CyOne Security AG
Zürich
Social Engineering: When Friend and Foe Are Hardly Distinguishable
- 07 August 2026
- 100%
- Permanent position
- Zürich
Job summary
Cyber criminals adopt roles like CEO or IT-Support to deceive.
Tasks
- They use social engineering to manipulate targets effectively.
- 80% of attacks now occur without malware involvement.
- Communities are increasingly targeted with CEO fraud scams.
Skills
- Understanding social engineering and its countermeasures is crucial.
- Awareness of phishing, vishing, and smishing techniques.
- Ability to identify and protect against deepfake threats.
Is this helpful?
About the job
CEO, IT support or municipal mayor – cyber criminals assume various roles to obtain data or money. Artificial intelligence exacerbates the risks of social engineering: attackers manipulate their victims with increasingly sophisticated methods. Learn more about the latest developments in the blog post and in the whitepaper how you can protect yourself against the tricks of social engineers.
Humans are the weakest link in cyber security – this is more obvious today than ever before. The focus of cyber crime is increasingly shifting towards social engineering. While the defensive walls of cyber protection have become more impenetrable in recent years, attackers have developed their techniques further to convince someone inside the target organisation to open the door. Employees are manipulated with ever new means to obtain data or money.
The vast majority of attacks today occur without malicious code. As the CrowdStrike 2025 Global Threat Report shows, around 80 percent of all cyber attacks now take place without the use of malware. Email remains the dominant attack vector, but the methods increasingly go beyond phishing. For example, smishing involves baiting via SMS or messaging apps, and vishing manipulates people via telephone. Due to the variety of platforms and the combination of channels, it is becoming ever more difficult to recognise fraud.
Social engineering often targets the helpdesk
A popular trick to gain access to user accounts is helpdesk social engineering. Here, the perpetrators call the IT helpdesk of an organisation, pose as employees and ask the counterpart to reset the password and multi-factor authentication (MFA) for the relevant account. MFA is often bypassed with SIM swapping by taking over the victim’s phone number – as was the case in the attack on Marks & Spencer, which paralysed the British retailer’s online shop for several weeks in spring 2025.
Increasingly, cyber criminals themselves assume the role of the helpdesk. For example, an employee is bombarded with spam emails, after which a supposed IT support contacts them to fix the problem. This support instructs the user to log into a remote support tool such as TeamViewer or Quick Assist, giving the attacker access to the network. Systems for Remote Monitoring and Management (RMM) have become a popular attack vector: according to analyses by the security provider Proofpoint, up to 60 cybercrime campaigns per month rely on access via RMM.
One of the most widespread social engineering methods remains CEO fraud: the attacker impersonates a managing director and tries to persuade employees to carry out a transaction. Voice cloning and deepfakes provide cyber criminals with new possibilities: it can happen that you find yourself in an online meeting with a fake boss. A finance employee in Hong Kong fell into such a trap in 2024 and authorised a transfer of 25 million dollars. The Federal Office for Cybersecurity (BACS) has also been reported such a deepfake attack, where the finance officer recognised the fraud in time.
Swiss municipalities in the crosshairs
In most cases, CEO fraud involves smaller sums that require less elaborate approval processes. Often, the perpetrators also instruct victims to organise gift cards for online or app stores. Municipalities in particular have recently been frequently targeted in this way. In 2025, BACS received increasing reports of attacks where the perpetrators impersonated municipal presidents. Due to their public structure and the high availability of information, municipalities are an attractive target for CEO fraud attempts.
Learn how you can protect yourself. The free whitepaper "Social Engineering – Attack Methods and Countermeasures" provides an overview of the most common methods and gives you valuable advice for defence.