Question

Difficulty: Very hardSocial Engineering Attacks and Vectors

An enterprise security operations center (SOC) detects an incident where remote executive assistants received customized SMS text messages appearing to originate from the corporate IT department. The messages contained links to a credential-harvesting landing page hosted on a typosquatted domain and warned that email access would be permanently suspended within two hours unless password re-verification was completed immediately. Which social engineering attack vector and primary principle of influence were executed in this scenario?

  1. Smishing leveraging the principle of urgencyAnswer
  2. B
    Vishing leveraging the principle of authority
  3. C
    Spear phishing leveraging the principle of consensus
  4. D
    Watering hole attack leveraging the principle of scarcity

Answer

The attack vector is smishing, combined with the principle of urgency.
The correct response accurately identifies smishing as the attack vector because the communication took place over SMS text messages. It also correctly pairs this vector with the principle of urgency, as the attacker attempted to force quick compliance by establishing a two-hour deadline before access suspension.

Step-by-Step Solution

1
Identify the delivery medium utilized in the attack scenario.
The message was delivered via SMS text message, which defines the vector as smishing (SMS phishing).
Phishing over cellular text messaging is categorized specifically as smishing, distinguishing it from email-based phishing or voice-based vishing.
2
Analyze the psychological trigger used to compel victim action.
The threat of account suspension within a short two-hour timeframe leverages urgency.
Social engineering attackers use strict time limits to induce panic and force targets to act before consulting technical support or verifying legitimacy.

Key Concept

Social Engineering Attacks and Vectors
Estimated Time:1m 30s
Rate this question