Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why LinkedIn is a hacker’s prime target

by The Gurus
July 7, 2016
in Opinions & Analysis
Share on FacebookShare on Twitter

Professional social networking site LinkedIn has proven to be a valuable business tool, bringing together professionals from all over the world. But few corporations grasp the security risks that the use of LinkedIn represents. The main problem is not with the LinkedIn website’s own digital security but with a widespread corporate ignorance of the way the organised criminal gangs (OCGs) who make billions, sometimes tens of billions of dollars, from cyber crime work.
The hackers are now using well-known brands names such as Standard Chartered Bank on LinkedIn to attract senior executives to divulge information that they can use. It’s all very plausible unless you know what to look for.
Using a process called ‘social engineering’, OCGs assemble as much information via the Internet as they can on a target subject within an organisation that has been identified as likely prey. LinkedIn is proving a rich vein for OCGs. Executives have become too cavalier about posting details of their movements and personal information on LinkedIn. What’s more, it is not uncommon for passwords take the form of the name of a sports team, a pet or other personal details. But even if the target has been careful to use a more complex password, his or her organisation’s most sensitive data might still be at risk. For example, details of business trip dates combined with personal details such as a recent illness or family names can be all an OCG needs to socially engineer a ‘Friday Afternoon’ attack.
Typically, this would take the form of an email, phone call or possibly a combination of the two in order to convince someone at the company that an important executive is making an urgent request. Sometimes, this is a straightforward scam where the end goal is a money transfer to a third party account.
But a quick financial hit is by no means the worst occurrence. Sometimes, the request may not be for cash but for passwords or access to sensitive data. This data may then be ransomed back to the company for a huge non-negotiable fee, sold to competitors or simply put up for sale on the Dark Web. In this scenario, the company may remain blissfully unaware it has been hacked for months or even years.
So far, in the UK this combination of psychological and technological techniques to access personal information is mainly being used to target law firms. The reason is thought to be that many law firms are hierarchical and if a senior partner emails the finance department to ask for a money transfer it generally has to be done swiftly and without question.
But this does not mean that organisations working in sectors other than law or healthcare have any room for complacency. OCGs have a tendency to target what they see as “low-hanging fruit” first, before adapting their new offensive strategies to those organisations which have sensitive data and security systems that can be breached fairly easily. There is, therefore, little doubt that companies working in other sectors are probably already being targeted by OCGs.
As with the ‘Friday Afternoon’ attacks taking place on banks and legal firms, social engineering will play a crucial part in future cyber attacks on a wide spectrum of industries and businesses. What it comes down to, is that the only real safeguard is to educate all staff that all social networks are potential minefields and that, under no circumstances, should they discuss confidential company information or reveal personal details that could be used by an OCG to socially engineer a cyber attack. 
Stuart Poole-Robb, Chief Executive of Business Intelligence and Cyber Security Adviser, KCS Group

ShareTweet
Previous Post

Over 6,000 Redis Database Servers Ready for the Taking

Next Post

Cyber-risk among the greatest dangers for the financial services industry

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol