CIO Brief: Social Engineering Your Employees Beats Hacking Your Systems
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by phoning Twitter employees and tricking them into handing over login details. Social engineering often beats technology.
Why people are the target
Attackers go where the defenses are weakest. A convincing phone call from "IT support" can get past firewalls, password rules and even some forms of multi-factor authentication. Employees with access to powerful internal tools are especially valuable targets.
The business impact
- Loss of control over customer accounts, systems or data.
- Public embarrassment when misuse is visible.
- Regulatory scrutiny of access controls and security leadership.
Questions to ask your team
- How many employees have access to powerful administrative tools?
- Is that access permanent, or granted only when needed?
- Would our sign-in protection stop a fake login page that relays codes in real time?
- How do employees verify that a call from "IT" is genuine?
What good looks like
Few administrators, time-limited access, phishing-resistant MFA for anyone with admin rights, and a simple verification rule: IT never asks for codes or passwords over the phone.
The decision
Ask how many people have standing administrative access today. Reducing that number — and making access temporary — directly limits what social engineering can achieve.
- The Twitter Hack (July 2020): Phone Spear-Phishing Against Internal Admin Tools Incident Teardowns
- How to Protect Internal Admin Tools With Privileged Identity Management How-To & Hardening
- Detecting Admin Tool Social Engineering: Entra Sign-In Logs and Sentinel KQL Detection & Response