---
title: The weakest link in safety is still man. Kevin Mitnick showed us how to outsmart us
description: The weakest link in safety is still man. Kevin Mitnick showed us how to outsmart us
---

# The weakest link in safety is still man. Kevin Mitnick showed us how to outsmart us

[Social Engineering](https://www.mitnicksecurity.com/in-the-news/tag/social-engineering), [Speaking Engagements](https://www.mitnicksecurity.com/in-the-news/tag/speaking-engagements), [Warsaw](https://www.mitnicksecurity.com/in-the-news/tag/warsaw), [Pendrives](https://www.mitnicksecurity.com/in-the-news/tag/pendrives), [Poland](https://www.mitnicksecurity.com/in-the-news/tag/poland), [Hacking Company Systems](https://www.mitnicksecurity.com/in-the-news/tag/hacking-company-systems), [Hacking Team](https://www.mitnicksecurity.com/in-the-news/tag/hacking-team), [Inside Trends](https://www.mitnicksecurity.com/in-the-news/tag/inside-trends), [Internet Cloud](https://www.mitnicksecurity.com/in-the-news/tag/internet-cloud), [Password Management](https://www.mitnicksecurity.com/in-the-news/tag/password-management), [Security Cards](https://www.mitnicksecurity.com/in-the-news/tag/security-cards), [Mitnick Security](https://www.mitnicksecurity.com/in-the-news/tag/mitnick-security), [Usb Cables](https://www.mitnicksecurity.com/in-the-news/tag/usb-cables), [Kevin Mitnick](https://www.mitnicksecurity.com/in-the-news/tag/kevin-mitnick), [Koneser](https://www.mitnicksecurity.com/in-the-news/tag/koneser)

[ Mitnick Security| ](https://www.mitnicksecurity.com/in-the-news/author/mitnick-security)  10.20.2018| 3 MIN READ TIME

Over the past 16 years, Kevin Mitnick's team of hackers broke into every company whose security he checked. - Those evil hackers are always looking for the weakest link in the security chain. In my opinion, most often these are people, not technology - said Mitnick on stage during the Business Insider Inside Trends conference at the Koneser Center in Prague. He showed that hackers are copying even the security cards of their victims during visits to office bathrooms.

Kevin Mitnick, once the most-sought-after FBI person in the United States , has been helping companies to check their security levels for years with his team.

Mitnick emphasized during the Business Insider Inside Trends conference that the most effective weapon in the hands of hackers is social engineering , which is appropriate manipulation of people and extracting information from them. - If an attacker can thus get into one person from your organization, all security measures can be bypassed without any problems - said Mitnick on the stage.

Interestingly, according to Mitnick, it may be easier to hack companies in the United States or Japan than in Poland, because people in our region are more skeptical and suspicious.

During the Business Insider Inside Trends conference, Mitnick presented techniques allowing to gain access to company systems.

### Social engineering in practice

Mitnick points out that using people to reach company systems is easier than utilizing hacking technology. It's almost free, and the risk for the attacker is very low. He noted that the effectiveness of such methods is even 99.5 percent.

The most famous hacker in the world pointed out that gathering information is a very important tool. He added that it is best to manipulate representatives of the sales and marketing department. - Students often work there - he explained.

Sometimes it's only a cursory search for information and the use of generally available tools. Mitnick told about one of the cases when he was hired by a large Canadian company. - I noticed that the website advertises a company dealing with human resources management in the Internet cloud - said Mitnick. All it took was just a few steps : registering the right domain, creating a fake page and tracking the person you can enter and the person to whom you should speak.

Within a few hours, he gained access to the data of all employees in the organization.

### Watch out for passwords, pendrives and cables

Mitnick also pointed out that by changing the password, which was previously stolen, it must be significantly modified . Hackers, using the database of stolen information, can check if the password has been changed only gently.

Many people know that they should not connect pen drives received from strangers to computers. Mitnick said that the attacks can be carried out using special, swapped ... USB cables.

### Double verification and copying of cards

Mitnick also showed that sometimes double verification will not save us from breaking into some websites . Hackers can steal ... session cookies that allow you to log on to a given page on another computer.

One of the most interesting "tricks" shown by Mitnick was copying access cards to office gates and doors. Hackers have tools that allow you to copy access cards to the building and premises in the company . It is enough to sometimes stand next to another person in a public toilet in a given building.

### How to defend yourself?

Kevin Mitnick pointed out that the best way to educate in companies is to carry out simulated tests . - When someone in the company clicks on such a link in the email, instead of downloading the malware, he will receive the following message: "You made a mistake. You have to watch the instructional video". The second mistake? He must watch the movie again. Third error? An hour of educational materials - said Mitnick. In the end, people have to learn, if only for their own protection..

He added that conducting security penetration tests is necessary in large organizations. Employees should also report suspicious emails or other activities within the company.

- "The bad guys" will always look for the weakest link in the security chain. In my opinion, most often these are people, not technology - explained Mitnick.

To view the original article and to read other great busines articles, refer to the [source.](https://businessinsider.com.pl/technologie/nowe-technologie/kevin-mitnick-na-inside-trends-o-tym-jak-wlamac-sie-do-firmy/nfwsbct)

Source: [BUSINESS INSIDER POLSKA](http://https://businessinsider.com.pl/technologie/nowe-technologie/kevin-mitnick-na-inside-trends-o-tym-jak-wlamac-sie-do-firmy/nfwsbct)

# Related Resources

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Screen%20Shot%202020-08-14%20at%203.48.55%20PM.png?width=350&name=Screen%20Shot%202020-08-14%20at%203.48.55%20PM.png)

by Mitnick Security  | 08.16.2019  | 1 min

#### Advice from Kevin Mitnick Featured in the Wall Street Journal Op-Ed

Kevin Mitnick was interviewed by Mr. Maniloff who is an attorney at White and Williams LLP in Philadelphia and an adjunct professor at Temple University’s Beasley School of Law.

 Continue Reading

Knowbe4, Cybercrime, Kevin Mitnick, Wsj, Op-ed 

](https://www.mitnicksecurity.com/in-the-news/advice-from-kevin-mitnick-featured-in-the-wall-street-journal-op-ed)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Images/Events/In%20The%20News/kevin-ku-w7ZyuGYNpRQ-unsplash.jpg?width=350&name=kevin-ku-w7ZyuGYNpRQ-unsplash.jpg)

by Mitnick Security  | 12.12.2018  | 3 min

#### 12 Ways to Defeat Two-Factor Authentication

Everyone knows that two-factor authentication (2FA) is more secure than a simple login name and password, but too many people think that 2FA is a perfect, unhackable solution. It isn't!

 Continue Reading

Speaking Engagements, Tw-factor Authentication - Roger A. Grimes, Chief Hacking Officer, Data-driven Defense Evangelist, Security Awareness Training, Knowbe4, Simulated Phishing Platform, 2Fa Solution, Kevin Mitnick 

](https://www.mitnicksecurity.com/in-the-news/12-ways-to-defeat-two-factor-authentication)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Images/Events/In%20The%20News/simon-abrams-k_T9Zj3SE8k-unsplash.jpg?width=350&name=simon-abrams-k_T9Zj3SE8k-unsplash.jpg)

by Mitnick Security  | 11.26.2018  | 1 min

#### We Need to Talk About NIST’s Dropped Password Management Recommendations

Passwords and their protection are among the most fundamental, essential aspects of enterprise data security. They also make up the bane of most users’ relationships with their enterprise devices, res...

 Continue Reading

Speaking Engagements, 2Fa, Biometric Security, Two-factor Authentication, Fraud Prevention, Password, Password Management, Kevin Mitnick Security Awareness Training, Multifactor Authentication (Mfa, Password Reuse, Kevin Mitnick 

](https://www.mitnicksecurity.com/in-the-news/we-need-to-talk-about-nists-dropped-password-management-recommendations)