Hacking News All articles
Opinion

They Read Your Slack Before They Phished You: How Attackers Are Mastering Your Company's Culture to Walk Right Through the Front Door

Hacking News
They Read Your Slack Before They Phished You: How Attackers Are Mastering Your Company's Culture to Walk Right Through the Front Door

Photo: Acabashi, CC BY-SA 4.0, via Wikimedia Commons

Let me paint a picture that should make your stomach drop a little.

A mid-sized logistics company in Ohio gets a Slack message from someone claiming to be a new IT contractor. The message references a recent all-hands meeting — by name, by topic, with a joke that landed. It mentions the sender's supposed manager, who is a real person, by their nickname. It uses the exact same casual tone the team uses internally. It asks for temporary VPN credentials "while the onboarding ticket gets sorted."

Three people said yes before anyone thought to pick up the phone.

This isn't a hypothetical. Variations of this scenario are playing out across American businesses at a pace that should be alarming security professionals a lot more than it currently is. The attackers behind these intrusions aren't necessarily more technically sophisticated than they were five years ago. They're more culturally sophisticated. And that distinction matters enormously.

The Reconnaissance Phase Nobody Talks About

When we talk about pre-attack reconnaissance, we usually mean technical stuff — scanning for open ports, identifying software versions, mapping network topology. That work still happens. But the most dangerous threat actors today are running a parallel reconnaissance track that's almost entirely human intelligence-focused.

LinkedIn is the starting point, but it's barely scratching the surface. Organizational charts, employee tenure, reporting relationships, recent promotions and departures — all of it is publicly accessible to anyone patient enough to piece it together. Job postings are a goldmine: they reveal internal tools, team structures, current projects, even the names of managers and leads. Press releases, conference talks, podcast appearances, and company blog posts fill in the cultural texture.

Then there's the stuff that's technically public but feels private. Glassdoor reviews reveal internal tensions, management friction, and cultural pain points with remarkable specificity. Reddit's r/cscareerquestions and similar communities are full of employees venting about their workplaces in ways they'd never say in a formal channel. GitHub repositories tied to company email addresses expose project codenames, internal tooling, and sometimes actual employee communication patterns in commit messages.

"By the time a sophisticated attacker makes contact with a target employee, they often know more about that person's work life than the employee's own manager does," says one social engineering researcher who has spent years doing adversarial simulation work for enterprise clients. "They know who the person likes, who they find annoying, what projects they're proud of, what's currently stressing them out. That's not a technical attack anymore. That's a relationship attack."

Why Culture Is a Security Surface

Every organization has cultural patterns that, once understood, can be exploited. The startup that prides itself on moving fast and not asking too many questions. The enterprise where nobody wants to be the person who slows down a deal by raising a security concern. The team that's so collegial that declining a request from a "colleague" feels socially costly.

Attackers catalog these dynamics deliberately. Urgency exploits work better in high-pressure sales cultures. Authority exploits land harder in hierarchical organizations where questioning leadership is implicitly discouraged. Helpfulness exploits are devastating in service-oriented teams where saying no feels antithetical to the team's identity.

One breach case study that made the rounds in the security research community last year involved a financial services firm where the attacker spent three weeks studying the company's public-facing content before attempting any contact. They identified that the firm had recently gone through a merger and that internal communications about the integration had been chaotic. They crafted a pretext around "merger-related IT reconciliation" — a completely plausible, anxiety-inducing scenario for employees who'd been living through exactly that chaos. The phishing campaign that followed had an open rate that made the security team's hair stand on end.

The Insider Threat Simulation Problem

Here's an uncomfortable truth: most security awareness training is built around obvious attacks. The Nigerian prince email. The "your account has been compromised" fake login page. Employees are getting decent at spotting those. They are not getting good at spotting attacks that feel like they're coming from inside the house.

Traditional phishing simulations send fake emails from external domains with slightly suspicious formatting. They don't simulate an attacker who knows your VP of Engineering just posted on LinkedIn about shipping a new feature, who knows your team uses 'lgtm' as shorthand in code reviews, who knows your company does 'no-meeting Fridays' because your CEO mentioned it in a podcast three months ago.

Security researchers I've spoken with are increasingly pushing for what some are calling "cultural penetration testing" — red team exercises that specifically test whether an organization's social and cultural patterns can be exploited. A few specialized firms are doing this work, and the results are consistently humbling for the client organizations involved. "We've never done a cultural red team engagement where we didn't find a viable path in," one researcher told me flatly. "The technical stuff is almost secondary at that point."

The AI Multiplier

This problem is getting worse, not better, and the reason is AI — specifically, the use of large language models to accelerate and scale the reconnaissance and impersonation phases of social engineering attacks.

An attacker who used to spend two weeks manually building a cultural profile of a target organization can now feed publicly available data into an LLM and get a sophisticated cultural briefing in hours. Writing style analysis, tone matching, vocabulary mirroring — these are things LLMs do well and do fast. The barrier to entry for high-quality, culturally fluent social engineering is dropping rapidly, which means the volume is going up.

We've already covered AI-assisted phishing in these pages. But the cultural intelligence layer is distinct from the writing style mimicry piece. It's not just about sounding like your boss. It's about understanding your organization's social physics well enough to know which buttons to push, in which order, to get a human being to do something they shouldn't.

Building Actual Cultural Defenses

So what do you do about an attack surface that's fundamentally human?

For starters, organizations need to get honest about what they're broadcasting publicly. Not every piece of cultural information needs to be scrubbed from the internet — that's neither possible nor desirable — but security teams should periodically audit what a determined attacker could learn about their organization from open sources. The results are often eye-opening.

Verification culture matters more than almost anything else. Organizations that make it genuinely easy and socially acceptable to verify identities out-of-band — "hey, I'm going to shoot you a quick text to confirm this is really you" — are dramatically harder to social engineer than organizations where such verification feels awkward or paranoid.

Security training needs to evolve past phishing simulations and into scenario-based exercises that reflect how sophisticated attacks actually work. That means simulations involving plausible internal contexts, real cultural references, and pretext scenarios drawn from the organization's actual situation.

And honestly? Security teams need to start thinking like anthropologists as much as engineers. Understanding your own organization's culture — its pressure points, its trust patterns, its social hierarchies — is no longer just a management concern. It's a security concern. The attackers already figured that out.

All Articles

Related Articles

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?