Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity News

Remote workers more at risk for social engineered deception and cyberattack

By Perry Carpenter
remote work
November 16, 2020

Social engineering is a term that refers to efforts by hackers and cybercriminals to use people — rather than technology — to gain access to sensitive systems and information. It’s a problem that information security experts have been wrestling with for years and one that, in the midst of COVID-19, has become both more prevalent and more challenging.

Lonely workers more likely to click

According to Stanford economist Nicholas Bloom, “42 percent of the U.S. labor force [is] now working from home full-time.” In fact, he says: “Almost twice as many employees are working from home as at work.”

They’re isolated. They’re anxious. They’re restless.

According to an article in Harvard Business Review: “Since the outbreak of the pandemic, 75% of people say they feel more socially isolated, 67% of people report higher stress, 57% are feeling greater anxiety, and 53% say they feel more emotionally exhausted.” The data is based on a global study of more than 3700 employees in 10 industries conducted in March and April 2020. It’s important to note that it is now over seven months since these findings were published. Imagine how this same isolation, anxiety, and emotional exhaustion has been compounded by each passing week.

While working at home, employees are even more likely than when in the workplace to spend time during the day focused on non-work activities, like surfing the web or surfing social media channels.

Enter the social engineers

Social engineering has been defined in TechRepublic, as: “Any act that influences a person to take an action that may or may not be in their best interest.” Here are a few common examples:

  • Phishing—attempts to get people to “click on a link, download a file, or respond with personal details.”
  • Vishing, or phone spoofing—calls made to people designed to get them to share personal information or reset a password.
  • Baiting people to get them to take an action like plugging in a found USB stick that contains malware.
  • SMS spoofing—getting people to call a number that is designed to steal their personal data.

In the environment we’re in right now dealing with Covid, people are even more susceptible to these types of attacks and general social engineering campaigns than ever before.

What workers need to be wary of

Phishing campaigns have gone up exponentially since the beginning of the pandemic and will continue as the virus rages on. Even once the virus has subsided, phishing campaigns will not. When they’re not focused on spreading compelling, and often inaccurate information about COVID, there are plenty of other issues to exploit — social issues, economic issues, political issues, etc.

“Active measures” – a phrased derived from Russian propaganda and disinformation practices– indicates that the bad players are actively using PR tools in a distorted and fake manner – leveraging everything in order to take advantage of circumstances, bring deception, and ultimately divide people.

People are always, ultimately, behind these attacks, but not always personally spreading them. There are hundreds of thousands of fake accounts that are disseminating news and false content; social networking platforms like LinkedIn, Twitter, Facebook, Instagram, and others are riddled with them. These accounts may look real but, in fact, are completely made up. Disinformation artists and security researchers refer to these as “sockpuppet” accounts — entirely fake accounts set up under the pretext of a real person or company. And the problem gets more complex because many of these accounts are bots, allowing attacks to be launched and to propagate at the speed of code.

These days seeing is not always believing

Everything you see, you have to be skeptical of these days, it seems.

Social media platforms are widely used for the purposeful spread of false content. How do government states use social media to spread disinformation? In a variety of ways, according to The Global Disinformation Order 2019 Global Inventory of Organised Social Media Manipulation:

  • 87% of countries use human accounts
  • 80% use bot accounts
  • 75% use disinformation and media manipulation to mislead users

Suffice it to say that these are organized campaigns purposefully designed to mislead and misinform.

The dangers of data breaches

Of course, disinformation is not the only risk that employees working from offsite locations pose for organizations. They are also at heightened risk for potential data breaches that can put an organization’s information at risk. In fact, 95% of successful data breaches start with a spear phishing attack — an email or electronic scam designed to steal data or install malware on targeted computers.

The crafting behind these campaigns is designed to draw attention — and clicks (often referred to as clickbait). When people click they often introduce malware that can destroy, lock-up or steal information.

The Defense: Education

Given these enhanced risks and the tendency for offsite employees to potentially be engaging more with online information of questionable veracity, it’s important to educate and inform them regularly of the risks. It’s equally important to help employees feel empowered, capable of detecting phishing and disinformation campaigns, and able to take the necessary precautions to protect themselves and your organization from data breaches and the spread of misinformation.

Education is an extremely effective way to get people’s awareness and understanding to a level where they recognize that what they see in their inbox, or on social media, increasingly represents someone — or something — with an agenda.  

Education and preparation are the only defense.

KEYWORDS: cyber security information security social engineering

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Perry carpenter

Perry Carpenter is author of Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors (Wiley, 2019). Working with noted hacker Kevin Mitnick, he is Chief Evangelist/ Strategy Officer for KnowBe4, developer of security awareness training and simulated phishing platforms with over 30,000 customers and 2 million users. He holds a MS in Information Assurance (MSIA) from Norwich University and is a Certified Chief Information Security Officer (C|CISO).

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • cybersecurity

    COVID-19 has enlarged the digital footprint for American businesses: We’ve never been more at risk for cybercrime

    See More
  • password1-900px.jpg

    New Dashlane Survey: Majority of Americans Feel More at Risk Online Due to COVID-19

    See More
  • Many Social Networking Users are at Risk for Identity Theft

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

  • 9781138378339.jpg

    Surveillance, Crime and Social Control

See More Products

Events

View AllSubmit An Event
  • June 24, 2025

    Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

    ON DEMAND: For today's security teams, making informed decisions in the first moments of a crisis is critical. Explore how real-time risk detection and situational awareness platforms empower teams to act quickly and confidently, before a crisis begins or escalates.
  • June 6, 2012

    Basic Remote Connection for AXIS Camera Companion

    In this webinar, you will learn how to setup basic forwarding rules and Network address translation (NAT) in a router. We will also show you how to setup remote connection using AXIS Camera Companion.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing