Accessibility Statement Skip Navigation
  • Resources
  • Investor Relations
  • Journalists
  • Agencies
  • Client Login
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • English-only
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business & Money
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

      • In-Language News

      • Arabic
      • español
      • português
      • Česko
      • Danmark
      • Deutschland
      • España
      • France
      • Italia
      • Nederland
      • Norge
      • Polska
      • Portugal
      • Россия
      • Slovensko
      • Suomi
      • Sverige
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • ALL CONTACT INFO
    • Contact Us

      888-776-0942
      from 8 AM - 10 PM ET

  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS

Interview With a Hacker: What Companies Need to Know to Protect Themselves


News provided by

E-Complish

Sep 24, 2018, 11:00 ET

Share this article

Share toX

Share this article

Share toX

NEW YORK, Sept. 24, 2018 /PRNewswire/ -- E-Complish wants to help its customers better protect themselves against system infiltration through phishing and other attacks on their employees. Phishing and other forms of social engineering have become a significant problem for businesses of all sizes. Statistics tell the tale: Wombat Security's "State of the Phish" report indicates that 76 percent of businesses reported being a victim of phishing last year, and the Webroot Threat Report reveals that nearly 1.5 million new phishing sites are created each month. What's more, according to the 2018 Verizon Data Breach Investigations Report, 30 percent of emailed phishing email messages are opened by targeted users, and 12 percent of these users click malicious links within these emails.

Continue Reading
E-Complish, Inc.
E-Complish, Inc.

With this in mind, we conducted an exclusive interview with an "ethical hacker"—an information security expert who, with companies' permission, attempts to penetrate systems to assess them for vulnerabilities that could be exploited by malicious hackers. Here, from our question-and-answer session, is what companies need to know about hacking.

Q: What methods do hackers use in order to compromise organizations' systems?

A: Social engineering and phishing are the most common; it is far easier than looking for network vulnerabilities when the objective is to infiltrate a company's system. In some cases, hackers engage in social engineering and phishing by sending a mass email to a group of employees, asking them to click on a link to a page where they will provide information that will allow them entrée into a company's system. But more commonly and for the same purpose, they will use information found elsewhere—on social media sites like Facebook, Instagram, and Twitter—to create tailored emails for tailored phishing attacks. People tend to open these emails more readily because they appear to come from a legitimate source—a source whose information hackers have found utilizing social media. In both situations, hackers will create a sense of fear and urgency, using phrases such as "Can you look at ___?" or "Help me by clicking this link."

Hackers also use the fear and urgency ploy in social engineering that happens on the telephone. Here, they use information found on business cards, LinkedIn, and other social media to contact an employee of the targeted company and pose as another employee or as a manager looking for assistance in accessing the organization's website or system. They often ask what the employee can see on his or her end or what he or she is working on in a bid for "help" in accessing the system.

Then, there is the "phishing in the middle" attack. To carry it out, hackers create a fake email from an outside entity—one that does not look like the phishing emails described above—and send it to an individual at a targeted company—the "middleman," so to speak Clicking a link in that email generates a mass phishing email to other employees of the company that appears to come from the "middleman," but is really hackers' entrée to the company's system.

Another method harnessed by hackers to infiltrate companies' systems involves the use of a fake email that directs employees to a "mandatory online security training" course. Once the course is completed, employees are directed to a survey about the course or to install a program to certify that they have taken it; these are intended to "grab" employees' credentials so that the hacker in question can get into the system.

Other phishing schemes include the sending of emails informing employees that their credentials have been changed or that new stock or benefits packages are available, and requesting that they click on a link to view their updated domain name and password or the new benefits. Doing so places employees' credentials directly under hackers' noses.

Q: How do hackers leverage Facebook, Instagram, and other social media to achieve their goals?

A: Hackers use Facebook, Instagram, and other social media to obtain a raft of personal information they can use to target employees, as well as to tailor phishing emails to particular individuals. They also rely on social media, especially Instagram, to find pictures that give them more insight into their targets—for example, what they like to do in their spare time, what type of pets they have, and even images of targets' badges. Additionally, social media is a good source of pictures of companies. From there, hackers can find out a lot about companies, specifically the types of systems they use and the way their facilities are laid out. It makes it easier for them to plan virtual and physical infiltrations.

Q: What are the specific things hackers look for on social media?

A: In addition to photographs, hackers look for workplace information, names of friends and business connections, telephone numbers, email addresses, birthdays, anniversaries, names of family members, details of activities and group affiliations—anything that can be used to get them an "in" in the schemes described above. On LinkedIn, specifically, they try to find the chain of command within the companies they are targeting, so that an email from a "manager" or superior looks legitimate.

Q: For hackers, what is the lowest-hanging "fruit" hackers try to pick, that they may not have thought of?

A: Any information that is posted on social media profiles is it, because as described above, it can so easily be used to give hackers an advantage. This includes birthdays, anniversaries, kids' names, kids' birthdays, and pets' names, as well as the work-related information found on LinkedIn. Companies cannot always tell employees what they can and cannot post—they can ask that their name not be on employees' Facebook page, but probably cannot say anything about revealing birthdays. However, they can suggest using caution.

Q: How do hackers gain credibility with the people with whom they are communicating?

A: It is easy. Just the way I described above, they scour social media, like LinkedIn, to find out whom the person they are targeting works. Then they refer to that person in the conversation. For example, if they have found out that an employee's manager is named Bill, and they want to get into a company's system, they will write in an email, "I work with Bill. Can you please check this link for me?" Or, they will see into which department an employee's responsibilities fall and find out on social media who is in charge of that department, and use his or her name in the communication.

Q: What about physically infiltrating a facility? What common methods of infiltration typically work?

A: Hackers always look and act like they belong. For example, if they are walking into a facility's lobby, they just follow the crowd, without hesitating and looking straight ahead. If there is some type of physical security in place—like a door or entryway that can only be opened by swiping a card or badge—they will go through with someone else. This is easy, because most people are polite and will hold a door, and it even works at government agencies and big companies that have not put an extra measure in place, such as looking at IDs up close.

It's important to point out that requiring employees to wear ID badges at all times isn't foolproof. Hackers are very good at making counterfeit badges, which they can easily do by using images of employee badges posted on social media. All that is necessary is to swap out the employee's name for their own name.

Q: What techniques do hackers use when speaking in person with a company receptionist or employee?

A: They try to create a rapport with the person, possibly using the information they have found on social media. For example, they will try to talk about sports if they have seen on social media that the person enjoys sports. This helps them gain the person's trust and get him or her to do what they want, whether it's providing physical access to a company's system, revealing a password, or something else.

Hackers may also attempt to generate a sense of urgency or fear, in the same way, they do on the telephone. In this case, they will pose as an employee from another office, or as an outside service person, and say they need help accessing the company's system or something of the kind.

Q: What is the easiest method used by hackers to infiltrate a data center?

A: Hacker would act as a technician would, gaining physical access by saying they are from a computer company and are there to check the temperature in the data center, or to look at connections to secondary equipment—any nonsense that references equipment and sounds real. If asked, they will use a false company name, usually one that includes a reference to technology, such as "Tech Serve." This strategy works 99 percent of the time.

Q: What are some of the simplest things companies can do to foil hackers, but may not think of doing?

A: Proper security awareness training is critical in preventing data breaches. Teach employees what malicious emails and phishing attacks look like and things to look for, such as obvious grammatical errors and misspellings or mentions of association with other employees or managers whose name they do not recognize. Instruct them not to click on any links.

Setting company password safety practices are also important. Passwords should be a good 10 to 12 characters long, with a mix of upper- and lower-case letters, numbers, and special characters. They should never contain the company's name or the season (e.g., "fall 2018"). If employees are choosing their own passwords, instruct them not to use information that can be found on social media (such as a birthday, anniversary, or pet's name) and should not be there in the first place. The more employees companies have, the more difficult it will be to ensure proper security awareness training, but it is a must anyway.

Ensuring that employees have access only to the data they need to do their jobs is important, too, so be certain to segment data into silos that cannot be "touched" except by employees who require it. Employees in the marketing department, for example, should not be able to access the personnel database.

Q: What should companies do first if they know or suspect that a data breach is occurring or about to occur?

A: If it is a remote breach, start to unplug all the systems and report the suspicions or occurrence to security. Try to find out who received a suspicious email and who clicked on it, and isolate it before it spreads. If credentials have been phished and it is impossible to detect who clicked a suspicious link, it may be a best practice to reset everyone's credentials immediately. Whatever the situation, it is imperative to work very quickly.

If it is a physical infiltration, ask the person who he or she is and why they are there. Follow them around. When in doubt, ask them to leave.

About E-Complish

Since 1998, E-Complish has provided merchants around the country with top online and over-the-phone payment processing services that keep customer data secure and make it easier for retailers to manage transactions. E-Complish uses the latest groundbreaking technology to design payment processing services that deliver ease of use, accuracy, dependability, personalization capabilities and automation that improves productivity.

Contact

Marc Hopkins

Vice President of Strategic Relations

[email protected]

888-847-7744 x205

SOURCE E-Complish

21%

more press release views with 
Request a Demo

Modal title

Contact PR Newswire

  • Call PR Newswire at 888-776-0942
    from 8 AM - 9 PM ET
  • Chat with an Expert
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices

Products

  • For Marketers
  • For Public Relations
  • For IR & Compliance
  • For Agency
  • All Products

About

  • About PR Newswire
  • About Cision
  • Become a Publishing Partner
  • Become a Channel Partner
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Italy
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • Vietnam

My Services

  • All New Releases
  • Platform Login
  • ProfNet
  • Data Privacy

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact PR Newswire

Products

About

My Services
  • All News Releases
  • Platform Login
  • ProfNet
Call PR Newswire at
888-776-0942
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookies
Copyright © 2025 Cision US Inc.