Social Engineering: When Humans Become the Target
When we think about cybersecurity, we usually think about malware, vulnerabilities, and technical attacks.
But sometimes, attackers don't need to hack the system directly.
They target the person who already has access.
Social Engineering is the use of psychological manipulation to trick people into revealing information or performing actions that could compromise security.
Common Techniques:
Phishing: Fake messages or websites designed to steal information.
Impersonation: Pretending to be a trusted employee or organization.
Urgency: Creating pressure so the victim acts without thinking.
Baiting: Using an attractive offer or file to lure the victim.
How Can You Stay Safe?
Before clicking a link or sharing information, ask:
Was I expecting this message?
Who sent it?
Can I verify the request through another trusted channel?
Remember:
Sometimes, attackers don't need to hack the system. They just need to convince someone who already has access.
KhlyBalak Security — Security starts with awareness.
الهندسة الاجتماعية: عندما يكون الإنسان هو الهدف
عندما نتحدث عن الأمن السيبراني، غالبًا ما نفكر في البرمجيات الخبيثة والثغرات والهجمات التقنية.
لكن في كثير من الأحيان، لا يحتاج المهاجم إلى اختراق النظام مباشرة… بل يحاول خداع الشخص الذي لديه صلاحية الوصول إليه.
الهندسة الاجتماعية (Social Engineering) هي أسلوب يعتمد على التلاعب النفسي لإقناع الضحية بتنفيذ إجراء قد يعرّض بياناتها أو أنظمتها للخطر.
أشهر الأساليب:
Phishing: رسائل أو مواقع مزيفة لسرقة البيانات.
Impersonation: انتحال شخصية موظف أو مسؤول موثوق. Urgency: استغلال الاستعجال والخوف لدفع الضحية للتصرف بسرعة.
Baiting: استخدام عرض أو ملف جذاب لإغراء الضحية.
كيف تحمي نفسك؟
قبل الضغط على أي رابط أو مشاركة أي معلومات، اسأل نفسك:
هل كنت أتوقع هذه الرسالة؟
من أرسلها؟
هل يمكنني التحقق من الطلب بطريقة أخرى؟
تذكر:
أحيانًا لا يحتاج المهاجم إلى اختراق النظام… يكفي أن يقنع شخصًا لديه صلاحية بالدخول.



