BusinessPostCorner.com
No Result
View All Result
Monday, June 29, 2026
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources
BusinessPostCorner.com
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources
No Result
View All Result
BusinessPostCorner.com
No Result
View All Result

Accounting firms and growing threat of social engineering

July 22, 2024
in Accounting
Reading Time: 4 mins read
A A
0
Accounting firms and growing threat of social engineering
ShareShareShareShareShare

Social engineering raises some serious questions about data protection and compliance of accounting firms. Therefore, accounting firms should have measures to protect their IT assets against this newly emerging threat.

There are several key reasons why firms are at risk for social engineering, not the least of which is their access to huge amounts of confidential data. Many also act on behalf of clients for managing financial transactions. But in order to truly understand this threat, we must first understand exactly what is involved. 

What is Social Engineering? 

Traditionally, cybercriminals looked for weak surface areas or system vulnerabilities to breach and infiltrate the digital landscape of an organization and conduct malicious activities. However, social engineering focuses on manipulating internet users to divulge confidential information. In this attack, the user is tricked into taking action to click malware or spyware that breaches information systems once it gains access. 

Let us illustrate this with an example. Generally, hackers send an intriguing pop-up or email saying that the user has won a prize or gift. The proposed offer is generally too good to be true but the gains lead the user to take action.

In the second stage, the user is manipulated to make security mistakes (click link, fill out a form, etc.) and provoked to give away confidential information. This series of fake manipulations takes control of the victim psychologically and extracts information.

In the third stage, cybercriminals infiltrate the user’s system and also remove traces of intrusion.

Social Engineering Attack Forms

Phishing: This is the most common and prominent social engineering technique used to acquire information. Cybercriminals often disguised as legitimate business owners trick users with a fake solicitation email to provide confidential or sensitive information. 

In many phishing cases, cybercriminals claim themselves as official bank employees and ask for online banking passwords. In other cases, they take users to a fake website. Whenever a user enters the login credentials, the cybercriminals capture and change them and can exploit the gathered information and access at will. 

Spear Phishing: A more personalized version of phishing that can often appear in the form of an online ad for free software. When a user clicks it, malware is downloaded into the system. In other cases, an attacker can appear as a CEO of a company asking for specific information via a link that may seem legitimate, but is only designed to gather computer access and install malware or ransomware.

Spear Phishing shares a resemblance with another social engineering attack form called Business Email Compromise (BEC). In this form of attack, the attacker closely studies the mailing pattern of an executive and requests subordinates to send mail transfers or execute financial transactions.

Scareware: Scareware is a malicious program that is designed to create a state of panic to elicit the download of malicious software or to visit a spoofed website. This form of social engineering attack is typically launched through pop-up ads which flash a warning that a user’s system is infected and promises a fake solution. Once the ad is clicked, the phony solution enters the system and steals personal data. In many cases, Scareware is also distributed through fake emails.

Quid Pro Quo: The attacker requests information in exchange for a desirable service. For example, the attacker may pretend to be a support engineer and call an employee to address an IT issue. This information is then used to access information systems and organizational data.

Counteracting Social Engineering

As the primary touch point in social engineering resides not in information systems, but in people, its prevention requires a different approach than simply having the latest malware detection or firewalls installed. 

Because social engineering relies heavily on human action, here are some steps you can take, and teach in your firm, in order to protect it from social engineering threats:

Regular Training

First and foremost, you can help counter social engineering threats in your firm simply by training employees to identify these elements in mail or other forms of solicitation. Know that all social engineering threats are composed of 1 or more of these 4 elements: 

  1. An emotional plea or luring promise
  2. It creates a state of fear, curiosity, excitement, anger, or guilt
  3. It stirs a feeling of urgency around a request
  4. It attempts to establish trust with the user

Nurturing Safe Communication Habits 

The employees must also be trained to be vigilant and not immediately trust unknown or uncommon messages they receive, or click on any ads online. Anything remotely suspicious can be from dubious sources and divulge information without checking its legitimacy. 

Use Comprehensive Data Security Software

Accounting firms should use comprehensive data security systems and access management solutions to protect against attacks. More importantly, the systems should be updated regularly to address vulnerabilities. 

If an intruder breaches through the system and captures login credentials multi-factor authentication can prevent further login attempts. The anti-malware system should be deployed and updated regularly as per the latest threat definitions. 

Ultimately, in order to prevent such attacks, accounting firms should create awareness by coordinating learning and development sessions. The employees should be acquainted with all forms of social engineering threats so that they can clearly identify threats and secure organizational information. 

Credit: Source link

ShareTweetSendPinShare
Previous Post

Kamala Harris, once Joe Biden’s voice on abortion, would take an outspoken approach to health

Next Post

Former chancellor Nadim Zahawi mulling bid for the Telegraph

Next Post
Former chancellor Nadim Zahawi mulling bid for the Telegraph

Former chancellor Nadim Zahawi mulling bid for the Telegraph

Singapore grads battle low-paid trainee stigma to get hired

Singapore grads battle low-paid trainee stigma to get hired

June 26, 2026
Ripple MiCA Approval: What It Means for XRP Price

Ripple MiCA Approval: What It Means for XRP Price

June 23, 2026
Kleros Founder’s ETH Tax Proposal Puts Bitmine’s 8M Revenue at Risk

Kleros Founder’s ETH Tax Proposal Puts Bitmine’s $258M Revenue at Risk

June 22, 2026
Labour MPs consider backing challenger to Andy Burnham

Labour MPs consider backing challenger to Andy Burnham

June 23, 2026
Citadel: the hedge fund that became an energy giant

Citadel: the hedge fund that became an energy giant

June 23, 2026
Harvard’s housing report has a message: the middle-class home was always a historical accident

Harvard’s housing report has a message: the middle-class home was always a historical accident

June 29, 2026
BusinessPostCorner.com

BusinessPostCorner.com is an online news portal that aims to share the latest news about following topics: Accounting, Tax, Business, Finance, Crypto, Management, Human resources and Marketing. Feel free to get in touch with us!

Recent News

Harvard’s housing report has a message: the middle-class home was always a historical accident

Harvard’s housing report has a message: the middle-class home was always a historical accident

June 29, 2026
South Korea unveils tn chip and AI investment plan

South Korea unveils $1tn chip and AI investment plan

June 29, 2026

Our Newsletter!

Loading
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2023 businesspostcorner.com - All Rights Reserved!

No Result
View All Result
  • Home
  • Business
  • Finance
  • Accounting
  • Tax
  • Management
  • Marketing
  • Crypto News
  • Human Resources

© 2023 businesspostcorner.com - All Rights Reserved!