Social Engineering: How One Scammer Took $100 Million from Tech Giants

Google and Facebook spend fortunes on cybersecurity, yet a single Lithuanian fraudster took $100 million from the two of them over two years. He used no exploit at all. He impersonated a hardware supplier both companies worked with, mocked up official letterheads, sent fake invoices, and was paid. This episode treats that case as the entry point to social engineering, the practice of attacking the human instead of the code, and explains why it is cheaper, faster, and more reliable for an attacker than hunting for a software flaw.

The tactics each press on a hardwired trait. Pretexting builds false legitimacy from scraped personal details. Scareware goes straight for panic. Tailgating turns politeness at a secure door into a breach, while baiting and waterholing let curiosity and habit do the work. The history runs from phone phreakers such as Kevin Mitnick and Susan Headley to the RSA breach, the Sony Pictures leak, and the phishing of John Podesta in 2016. The law has tried to catch up, but no statute can patch curiosity, empathy, or fear.

  • In a 2016 University of Illinois study, 290 of 297 USB drives dropped around campus were picked up, and 135 were plugged in and opened.
  • The Badir brothers, three siblings in Israel who were blind from birth, ran an extensive telecommunications fraud scheme in the 1990s using voice impersonation.
  • The 2011 RSA hack began with emails to four employees carrying a spreadsheet titled 2011 recruitment plan.
  • Ubiquiti Networks lost nearly $47 million in 2015 to a spear-phishing email posing as an executive, recovering about $8 million.
  • Within 24 hours of Equifax launching its breach response site, attackers registered 194 lookalike domains built on typing errors.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading