Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementSecurity & Business Resilience

Can the Tsunami of Phone-Based Social Engineering be Contained?

As soft target telephone scams become more sophisticated, people are turning to protocols like biometric verification for enhanced protection. But implementation is key.

By Aman Khanna
SEC0919-Mobile-Feat-slide1_900px
March 17, 2020

In the world of cybersecurity, it’s called a window of opportunity. That’s the limited time when hackers can exploit a system weakness or design flaw to steal sensitive personal information.

But what to do when that window means a return to attacks using old school technologies and approaches that successfully exploit human nature?

As digital security through online portals continually improves and people become more wary of phishing emails, hackers have turned to old fashioned telephone calls to elicit key pieces of personal information they can use for profit. It takes little technical skill—just the ability to sound convincing to vulnerable people over the phone. These scams target both individuals and businesses and in 2018 were one of the top three types of consumer fraud identified by the Federal Trade Commission in its annual report.

Talking ‘Bout the Man-in-the-Middle

The most common form of this type of scam is a variation on the classic “man-in-the-middle” attack. In this con, the hacker places a phone call to an individual pretending to be a representative from an entity with which the individual has a preexisting relationship—say a bank or e-commerce site. The hacker then works to extract sensitive data—like a password—from the individual. With that information, plus gathering someone’s date of birth and address through platforms like Facebook, the hacker has all he needs. He can clean out bank accounts, establish false credit cards and steal the individual’s identity.

Beyond its obvious utility for the thief, who can now drain this person’s bank account, this personal information also has value on the dark web. Passwords are frequently sold to the highest bidder, whether a nefarious actor wants to take free Uber rides or your dime or take down your employer’s systems.

Another common goal is account takeover (ATO). While on the call, the hacker claims to need immediate access to the person’s computer to remove a virus or resolve another (fake) issue. If the person agrees and provides the necessary info, then the hacker immediately locks them out of their computer and takes control of all their accounts. Meanwhile, they often extort the individual for money to “fix” the problem.

Risky Business

Old school scams like these, which exploit human nature, are also used against businesses. In one scenario, helpful members of a company’s staff are conned into giving the hacker pieces of identifying information about the victim of the fraud with whom the business has a relationship. That information, in turn, is used with other readily available information on social platforms to take over an individual’s bank or other accounts and steal their identity.

Apart from being non-secure, these verification methods are expensive, kludgy and inefficient. It also takes significant time and resources to ask personal questions and go through verification with an employee over the phone.

A Possible Solution to Hacker Phone Calls

To counter this rise, some companies are migrating to biometric verification. Typically, this verification includes three-point facial recognition or fingerprints. Smartphone-based biometric sensors like TouchID and FaceID are the most universally available sensors these days, so no additional investment in hardware is needed.

Here’s an example of how it can work:

  • A customer calls in.
  • An agent clicks a button on his screen.
  • The user gets a push notification on his smartphone.
  • The user taps the notification to open the mobile app They present a fingerprint or FaceID for biometric match.
  • The user is authenticated with the agent.

This technology is a part of a seamless omnichannel authentication experience, using one device to log in to a mobile app, web portal, phone and other accounts. And instead of simply needing a few key pieces of personal information about an individual, the hacker would need that individual’s facial identification data or fingerprint. It’s nearly impossible to falsify. But, as with many technologies, the implementation must be structured carefully to avoid another level of exposure to theft and fraud.

Beware of Remote Server Storage

Biometric authentication technologies that warehouse facial identifiers or fingerprints on centralized databases must be avoided. Such implementations create hacking targets that are potential goldmines for hackers since a single successful data-breach attempt can lead to compromise of biometric information of every single user on the system. The loss of these identifiers to hackers would be a huge problem for the victim—the victim can change his passwords, but he can’t change his fingerprint.

More recent technological changes have helped to solve this dilemma by marrying biometric authentication with a means of keeping that data safe. The inclusion of biometric sensors on nearly all smartphones and many other mobile devices makes it feasible to contain these biometric authenticators on the individual’s personal device at scale, allowing individuals and businesses to use it for ongoing verification.

Technologies that allow decentralized biometric authentication only on the user’s phone or other mobile devices provide greater security without sacrificing convenience. An individual’s personal data never leaves their phone. It is never transmitted over the air and it is never stored on a remote server. A business could simply initiate a biometric verification request, send it to the individual’s phone and conduct that verification without ever possessing the individual’s data.

For a hacker to get access to this information, they would first physically need to get access to the person’s device and then go through the laborious process of cracking Apple or Google security protocols just to steal a single user's credentials. This task is so difficult that it's not worth a hacker’s time.

It’s certain that hacking, whether through a phone call or with the most advanced technology, will never be eliminated. Biometric authentication – done right – could be the tool we need to close the current window of opportunity for hackers to exploit our weaknesses. But, nothing is a replacement for good judgment. If a phone call sounds phishy, hang up.

KEYWORDS: cyber security cybersecurity digital security scams social engineering

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Amankhanna

Aman Khanna is Vice President for Product Growth at Oloid.

 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • threat

    How security teams can combat social engineering and insider threats

    See More
  • blurry multicolored text on black screen

    Report reveals new browser-based social engineering trends

    See More
  • hacker

    How can companies keep up with social engineering attacks?

    See More

Related Products

See More Products
  • 9781138378339.jpg

    Surveillance, Crime and Social Control

  • Optimizing Social Media from a B2B Perspective

  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing