Skip to content
HALOCK Logo

Reasonable Security847-221-0200

Incident Response Hotline: 800-925-0559

  • Services
    • Artificial Intelligence (AI) Security
      • AI Risk Assessment
      • CCPA Privacy Risk Assessment
      • Microsoft Copilot Security
    • Offensive Security (Pen Testing, Adversarial Test, Application Test)
      • Application Testing
      • Adversarial Testing
      • Penetration Testing
    • Governance and Risk Management
      • Risk Assessments
      • Governance and Risk Solutions
      • CISO & vCISO Advisory
      • CIS RAM Consulting
      • DoCRA Services
    • Security Management
      • Policy Library & Development
      • Security Awareness Training
      • Incident Response Plan Development
    • Compliance
      • PCI DSS Compliance
    • Security Engineering
      • Microsoft Copilot Security Services
      • External Attack Surface Management (EASM)
      • CIS Based Security Assessment
      • Risk Based Threat Assessment
      • Cloud Assessment Services
      • HALOCK Industry Threat HIT Index
      • Sensitive Data Scanning
      • Compromise Assessment
    • Incident Response and Forensic Services
      • Live Breach Response & Forensic Services
      • Incident Response Readiness as a Service (IRRaaS)
      • Compromise Assessment
  • Products
  • Industries
    • Communications
    • Cloud Based
    • Education
    • Energy Utilities
    • Financial Services
    • Gambling Businesses
    • Government
    • Healthcare
    • IT Cyber Security
    • Manufacturing
    • Media And Entertainment
    • Nonprofit
    • Payments
    • Retail
    • Startups
    • Supply Chain
    • Transportation
  • Resources
    • Blog – Cyber Security Articles
    • Reference Materials
    • InfoSec Tip Posters
    • Client Security Briefing
    • On-Demand Webinars
    • eNewsletters
    • HALOCK Media Room
  • About Us
    • Why HALOCK?
    • Our Team
    • Careers
    • HALOCK News
    • Events
    • HALOCK in the Press
    • Blog
  • Contact Us

emergency phone
  • Services
    • Artificial Intelligence (AI) Security
      • AI Risk Assessment
      • CCPA Privacy Risk Assessment
      • Microsoft Copilot Security
    • Offensive Security (Pen Testing, Adversarial Test, Application Test)
      • Application Testing
      • Adversarial Testing
      • Penetration Testing
    • Governance and Risk Management
      • Risk Assessments
      • Governance and Risk Solutions
      • CISO & vCISO Advisory
      • CIS RAM Consulting
      • DoCRA Services
    • Security Management
      • Policy Library & Development
      • Security Awareness Training
      • Incident Response Plan Development
    • Compliance
      • PCI DSS Compliance
    • Security Engineering
      • Microsoft Copilot Security Services
      • External Attack Surface Management (EASM)
      • CIS Based Security Assessment
      • Risk Based Threat Assessment
      • Cloud Assessment Services
      • HALOCK Industry Threat HIT Index
      • Sensitive Data Scanning
      • Compromise Assessment
    • Incident Response and Forensic Services
      • Live Breach Response & Forensic Services
      • Incident Response Readiness as a Service (IRRaaS)
      • Compromise Assessment
  • Products
  • Industries
    • Communications
    • Cloud Based
    • Education
    • Energy Utilities
    • Financial Services
    • Gambling Businesses
    • Government
    • Healthcare
    • IT Cyber Security
    • Manufacturing
    • Media And Entertainment
    • Nonprofit
    • Payments
    • Retail
    • Startups
    • Supply Chain
    • Transportation
  • Resources
    • Blog – Cyber Security Articles
    • Reference Materials
    • InfoSec Tip Posters
    • Client Security Briefing
    • On-Demand Webinars
    • eNewsletters
    • HALOCK Media Room
  • About Us
    • Why HALOCK?
    • Our Team
    • Careers
    • HALOCK News
    • Events
    • HALOCK in the Press
    • Blog
  • Contact Us

How to Protect Yourself from Social Engineers in Social Media

Social Engineering Reasonable Security Risk

 

The use of social media like Twitter, Facebook, Instagram, Tumblr, Google Plus, LinkedIn and others have been steadily growing. It is used not only between individuals connecting with their “tweeps,” but also for businesses connecting with their customers, and even politicians with their constituents. Social media platforms have become a forum for sharing all manner of expression on all subjects.

Businesses need to take special care in their security training regarding all social media, however Twitter and LinkedIn are particularly fertile sources of information for hackers preparing for a social engineering attack. Both of these social media platforms have high adoption rates in a business setting.

By gathering benign information about a company and “name dropping” in a DM (direct message) conversation, attackers may build a level of trust with insiders and thereby gain secrets. Employees post seemingly innocuous information on Twitter that may be readily and easily gathered and assembled by an adversary. For example, photos of office space and co-workers, descriptions of work (My jerk of a boss makes me fill in his TPS report every Friday #ihateexcel), and names of customers or clients, all reveal enough information for an attack or to recruit unwitting accomplices.

This technique is often used in operational penetration testing. It goes something like this:

An employee receives a call from a person claiming to be a new guy from a different office, and then claims that their boss is yelling at him to give them a weekly TPS report. The person claims that they are having trouble with the macros. Finally, the person asks if the employee could please forward a copy so they could copy the formulas… The employee, feeling sorry for the person on the other end of the phone, sends the file and the mission has been successful.

Businesses should implement policies that are well-“socialized” around the office with the following components:

  • Never use your work email address as your account ID for social networking services.
  • Never use the same account name and password combination for multiple services.
  • Websites often ask users the answers to “secret questions” like the high school you attended, or the street you grew up on. Don’t post these “answers” inadvertently on social media.
  • Encourage employees to limit social media posts to personal interests, and not related to their work, office, or co-workers unless they have a legitimate business purpose for posting (corporate communications, marketing, etc).
  • Never share company information with strangers, even long-time “connections” on LinkedIn or long-time connections that were made over social media. Many of which the person has never met face-to-face. Instead refer them to your corporate webpage, or say you will have someone get back to them.
  • Always ask for a callback number or email address from anyone requesting information by phone, LinkedIn or Twitter, and forward the request to security or to marketing/PR.
  • Remove references to places of employment from all Twitter profiles.
  • LinkedIn profiles can be more complete, but only connect with people you actually know or who are personally introduced to you. Social Engineers create fake, legitimate-sounding profiles on LinkedIn and connect to hundreds of people in a particular industry to appear legitimate. Just because a person is connected to (or follows) many of the same people as you, does not mean that they are legit.

Twitter and LinkedIn are great tools for business, which, if used properly by well-informed employees, won’t be a gateway for hackers. Don’t let hackers exploit you via social media. Download the “Keep Them Puzzled” poster now.

Download Cybersecurity Awareness Posters.

Cindy Kaplan2025-06-17T22:03:42+00:00Tags: security awareness, social engineers, Social Media|

BLOG CATEGORIES

  • Artificial Intelligence (AI)
  • Bug Reports
  • Case Study
  • Checklists
  • Cloud Security Insights
  • Compromise Assessments
  • Cyber Insurance
  • Duty of Care Risk Assessment (DoCRA)
  • Education
  • Emerging Solutions & Trends
  • Enewsletters
  • Events
  • Exploit Insider
  • Financial
  • Gambling
  • Governance & Risk Management
  • HALOCK
  • HALOCK Breach Bulletin
  • HALOCK Helps
  • HALOCK Investigates
  • HALOCK Pandemic Breach Bulletin
  • HALOCK Radio
  • Healthcare
  • HIPAA Compliance
  • Incident Response
  • Industry Verticals
  • Infosec Industry Reports
  • ISO 27001
  • Modern Malware
  • Past Events
  • PCI Compliance
  • Penetration Testing
  • Posters
  • Primers
  • Privacy
  • Reasonable Security | Reasonable Risk
  • Regulation & Litigation
  • Retail
  • Risk Assessments
  • Securities and Exchange Commission (SEC)
  • Security Approaches & Methods
  • Security Awareness
  • Security Breach
  • Security Briefing
  • Security Briefing Solutions
  • Security Incidents
  • Security Incidents
  • Security Industry Reports
  • Security Privacy Risk
  • Security Ransomware
  • Sensitive Data
  • Standards & Frameworks
  • Templates & Tools
  • Third-Party Risk & Vendor Risk Management
  • Transportation
  • Uncategorized
  • Vulnerability Management
  • What's New & Tech
  • WorkForce

Incident Response Hotline: 800-925-0559

cybersecurity managementSubscribe to Our Newsletter

© 2025 HALOCK. All rights reserved.
Privacy Policy      Terms of Use     Site Map

blue Halock logo
1834 Walden Office Square, Suite 200
Schaumburg, IL 60173
847-221-0200
Page load link
Go to Top