Habr•August 30, 2026•🇷🇺Translated from Russian

Why 'Be Vigilant' Is Not Enough: Dissecting Human Psychology During Social Engineering Attacks

A cybersecurity specialist with extensive experience in SOC operations and penetration testing argues that the most expensive perimeter breaches rarely occur through code vulnerabilities. They happen through the person sitting behind that perimeter. Firewalls do not get tired, do not want to please management, and do not feel fear. Humans do.

This analysis focuses on the mechanics of what happens to a person at the moment of a social engineering attack and why standard awareness briefings provide little protection. The author stresses that social engineering does not target vices but rather positive traits such as politeness, willingness to help, and respect for authority.

Why vigilance fails under pressure

Standard responses to social engineering involve presentations and posters urging employees to “be vigilant.” Within weeks the same employees fall for the same tactics. The training lives in the conscious layer of the mind, while attacks operate by forcing automatic responses. Under time pressure and perceived authority, employees stop asking clarifying questions. The same person who would spot inconsistencies in a written request without time constraints will approve it when rushed.

The practical conclusion is that protection cannot depend on an individual’s willpower during their worst moment. It must rely on procedures that activate automatically.

Psychological levers attackers use

Attackers apply well-known mechanisms from social psychology:

  • Authority — confident tone and references to senior roles make employees reluctant to question requests, especially in hierarchical organizations.
  • Urgency — phrases such as “act immediately” or “account will be blocked in an hour” eliminate time for verification.
  • Reciprocity — attackers first “solve” a problem they created, creating a sense of obligation.
  • Social proof — claims that colleagues have already approved the action remove personal responsibility.
  • Sympathy and fear — emotional manipulation shifts the target from analytical thinking to emotional response.

All five levers target the same point: the willingness to take a pause. Effective defense must therefore protect that pause.

What actually works

Organizations should codify the right to pause in official procedures rather than presentations. Any urgent request involving money, access, or data must be confirmed through an independent channel. Employees must know they will not be punished for verifying requests, even when the caller claims to be the CEO. A culture that treats early error reporting as a positive action rather than a source of shame catches incidents early. Technical controls such as out-of-band confirmation codes and external-sender markings further reduce reliance on a single stressed individual.

The article concludes that security does not end at ports and patches. When psychological levers override procedures, the human element becomes the weakest link unless organizations deliberately design processes that think for employees when thinking becomes difficult.

Related articles

Habr•Fraud & Social Engineering

Silent Call Answering on Android: Defeating Phone Spam by Removing Human Attention

A detailed proposal suggests abandoning traditional spam call blocking in favor of allowing all incoming calls to connect automatically while keeping them invisible to the user. The approach uses Android's Telecom Framework and InCallService to answer calls silently without ringing, notifications, or screen activation. This breaks the economic model of mass dialing systems by inflating answered call metrics with empty connections that contain no human. The concept separates the technical establishment of a call from delivering user attention, forcing spammers to detect real people after the connection is made. Implementation requires the app to hold the ROLE_DIALER role and selectively invoke Call.answer() based on custom rules instead of always showing the incoming call UI. The author argues this shifts the detection burden onto robocall platforms and reduces the value of every successful connection.

Habr•Fraud & Social Engineering

Telegram Scam Bot Exposed by Fixed Timer and Deleted Messages in Telethon Userbot Analysis

A detailed investigation into a romance scam attempt on Telegram revealed an AI-driven userbot masquerading as a woman named Maria from Yaroslavl. The bot maintained consistent 4-5 minute response delays regardless of message length or time of day, responded to deleted messages, and accumulated multiple inputs before replying in batches. It refused out-of-character requests using repetitive phrases like "I am not a..." and handed off media or confusing inputs to a human operator. The bot failed to react to a nonexistent city name and ignored voice messages containing silence, leading to delayed human intervention. The chat was later deleted from the scammer side after testing, and the account ignored messages from a second profile. The analysis includes a full reconstruction of the bot's logic using the Telethon library, highlighting prompt protections against jailbreaks and reliance on fixed delays.

嘶吼•Fraud & Social Engineering

CACTER Upgrades PhishSim Anti-Phishing Simulation System to Reduce Employee Click Rates

CACTER has released an updated version of its PhishSim anti-phishing training platform that allows organizations to run realistic simulated attacks in just four steps. The system replicates common phishing vectors including malicious links, infected attachments, and disguised QR codes while spoofing sender addresses and official domains. Organizations can draw from a continuously refreshed template library covering invoices, financial subsidies, system notifications, and industry-specific scenarios. After each campaign the platform produces detailed visual reports that rank departments, classify employee risk levels, and recommend concrete remediation steps. Long-term use of the platform has been shown to lower average click rates from 23.88 percent to 4.16 percent. The solution is designed for immediate deployment without requiring dedicated security staff.

AntiMalware•Fraud & Social Engineering

Scammers Abuse Custom GPT on ChatGPT.com to Deploy Windows RAT via ClickFix Technique

Researchers at Huntress uncovered a phishing campaign that leveraged a custom GPT named Plus 5.6 hosted directly on the official ChatGPT.com domain. Victims searching for ChatGPT were directed to the malicious GPT through sponsored Google results, where the bot instructed them to visit a backup domain due to alleged service issues. The link led to a Google Sites page mimicking a Cloudflare security check that triggered the ClickFix social engineering tactic. Users were prompted to copy and execute a command in Windows, initiating a multi-stage infection with a remote access trojan capable of full system control, file access, screen viewing, and camera or microphone activation. Huntress confirmed at least 40 incidents tied to the campaign, though only two infections were directly traced to the malicious GPT. The first GPT was removed on September 25 after notification, but a replacement linked to the same operation appeared by September 27.