Social Engineering
Social engineering targets people, not passwords. An attacker might impersonate a banker, a lawyer, or even a family member to pressure someone into wiring funds, sharing login credentials, or bypassing a normal approval process. Because the "hack" happens in a conversation rather than a computer, technical security tools alone cannot stop it.
Family offices are attractive targets precisely because of what they are: concentrated organizational infrastructure around significant wealth, often staffed by a small, trust-based team. A tight-knit staff can become a vulnerability when an outsider convincingly mimics an insider. Common tactics include fake urgency ("the wire must go today"), authority spoofing ("the patriarch asked me to call"), and pretexting — building a believable backstory to lower a staff member's guard.
Consider a hypothetical: a family office CFO receives a call from someone claiming to be the family's outside counsel, referencing a real ongoing transaction by name. The caller asks for wiring instructions to be "confirmed" by email. That reference to genuine details — harvested from a prior phishing email — is what makes social engineering so effective. Families typically address this by establishing verbal code words or callback procedures for any out-of-band financial request.
Social engineering is the foundation beneath most financial fraud, including phishing and incident response scenarios. Training staff to pause, verify through a known channel, and never feel embarrassed to slow down a request is widely considered the single most practical defense.
Istilah Terkait
A fraudulent message — usually email, text, or voice — designed to trick a recipient into revealing…
IstilahWire FraudWire fraud, in the family office context, is a cyberattack in which criminals impersonate a trusted…