Even the best passwords are no match for this simple hack

It turns out that just asking is often the easiest way in.
 By 
Jack Morse
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Why go to all the trouble of breaking into an online account when you can just ask for the keys?

While security experts released new password recommendations this summer, legions of hackers long ago realized that getting into a victim's email or iCloud doesn't require keyloggers, zero days, or USBs pre-loaded with malware. Nope, it's much easier than that.

All it takes is a little charm.

Welcome to the world of social engineering, where those looking gain access to protected places (be they physical or digital) talk, bluff, confuse, or trick their way past the gatekeepers. Social-Engineer, Inc., a security company that specializes in helping corporations prepare for this sort of attack, defines the technique as "any act that influences a person to take an action that may or may not be in their best interest."

Say, just for example, a stranger calls up your cell provider — pretending to be you — and convinces the call center worker to reset your SIM card. That's not in the employee's interest, nor yours. And, as Black Lives Matter activist DeRay Mckesson found out in 2016, the consequences can be rough.

This wasn't the first time someone talked their way past a public figure's digital security. In 2012, a hacker tricked Apple into giving up access to tech reporter Mat Honan's iCloud account. Through that, the attacker was able to get into both Honan's Gmail and Twitter accounts — remotely wiping his iPhone, iPad, and MacBook Air for good measure.

"I know how it was done now," Honan explained on his blog at the time. "Confirmed with both the hacker and Apple. It wasn't password related. They got in via Apple tech support and some clever social engineering that let them bypass security questions."

Basically, all the maliciously inclined need to socially engineer their way in is the right talking points and a little luck. AND for those in need of some help, there are even web forums dedicated to sharing tricks of the trade.

It's almost too easy, and no five-word passphrase can do anything to prevent it.

That being the case, shouldn't the companies that protect our data be on the lookout for this sort of thing? Thankfully, many now are. However, they are essentially forever fighting a losing battle. Social engineering relies on exploiting human nature, and last time we checked human nature is something that doesn't change all that easily.

So what can you do? Well, besides making sure you don't give out any information that could later be used to impersonate you, a simple bit of protection is to enable two-factor authentication on everything and use authenticator apps wherever possible. Also, definitely go ahead and get a PIN/customer care password for your cellphone account.

Oh, and be paranoid. Very, very paranoid.

Topics Cybersecurity

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You
Match Group responding to alleged hack of user data
Tinder and Match Group logo displayed on a phone screen

How to use Spotify's Page Match feature while reading
Mock-ups of Spotify's Page Match feature on smartphones on a colourful background.

Match vs. eharmony: Which dating app is worth your money?
Hands Holding Smartphone with Social Media Love Icons on Vibrant Red Background

Here's a simple trick for getting over someone
forlorn woman sitting on sofa looking out the window

Honda's solar-powered trailer is a perfect match for EV owners who love camping
Honda Base Station Prototype

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

NYT Connections hints today: Clues, answers for April 2, 2026
Connections game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!