In July 2020, a 17-year-old in Tampa, Florida named Graham Ivan Clark convinced a Twitter employee to hand over access to the company's internal administrative tools. He did not write a single line of malicious code. He did not exploit a software vulnerability. He called the employee on the phone, pretended to be from Twitter's IT department, and asked for the credentials. The employee gave them. Within hours, Clark had taken over the accounts of Barack Obama, Joe Biden, Elon Musk, Apple, and dozens of others, and used them to run a Bitcoin scam that netted over 100,000 dollars before Twitter shut it down.
The most sophisticated cybersecurity infrastructure in the world could not have stopped this attack. Twitter had firewalls, intrusion detection systems, multi-factor authentication, and a security team. None of it mattered, because the attacker did not go through any of it. He went around it, through a person.
This is the story that the cybersecurity industry has been telling itself for thirty years, and largely failing to act on: the most dangerous vulnerability in any system is not the software. It is the human being operating it.
The Anatomy of a Social Engineering Attack
The term for what Clark did is social engineering, a phrase that makes it sound more technical and less embarrassing than it actually is. Social engineering is manipulation. It is the practice of convincing people to do things they should not do by exploiting the psychological tendencies that make humans functional social creatures: the desire to be helpful, the reluctance to challenge authority, the discomfort of conflict, the tendency to trust people who seem confident and knowledgeable.
The classic social engineering attack is the phishing email, a message that appears to come from a trusted source and asks the recipient to click a link, enter credentials, or take some action that gives the attacker access. Phishing has been around since the 1990s and is still, by a significant margin, the most common initial vector for data breaches. The reason it persists is not that defenders have not tried to stop it. It is that the attack exploits something that cannot be patched: the human tendency to make quick decisions under time pressure.
But phishing is the least sophisticated version of the attack. The more advanced forms, the ones that are actually difficult to defend against, involve research, patience, and a level of psychological sophistication that most security tools are not designed to detect.
"The most dangerous vulnerability in any system is not the software. It is the human being operating it."
The $81 Million Heist That Started With an Email
In 2016, attackers sent a series of emails to employees at Bangladesh Bank, the country's central bank. The emails appeared to come from the Federal Reserve Bank of New York, where Bangladesh Bank held an account. The emails requested transfers totaling nearly one billion dollars to accounts in the Philippines and Sri Lanka. The Federal Reserve processed the transfers. By the time the fraud was detected, 81 million dollars had already been moved and was largely unrecoverable. The attackers had spent months studying the bank's internal communication patterns, learning the names of executives, understanding the timing of legitimate transfer requests, and crafting messages that were indistinguishable from the real thing.
The Bangladesh Bank heist was not a technical marvel. It was a patient, methodical research project followed by a well-timed deception. The attackers understood that the most secure systems in the world have humans at their edges, and humans can be convinced to do almost anything if the request arrives in the right format, from the right apparent source, at the right moment.
Why the Industry Gets This Wrong
The cybersecurity industry generates approximately 200 billion dollars in annual revenue. The vast majority of that money is spent on technical solutions: firewalls, endpoint detection, vulnerability scanners, intrusion prevention systems, encryption tools. These products are necessary. They are not sufficient.
The problem is structural. Security vendors sell products, and products are technical objects. A vendor cannot sell you "better judgment under pressure" or "increased skepticism of unusual requests." They can sell you a software tool that scans emails for phishing indicators, which is useful, but which an attacker who has done sufficient research can route around by making their phishing email look exactly like the legitimate emails your organization receives every day.
Kevin Mitnick, the most wanted computer criminal in US history, said he never needed to break encryption. He just asked people for their passwords. They gave them to him.The fundamental insight of social engineering: humans are the vulnerability
The Verizon Data Breach Investigations Report, which analyzes thousands of confirmed breaches every year, has consistently found that the human element is involved in the majority of incidents. In the 2023 report, 74 percent of all breaches involved a human element, whether through error, privilege misuse, use of stolen credentials, or social engineering. This number has not meaningfully declined in the decade the report has been tracking it.
The Deepfake Dimension
The problem is about to get significantly worse. The emergence of convincing AI-generated audio and video has added a new dimension to social engineering attacks that the industry is not prepared for. In 2024, an employee at a multinational firm in Hong Kong was convinced to transfer 25 million dollars after attending a video call in which every other participant, including the company's CFO, was a deepfake. The employee had initially been suspicious of the request, which had arrived via email. The video call was designed to overcome that suspicion. It worked.
This attack required capabilities that were not available to attackers five years ago. The quality of AI-generated video has improved to the point where a real-time deepfake of a known executive, generated from publicly available video footage, is convincing enough to fool a trained employee in a live call. The attack surface has expanded from text to voice to video, and the cost of mounting a sophisticated impersonation attack has dropped dramatically.
The defenses against this kind of attack are not primarily technical. They are procedural. Organizations that have implemented out-of-band verification requirements, meaning that any request for a significant financial transfer must be confirmed through a separate, pre-established channel that is not the one the request arrived on, are substantially more resistant to this class of attack. The technology to make a convincing deepfake exists. The technology to simultaneously compromise a separate phone line or physical verification process does not, yet.
The Insider Threat
Not all human-element attacks come from outside the organization. The insider threat, the employee, contractor, or partner who misuses their legitimate access, is responsible for a significant proportion of serious breaches. The motivations vary: financial gain, grievance, coercion, ideology, or simple carelessness. The common thread is that the attacker already has access, which means that the perimeter defenses that consume most of the security budget are irrelevant.
The most damaging insider incidents in recent history have involved people with privileged access: system administrators, database operators, developers with production credentials. Edward Snowden was a contractor with legitimate access to NSA systems. The Capital One breach in 2019 was carried out by a former AWS employee who understood the cloud infrastructure from the inside. The Twitter hack of 2020 required only a single employee with access to the right internal tool.
Defending against insider threats requires a different approach than defending against external attackers. It requires the principle of least privilege, ensuring that every person has access only to what they need for their specific role. It requires behavioral monitoring, looking for anomalies in how people access and use data. And it requires a culture in which employees feel comfortable reporting suspicious requests or behavior without fear of retaliation, because the most reliable early warning system for an insider threat is often another employee who noticed something wrong.
What Actually Works
The organizations that are most resistant to human-element attacks share a set of characteristics that have less to do with their technology stack than with their culture and processes. They run regular, realistic phishing simulations that are designed not to punish employees who fail but to teach them what sophisticated attacks actually look like. They have clear, enforced procedures for verifying unusual requests, regardless of how urgent or authoritative the request appears. They treat security as a shared organizational responsibility rather than a function delegated entirely to a separate team.
They also invest in something that is difficult to measure and therefore often deprioritized: the psychological safety to say no. The Twitter hack succeeded in part because the employee who received the call from Graham Clark felt pressure to be helpful to someone who appeared to be from IT. Organizations where employees feel empowered to challenge unusual requests, to say "I need to verify this through a different channel before I proceed," are substantially harder to social-engineer than organizations where compliance and helpfulness are the dominant cultural values.
The technology will keep improving on both sides of this equation. Attackers will have better tools for impersonation and manipulation. Defenders will have better tools for detection and response. But the fundamental dynamic, that humans are the most exploitable component of any security system, and also the most capable of recognizing and resisting manipulation when properly prepared, is not going to change. The organizations that understand this, and invest accordingly, will be the ones that survive the next Graham Ivan Clark.





Comments
Comments are reviewed before they appear.
No comments yet. Be the first to share your thoughts.