Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Attack #1: Phishing & Social Engineering

DIAMATIX_Post_14.01.2026 - Copy

Attack #1: Phishing & Social Engineering

Threat snapshot – Phishing & Social Engineering

CategorySummary
What it isAttacks that manipulate people into taking actions – opening files, entering credentials, approving payments, or granting access.
Most common targetsEmployees, finance teams, leadership, IT staff, fast-growing organizations.
What it relies onHuman factors combined with lack of MFA and weak verification processes.
How it’s detectedSuspicious emails, abnormal logins, behavioral anomalies, early SOC indicators.
Primary impactAccount compromise, financial fraud, and initial access for deeper attacks.
What realistically helpsTraining + clear processes + MFA everywhere + behavior-based detection.

How the attack works

Most cyber incidents do not begin with a system failure. They begin with a breakdown of trust.
Phishing and social engineering attacks do not rely on technical exploitation. They rely on people.

The attacker impersonates a legitimate entity. A colleague, a partner, a vendor, a platform, or an institution. The objective is not to send a message, but to trigger an action. Opening a file. Entering credentials. Approving a payment. Granting access.

These attacks are built on context, pressure, and psychological response. That is why they remain the most effective and consistent entry point.

Real-World Cases

The following incidents demonstrate that phishing and social engineering remain among the fastest ways to gain initial access to corporate environments. Rather than attacking technology directly, attackers manipulate people into revealing information, approving access, or performing actions on their behalf.

MGM Resorts (United States, 2023)

Sector: Hospitality and Entertainment

How did the incident begin?
The attackers gathered publicly available information about an employee and contacted the internal IT Help Desk while impersonating that individual. Through voice phishing (Vishing), they convinced the help desk to restore access to the employee’s account.

What was compromised?

  • internal user accounts;
  • corporate information systems;
  • customer personal information, including names, addresses, phone numbers, and certain identification details.

How did the attack develop?
After gaining access, the attackers expanded their control within the corporate environment, compromised internal systems, and caused widespread operational disruption. To contain the incident, MGM temporarily shut down parts of its infrastructure.

Operational and financial impact

  • several days of disruption across hotels and casinos;
  • reservation, room key, and payment systems affected;
  • approximately US$100 million financial impact reported by the company.

What could have reduced the impact?

  • stronger verification procedures for help desk requests;
  • Multi-Factor Authentication (MFA);
  • training against voice phishing;
  • monitoring for unusual account and privilege changes.

Twilio (2022)

Sector: Cloud Communications Services

How did the incident begin?
Employees received SMS messages impersonating the company’s authentication system. The messages linked to a fake login page where some employees entered their credentials.

What was compromised?

  • employee credentials;
  • access to internal systems;
  • limited customer data associated with approximately 163 customer organizations.

How did the attack develop?
After successful authentication, the attackers accessed internal applications and customer information. One affected customer, Signal, reported attempts to register new devices for a limited number of user accounts.

Operational and financial impact

  • approximately 163 customer organizations affected;
  • customer notification and incident investigation;
  • improvements to identity protection and authentication processes.

What could have reduced the impact?

  • phishing-resistant Multi-Factor Authentication (MFA);
  • employee awareness training for SMS phishing (Smishing);
  • restricted access to sensitive internal systems;
  • monitoring for unusual logins and device enrollment activity.

What do these incidents show?

In MGM Resorts, a single phone call to the IT Help Desk provided the initial access that ultimately led to several days of operational disruption and an estimated US$100 million financial impact. In Twilio, a coordinated SMS phishing campaign compromised employee credentials and affected approximately 163 customer organizations.

Both incidents demonstrate that social engineering relies on trust and human error rather than technical vulnerabilities. Strong identity verification procedures, phishing-resistant Multi-Factor Authentication (MFA), and continuous security awareness training significantly reduce the likelihood of these attacks succeeding.

Who they most often target

Phishing does not choose victims. It chooses access and influence.
The closer someone is to systems, money, or decision-making, the more attractive they become.

Roles
  • employees with email and internal system access

  • finance and operations teams

  • leadership and key decision makers

  • IT and support staff

Sectors
  • small and mid-sized businesses

  • professional services

  • manufacturing and logistics

  • public sector

  • healthcare and education

Organization types
  • with unclear or immature security processes

  • operating hybrid and cloud environments

  • undergoing growth and organizational change

The more dynamic the environment, the easier it is for phishing to blend into daily operations.

What the attack relies on

Phishing rarely succeeds because of a single weakness.
It works when human, technical, and process layers align in the attacker’s favor.

Human factors
  • urgency and time pressure

  • cognitive overload

  • trust in authority

  • fear of mistakes

  • willingness to help

Technical gaps
  • lack of multi-factor authentication

  • weak email protection

  • compromised accounts

  • limited visibility

Process weaknesses
  • unclear approval flows

  • missing verification steps

  • insufficient training

  • no established reporting habits

Phishing succeeds when the environment enables it.

How it is detected

Phishing is rarely detected through a single signal. More often, it is recognized through patterns.
The difference between an incident and a breach is how early those signals are seen.

What users may notice
  • unusual tone or urgency

  • unexpected financial changes

  • suspicious links or attachments

  • subtle inconsistencies

What IT teams observe
  • abnormal logins

  • new or unknown devices

  • irregular access patterns

  • anomalous email activity

What SOC teams detect
  • behavioral anomalies

  • indicators of active campaigns

  • credential misuse

  • post-email lateral movement

Phishing rarely remains isolated. When unnoticed, it almost always becomes the first step of a larger incident.

How impact is contained

In phishing incidents, speed matters more than perfect certainty.
The first priority is not full investigation, but breaking the attack chain.

  • immediately isolating affected accounts

  • resetting credentials and revoking active sessions

  • removing malicious inbox rules and forwards

  • investigating follow-on activity

  • notifying internal teams

What does not help:
  • deleting the email without analysis

  • assigning blame

  • delaying response

Phishing does not wait. Containment should not either.

What realistically helps

Phishing is not eliminated. It is managed as an ongoing risk.
And it requires coordination across people, processes, and technology.

People
  • regular, realistic training

  • non-punitive reporting culture

  • simple escalation paths

Processes
  • clearly defined financial and access workflows

  • dual-approval principles

  • response playbooks

  • attack simulations

Technology
  • advanced email and domain protection

  • multi-factor authentication

  • behavior-based monitoring

  • XDR and SOC visibility

The better these layers work together, the harder it becomes for phishing to escalate into an incident.

Common myths

Myths around phishing often create false confidence.

  • “Training alone will solve it”

  • “We have email security, so we’re covered”

  • “We would notice if it happened”

  • “Only small organizations get phished”

In reality, phishing remains the most common entry point even in mature security environments.


Next: Attack #2 – Credential Abuse & Account Takeover

Could your email already be exposed? Use the DIAMATIX email exposure check to review whether your address appears in known breaches and understand what action may be needed. 

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.