Bank of Baroda Data Breach: 700 GB to 1 TB of Alleged Banking Data Leaked
Bank of Baroda data breach has placed India's banking sector under the...
Read more ›Kevin Mitnick spent years as the FBI’s most-wanted computer criminal, breaking into networks at Nokia, Motorola, Sun Microsystems, and Pacific Bell. But the uncomfortable truth in his own account of that era is this: most of his access didn’t come from exploiting code. It came from exploiting people.
He’d call an employee, sound confident, use the right internal jargon, claim to be from IT or a manager under pressure, and ask for what he needed. A password. A callback number. A “quick favor.” He called this social engineering, and he was so effective at it that prosecutors reportedly told a judge he could start a nuclear war by whistling into a payphone. That claim was absurd. But the underlying fear it revealed wasn’t: that a sufficiently convincing human voice can bypass almost any technical safeguard.
Mitnick spent the years after prison until he died in 2023 teaching companies exactly this lesson through his books and security consulting work: the strongest firewall in the world means nothing if someone can be talked past it.
Nowhere is that more true today than in financial fraud.
The techniques Mitnick pioneered on landlines in the 1990s haven’t gone away. They’ve been repackaged for online banking, mobile payments, and messaging apps. The core move is unchanged: create urgency and get the target to act before they think.
A few patterns are dominating financial fraud across the US, UK, and Australia right now:
Every one of these succeeds the same way Mitnick’s calls did decades ago, not by breaking encryption, but by breaking judgment under manufactured pressure.
One of Mitnick’s most repeated points, later echoed across the security industry, is that social engineering isn’t about tricking gullible people; it’s about exploiting normal, healthy human instincts:
None of this requires a single line of malicious code. It requires a script, a phone, and a target who hasn’t been trained to pause.
Mitnick’s later career was built on a simple premise: organizations spend heavily on technical controls and comparatively little on preparing people to recognize manipulation. The same gap shows up individually with financial fraud. A few habits close most of it:
If a call, text, or email claims to be your bank or a government agency, hang up and call the organization back using the number on the back of your card, or the official number from their website — never one given to you during the contact.
Legitimate banks and tax authorities do not ask you to move money to a “safe account,” do not request one-time passcodes, and do not demand payment via gift cards, wire transfer, or cryptocurrency.
Legitimate institutions rarely require you to act within minutes. Pressure to skip verification is itself the strongest signal something is wrong.
Not your bank, not “IT support,” not a “financial advisor” you’ve never met in person.
Guaranteed investment returns, unexpected romantic interest that turns into financial requests, “insider” trading tips these use the same rapport-building playbook as impersonation scams, just with a friendlier tone.
In all three countries, speed matters; funds can sometimes still be frozen or recalled if reported within the first hours after a transfer.
Mitnick’s own transformation from the person exploiting trust to the person teaching organizations how to defend against it carried one consistent message: technology can be patched, but human trust has to be trained. Banks harden their systems every year. Fraudsters don’t bother trying to break them. They call the person holding the account instead, because it’s still the easiest way in.
The best defense against social engineering isn’t smarter technology. It’s a habit of pausing, verifying independently, and refusing to let urgency decide for you.
Weekly intelligence digest. Breaches, detections, and analysis
By submitting this form, you agree to our terms of use and acknowledge our privacy statement.
Bank of Baroda data breach has placed India's banking sector under the...
Read more ›
June 19, 2025: In a massive twist of events, Bitdefender has announced...
Read more ›
On May 15, 2025, Coinbase acknowledged its most serious security lapse to...
Read more ›Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.
Phone
+1 607 360 5504
Sales Office - United States
651, N Broad St, Middletown
Delaware-19709
Operations Center- India
Level 17, TransAsia Cyber Park
Kochi, Kerala-682030
Data privacy notice.
All submissions are protected via TLS 1.3 encryption in transit and
processed within our secure, air-gapped data environment. We never resell your data.