Step 4 – launching the attack

Technically, launching the attack is not complicated. The most important part is to create a message that is 100% trustworthy and realistic with a clear call to action.

Another thing to consider is timing. In our experience, we have been most successful when sending emails at the end of the working week when people are less focused. When successful, it also gives us the opportunity to initiate operation during the weekend when IT staff numbers are normally heavily reduced.

In this particular scenario, we sent the first email on a Friday, right after lunch. When we later realized that the recipient had not downloaded ...

Get Learn Social Engineering now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.