Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity News

Remote workers more at risk for social engineered deception and cyberattack

By Perry Carpenter
remote work
November 16, 2020

Social engineering is a term that refers to efforts by hackers and cybercriminals to use people — rather than technology — to gain access to sensitive systems and information. It’s a problem that information security experts have been wrestling with for years and one that, in the midst of COVID-19, has become both more prevalent and more challenging.

Lonely workers more likely to click

According to Stanford economist Nicholas Bloom, “42 percent of the U.S. labor force [is] now working from home full-time.” In fact, he says: “Almost twice as many employees are working from home as at work.”

They’re isolated. They’re anxious. They’re restless.

According to an article in Harvard Business Review: “Since the outbreak of the pandemic, 75% of people say they feel more socially isolated, 67% of people report higher stress, 57% are feeling greater anxiety, and 53% say they feel more emotionally exhausted.” The data is based on a global study of more than 3700 employees in 10 industries conducted in March and April 2020. It’s important to note that it is now over seven months since these findings were published. Imagine how this same isolation, anxiety, and emotional exhaustion has been compounded by each passing week.

While working at home, employees are even more likely than when in the workplace to spend time during the day focused on non-work activities, like surfing the web or surfing social media channels.

Enter the social engineers

Social engineering has been defined in TechRepublic, as: “Any act that influences a person to take an action that may or may not be in their best interest.” Here are a few common examples:

  • Phishing—attempts to get people to “click on a link, download a file, or respond with personal details.”
  • Vishing, or phone spoofing—calls made to people designed to get them to share personal information or reset a password.
  • Baiting people to get them to take an action like plugging in a found USB stick that contains malware.
  • SMS spoofing—getting people to call a number that is designed to steal their personal data.

In the environment we’re in right now dealing with Covid, people are even more susceptible to these types of attacks and general social engineering campaigns than ever before.

What workers need to be wary of

Phishing campaigns have gone up exponentially since the beginning of the pandemic and will continue as the virus rages on. Even once the virus has subsided, phishing campaigns will not. When they’re not focused on spreading compelling, and often inaccurate information about COVID, there are plenty of other issues to exploit — social issues, economic issues, political issues, etc.

“Active measures” – a phrased derived from Russian propaganda and disinformation practices– indicates that the bad players are actively using PR tools in a distorted and fake manner – leveraging everything in order to take advantage of circumstances, bring deception, and ultimately divide people.

People are always, ultimately, behind these attacks, but not always personally spreading them. There are hundreds of thousands of fake accounts that are disseminating news and false content; social networking platforms like LinkedIn, Twitter, Facebook, Instagram, and others are riddled with them. These accounts may look real but, in fact, are completely made up. Disinformation artists and security researchers refer to these as “sockpuppet” accounts — entirely fake accounts set up under the pretext of a real person or company. And the problem gets more complex because many of these accounts are bots, allowing attacks to be launched and to propagate at the speed of code.

These days seeing is not always believing

Everything you see, you have to be skeptical of these days, it seems.

Social media platforms are widely used for the purposeful spread of false content. How do government states use social media to spread disinformation? In a variety of ways, according to The Global Disinformation Order 2019 Global Inventory of Organised Social Media Manipulation:

  • 87% of countries use human accounts
  • 80% use bot accounts
  • 75% use disinformation and media manipulation to mislead users

Suffice it to say that these are organized campaigns purposefully designed to mislead and misinform.

The dangers of data breaches

Of course, disinformation is not the only risk that employees working from offsite locations pose for organizations. They are also at heightened risk for potential data breaches that can put an organization’s information at risk. In fact, 95% of successful data breaches start with a spear phishing attack — an email or electronic scam designed to steal data or install malware on targeted computers.

The crafting behind these campaigns is designed to draw attention — and clicks (often referred to as clickbait). When people click they often introduce malware that can destroy, lock-up or steal information.

The Defense: Education

Given these enhanced risks and the tendency for offsite employees to potentially be engaging more with online information of questionable veracity, it’s important to educate and inform them regularly of the risks. It’s equally important to help employees feel empowered, capable of detecting phishing and disinformation campaigns, and able to take the necessary precautions to protect themselves and your organization from data breaches and the spread of misinformation.

Education is an extremely effective way to get people’s awareness and understanding to a level where they recognize that what they see in their inbox, or on social media, increasingly represents someone — or something — with an agenda.  

Education and preparation are the only defense.

KEYWORDS: cyber security information security social engineering

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Perry carpenter

Perry Carpenter is author of Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors (Wiley, 2019). Working with noted hacker Kevin Mitnick, he is Chief Evangelist/ Strategy Officer for KnowBe4, developer of security awareness training and simulated phishing platforms with over 30,000 customers and 2 million users. He holds a MS in Information Assurance (MSIA) from Norwich University and is a Certified Chief Information Security Officer (C|CISO).

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • security awareness freepik

    Building a culture of cybersecurity: 3 key takeaways from the 2021 SANS report

    See More
  • people-business-freepik170x658v4.jpg

    3 reasons why cybersecurity must be people-centric

    See More
  • risk management freepik

    3 steps to promote a human-centric security awareness culture

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

  • 9781138378339.jpg

    Surveillance, Crime and Social Control

See More Products

Events

View AllSubmit An Event
  • June 6, 2012

    Basic Remote Connection for AXIS Camera Companion

    In this webinar, you will learn how to setup basic forwarding rules and Network address translation (NAT) in a router. We will also show you how to setup remote connection using AXIS Camera Companion.
  • May 14, 2012

    Effective Risk Communication: Theory, Tools, and Practical Skills for Communicating about Risk

    Stay ahead of the curve by attending this in-depth program, featuring the latest scientific findings on risk perception, case studies from around the world, a suite of practical tools, and hands-on skill training.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing