43and an example of a hacktivist would be a person who's

3:46driven by a political agenda.

3:48And perhaps they want to deface or disable a website

3:51or embarrass somebody to promote their cause.

3:54Now, I've got two questions for you regarding

3:56these classes of hackers.

3:58Question number one, is it possible

4:00that an individual may be in more than one of these classes

4:04at any given time?

4:05For example, say we have a user like Bob, who is disgruntled,

4:08and he doesn't care if he gets caught.

4:10And he's also going to use some tools that maybe he

4:12doesn't completely understand that he download

4:14from the internet and is simply going

4:15to place a run on the network.

4:17Now, that's a simple example of how an individual could fit

4:19into two or more categories.

4:21And my second question for you, my friend,

4:22is which of these classes of attackers or hackers

4:25could, either through intention or accidentally,

4:28land up in really hot water and possibly be put in jail

4:32or fined or both due to their activities?

4:35Think about that for a moment.

4:36Which one of these classes of attackers

4:38could be in trouble based on using tools?

4:41And the answer to that question is

4:42that any one of these classes of attackers and hackers

4:46could end up in very serious trouble

4:48if they're not mindful and careful about the tools

4:50that they're using.

4:52In this Nugget, we've taken a look at a few classes

4:54that an attacker or a hacker may fall into,

4:57including black hat, white hat, gray hat, suicide hackers,

5:00script kiddies, cyber terrorist, state-sponsored hackers,

5:02and hacktivists.

5:03I hope this has been informative for you,

5:06and I'd like to thank you for viewing.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need Cybersecurity Awareness Online Training?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo