Homo Hackabilis: Why Hack a Server When You Can Just Call a Human?
A hospitality consultant recounts four near-identical cyberattacks on clients, all exploiting staff via phone-based impersonation rather than technical exploits.
Photo by Hospitality Net
This week, I found myself dealing with the fourth cybersecurity incident involving one of my clients, virtually identical to the others I’ve seen over the past few months. And by the fourth one, I started to suspect that the problem with cybersecurity has much less to do with the "cyber" and much more to do with the "security" that Mother Nature forgot to install in our brains.
The mechanics are wonderfully primitive: someone calls, introduces themselves as tech support, convinces an employee to install remote-access software, and the employee promptly hands them the keys to the computer. No cascading streams of green Matrix code (which, fun fact, isn’t actually code: designer Simon Whiteley took those characters from his wife’s Japanese cookbooks. In other words, for twenty-five years we thought we were staring at the source code of reality when, in fact, we were looking at sushi recipes…). No WarGames. No antisocial genius locked in a basement cracking RSA while listening to Aphex Twin. Just a phone call.
Which almost makes the word “hacker” feel undeserved.
Odysseus had to design a gigantic wooden horse, convince the Trojans to drag it inside their walls, and wait until nightfall before crawling out of the beast’s belly. In 2026, all you need to do is introduce yourself as “Expedia support” and ask someone to install AnyDesk. Twenty-eight centuries of evolution, and social engineering still works exactly as it did in the Iliad: someone knocks on the door bearing a gift, and we let them in.
And that’s what I find fascinating: we spend thousands of euros on firewalls, endpoint detection, antivirus software, multi-factor authentication, and consultants whose certifications are longer than Wittgenstein’s Tractatus, while leaving the most vulnerable device in the entire infrastructure fully operational:
Homo sapiens.
Perhaps, then, the real malware has always been us.
And I’m afraid no patch has been released for that yet.
Comments
Comments for this content
0 comments available