Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • How Phishing Uses Our Strengths Against Us current page
Link copied

How Phishing Uses Our Strengths Against Us

Jan 22, 2020
Author:
Jay Beale 2021 Headshot
Jay Beale
CEO, CTO at InGuardians, Inc.
Blog banner default
How Phishing Uses Our Strengths Against Us
Jay Beale 2021 Headshot
Jay Beale
CEO, CTO at InGuardians, Inc.

In my December 2019 webinar, Hacking the Human, I demonstrate how to conduct a phishing campaign, using email-based social engineering to gain passwords. Why do I teach you how to phish this time, instead of showing you how to compromise computer systems? Well, one of the most effective ways to hack into an organization, hands down, is to use social engineering against its employees/members. This is borne out time and time again, as we see the bulk of compromises begin with a phishing attack. Even nation-state hacking operations, which have certainly bought/collected “zero day” exploits, appear to save these for precious few occasions. They know the same thing that organized crime and professional loan wolf bad actors know: phishing will get the initial access you’re seeking—almost every time.

Phishing is the best bang-for-your-buck form of social engineering, where “buck” here refers to a threat actor’s time. It scales better (hits more people per second) than in-person confidence games. Even in this era of robo-calls, online phishing still appears to have a higher success rate than phishing by voice (phone), also known as “vishing.”

So, why do phishing and social engineering techniques continue to work with such unwavering consistency?

At the end of the day, social engineering is effective because human beings have evolved to be vulnerable to it. That might sound pessimistic, so let’s expand. Social engineering is effective because it targets the very strengths that evolution has built for us.

Humanity’s unique strength as compared to other mammals, and even primates: we are incredibly social and can work together in very large groups. Put simplistically, we are inclined to be helpful to each other. That helpfulness means ancient human teams could hunt mammoths and that modern human teams can create multi-year, 50-person software engineering projects.

Unfortunately, social engineering can prey on humanity’s social strengths. Our helpful nature is one of the primary targets that effective social engineering exploits.

For a more in-depth exploration of how phishing works, and a demonstration on how to build your own phishing campaigns, watch this webinar.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • And the United Kingdom Just Became a Safer Country Because....?
    Dec 2, 2016 And the United Kingdom Just Became a Safer Country Because....?
    Blog
    1m
  • Learning Defense from NSA's Elite Offensive Hacking Teams – part 1
    Feb 10, 2016 Learning Defense from NSA's Elite Offensive Hacking Teams – part 1
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.