Ace of Information Disclosure I
You’ve invented a new information disclosure attack.
Threat |
|
Your staff in tech support, customer services, finance, or some other department receive a call from someone asking for information urgently. The attacker is performing a technique called pretexting and will often use pressure and urgency to rush staff into not thinking clearly. |
|
CAPEC |
CAPEC-416 - Manipulate Human Behavior CAPEC-407 - Pretexting CAPEC-412 - Pretexting via Customer Service CAPEC-415 - Pretexting via Phone |
ASVS |
N/A |
CWE |
N/A |
Mitigations |
|
|