Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity News

Where Cyber Meets Skinware: An Enterprise Security Problem

By Mark McCourt
October 1, 2014

As your enterprise virtualizes and leverages cyber technology to speed productivity, the incidence of cybercrime will, of course, increase. Similarly, as your employees’ behavior, as consumers, drives the technology they use (BYOD), the cybercrime cat will continue to be let out of the bag. What can any enterprise, security leader or technology truly do to eliminate or prevent cyber terror, espionage, theft, network intrusions and major fraud when the humans involved are making it so easy?

In the connected world, there are only three components that can cause failure: hardware, software, and skinware. For example, with hardware, your hard drive can crash. Or with software, an operating system may have a continuous loop in which you start your computer and an error message indicates it has encountered a problem and has to restart and that repeats until you cry. Or a skinware issue, which is, well.... you. You don’t know what you are doing, and you are the problem.

While the Home Depot, Target and (oh, just fill in your favorite retailer here) hacks are real network breached cybercrimes, there are too many schemes – scams and human error – due to poor or no training that are leading to real crimes. That’s right – skinware!

A perfect example is the African Cyber Crime School Impersonation Scheme. No, really. I didn’t make this up. It’s on the FBI’s cybercrime alert site if you want to check it out. So how do you successfully impersonate an entire school? I couldn’t even get away with forging a lousy hall pass!

If you have not read about the African School Impersonation Scheme or are not familiar with the FBI’s Internet Cyber Crime Complaint Center (IC3), it all sounds so technical and scary. Somehow, it would appear, Africans will steal our schools blind through the Internet while we sit in the cafeteria, helplessly trying to guess what we are eating.

But that is not it at all. Whether or not Cyber is in your job description, I assure you that stopping this scheme is right in every security leader’s sweet spot.

First, no encrypted passwords are broken or firewalls hacked. Your CIO, CISO or network security administrators have nothing to breach, protect or stop in this matter. No computer needs to be turned on or connected to the Internet. So, it is not about the Internet or cyber. The only technology the criminals use is the “good ole telephone.” Imagine that.

Second, it is not about schools, although they were initially used as the golden ticket to steal millions in products. This scheme is very successful and, as a result, it has quickly spread to businesses and other institutions. The FBI shares that the scheme is resulting in $200,000 per incident thefts. (Laptops, medical supplies, industrial equipment, etc., are all at play).

This scheme is all about you and physical security insider threats. But no, that nice customer service representative is not a nefarious criminal mind; just a poorly trained employee without policies in place to prevent them from being human engineered. Indeed, they are so helpful that they are helping a criminal perpetrate a crime.

 Here are the 1-2-3’s of the School Impersonation Scheme. The criminal contacts a business’s customer service center, poses as a school official and, using human engineering techniques, gathers additional information about the purchasing account. Most customer service training ends the call by asking, “I have answered all your questions and is there anything else I can help you with today?” And in this case the agent most certainly has.

Next, the criminal calls the targeted vendor again with account information in hand and places an order billing to the school’s line of credit. This is bold; they give the actual school address for the shipment and then call the school pretending to be the business they just ripped off. Stating they shipped an order in error, they ask them to return it. They then ship labels to the school, and the school unwittingly forwards the shipment to the criminal’s address.

As noted, it started with schools, but has spread quickly to other sectors. And why not? Without policies, training and a way for employees to “see something, say something,” your company doesn’t stand a chance. And having a CIO buy more hardware and software with more passwords is not the answer in this and in many other criminal cases.

Cyber or not, naming it is less important than stopping it. This is where physical security’s expertise, leadership and experience are perfectly suited to identify and mitigate known risks. Otherwise, your customer service representatives will not even recognize a well-crafted fake hall pass.   

KEYWORDS: cyber espionage cyber security data breach insider threats skinware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Mark McCourt was once the publisher of Security magazine.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Trophy and soccer ball

Security Experts Discuss Threats to FIFA World Cup 2026

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Neighborhood

Residential AI Data Centers: Security, Privacy, and Governance Concerns

Colorful laptop

Organizations Think They Know Who’s Visiting Their Sites. They Don’t.

Construction

Texas Tech University Constructing Critical Infrastructure Security Site

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • face-recognition-freepik1170.jpg

    Facial recognition technology’s serious security problem

    See More
  • social-snaptrends

    The Social Media Security Problem for Corporations around the World

    See More
  • Does Pre-Employment Vetting Bring an Enterprise More Value or Liability?

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • 9780367339456.jpg.jpg.jpg

    Cyber Strategy: Risk-Driven Security and Resiliency

  • 150952519X.jpg

    Intelligence in An Insecure World, 3rd Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing