Question

Difficulty: MediumSocial Engineering Attacks and Vectors

An organization's security team detects an unauthorized login to a corporate account. Incident analysis reveals that the compromised employee received an SMS notification on their mobile device claiming to be from the IT helpdesk, warning that their account access would be revoked unless verified immediately via a provided URL. The link directed the user to a fraudulent authentication portal where their credentials were captured. Which social engineering attack vector initiated this security incident?

  1. SmishingAnswer
  2. B
    Vishing
  3. C
    Spear phishing
  4. D
    Pharming

Answer

Smishing is the social engineering attack vector delivered through SMS text messaging.
Smishing (SMS phishing) specifically leverages Short Message Service (SMS) text messages as the vector to deliver deceptive lures and malicious links to mobile devices. In this scenario, the attack was initiated through an urgent SMS notification containing a link to a credential harvesting site.

Step-by-Step Solution

1
Identify the communication channel used in the attack vector.
The attack initiated with an SMS text message delivered to a mobile device.
Social engineering attack classification relies on the transport medium utilized to contact the target.
2
Map the identified SMS channel to the correct Security+ attack taxonomy term.
Phishing conducted specifically over SMS text messages is defined as smishing.
Differentiation between phishing variants depends on the transport protocol (SMS = smishing, voice call = vishing, targeted email = spear phishing).

Key Concept

Social Engineering Attack Vectors and Transport Media
Estimated Time:1m 0s
Rate this question