Attack #1: Phishing & Social Engineering
Threat snapshot – Phishing & Social Engineering
| Category | Summary |
|---|---|
| What it is | Attacks that manipulate people into taking actions – opening files, entering credentials, approving payments, or granting access. |
| Most common targets | Employees, finance teams, leadership, IT staff, fast-growing organizations. |
| What it relies on | Human factors combined with lack of MFA and weak verification processes. |
| How it’s detected | Suspicious emails, abnormal logins, behavioral anomalies, early SOC indicators. |
| Primary impact | Account compromise, financial fraud, and initial access for deeper attacks. |
| What realistically helps | Training + clear processes + MFA everywhere + behavior-based detection. |
How the attack works
Most cyber incidents do not begin with a system failure. They begin with a breakdown of trust.
Phishing and social engineering attacks do not rely on technical exploitation. They rely on people.
The attacker impersonates a legitimate entity. A colleague, a partner, a vendor, a platform, or an institution. The objective is not to send a message, but to trigger an action. Opening a file. Entering credentials. Approving a payment. Granting access.
These attacks are built on context, pressure, and psychological response. That is why they remain the most effective and consistent entry point.
Real-World Cases
The following incidents demonstrate that phishing and social engineering remain among the fastest ways to gain initial access to corporate environments. Rather than attacking technology directly, attackers manipulate people into revealing information, approving access, or performing actions on their behalf.
MGM Resorts (United States, 2023)
Sector: Hospitality and Entertainment
How did the incident begin?
The attackers gathered publicly available information about an employee and contacted the internal IT Help Desk while impersonating that individual. Through voice phishing (Vishing), they convinced the help desk to restore access to the employee’s account.
What was compromised?
- internal user accounts;
- corporate information systems;
- customer personal information, including names, addresses, phone numbers, and certain identification details.
How did the attack develop?
After gaining access, the attackers expanded their control within the corporate environment, compromised internal systems, and caused widespread operational disruption. To contain the incident, MGM temporarily shut down parts of its infrastructure.
Operational and financial impact
- several days of disruption across hotels and casinos;
- reservation, room key, and payment systems affected;
- approximately US$100 million financial impact reported by the company.
What could have reduced the impact?
- stronger verification procedures for help desk requests;
- Multi-Factor Authentication (MFA);
- training against voice phishing;
- monitoring for unusual account and privilege changes.
Twilio (2022)
Sector: Cloud Communications Services
How did the incident begin?
Employees received SMS messages impersonating the company’s authentication system. The messages linked to a fake login page where some employees entered their credentials.
What was compromised?
- employee credentials;
- access to internal systems;
- limited customer data associated with approximately 163 customer organizations.
How did the attack develop?
After successful authentication, the attackers accessed internal applications and customer information. One affected customer, Signal, reported attempts to register new devices for a limited number of user accounts.
Operational and financial impact
- approximately 163 customer organizations affected;
- customer notification and incident investigation;
- improvements to identity protection and authentication processes.
What could have reduced the impact?
- phishing-resistant Multi-Factor Authentication (MFA);
- employee awareness training for SMS phishing (Smishing);
- restricted access to sensitive internal systems;
- monitoring for unusual logins and device enrollment activity.
What do these incidents show?
In MGM Resorts, a single phone call to the IT Help Desk provided the initial access that ultimately led to several days of operational disruption and an estimated US$100 million financial impact. In Twilio, a coordinated SMS phishing campaign compromised employee credentials and affected approximately 163 customer organizations.
Both incidents demonstrate that social engineering relies on trust and human error rather than technical vulnerabilities. Strong identity verification procedures, phishing-resistant Multi-Factor Authentication (MFA), and continuous security awareness training significantly reduce the likelihood of these attacks succeeding.
Who they most often target
Phishing does not choose victims. It chooses access and influence.
The closer someone is to systems, money, or decision-making, the more attractive they become.
Roles
employees with email and internal system access
finance and operations teams
leadership and key decision makers
IT and support staff
Sectors
small and mid-sized businesses
professional services
manufacturing and logistics
public sector
healthcare and education
Organization types
with unclear or immature security processes
operating hybrid and cloud environments
undergoing growth and organizational change
The more dynamic the environment, the easier it is for phishing to blend into daily operations.
What the attack relies on
Phishing rarely succeeds because of a single weakness.
It works when human, technical, and process layers align in the attacker’s favor.
Human factors
urgency and time pressure
cognitive overload
trust in authority
fear of mistakes
willingness to help
Technical gaps
lack of multi-factor authentication
weak email protection
compromised accounts
limited visibility
Process weaknesses
unclear approval flows
missing verification steps
insufficient training
no established reporting habits
Phishing succeeds when the environment enables it.
How it is detected
Phishing is rarely detected through a single signal. More often, it is recognized through patterns.
The difference between an incident and a breach is how early those signals are seen.
What users may notice
unusual tone or urgency
unexpected financial changes
suspicious links or attachments
subtle inconsistencies
What IT teams observe
abnormal logins
new or unknown devices
irregular access patterns
anomalous email activity
What SOC teams detect
behavioral anomalies
indicators of active campaigns
credential misuse
post-email lateral movement
Phishing rarely remains isolated. When unnoticed, it almost always becomes the first step of a larger incident.
How impact is contained
In phishing incidents, speed matters more than perfect certainty.
The first priority is not full investigation, but breaking the attack chain.
immediately isolating affected accounts
resetting credentials and revoking active sessions
removing malicious inbox rules and forwards
investigating follow-on activity
notifying internal teams
What does not help:
deleting the email without analysis
assigning blame
delaying response
Phishing does not wait. Containment should not either.
What realistically helps
Phishing is not eliminated. It is managed as an ongoing risk.
And it requires coordination across people, processes, and technology.
People
regular, realistic training
non-punitive reporting culture
simple escalation paths
Processes
clearly defined financial and access workflows
dual-approval principles
response playbooks
attack simulations
Technology
advanced email and domain protection
multi-factor authentication
behavior-based monitoring
XDR and SOC visibility
The better these layers work together, the harder it becomes for phishing to escalate into an incident.
Common myths
Myths around phishing often create false confidence.
“Training alone will solve it”
“We have email security, so we’re covered”
“We would notice if it happened”
“Only small organizations get phished”
In reality, phishing remains the most common entry point even in mature security environments.
Next: Attack #2 – Credential Abuse & Account Takeover






