# Social Engineering: A Chain of Attacks That Starts With One Click

**URL:** https://securesys.com.tr/en/learning/penetration-testing/social-engineering-awareness-in-penetration-testing

A manufacturing company trusted the web-based ERP system it had used for years.

It ran a [next-generation firewall](/en/services/firewall-solutions-ngfw).

An EDR solution was in place.

Employees connected over VPN.

Backups were taken regularly.

At first glance, everything looked secure.

One Monday morning, an employee in the procurement department received an email that appeared to come from a supplier.

It contained a single line.

#### "Could you review the updated price list?"

![Social Engineering: A Chain of Attacks That Starts with a Single Click](/images/bilgi-merkezi/covers/cover-sizma-05.webp)

The employee clicked the link.

Nothing happened.

Or so it seemed.

At that moment the attacker captured the user's session credentials.

They logged into the VPN.

They reached the internal network.

They discovered the file servers.

Using a misconfigured service account in Active Directory, they escalated their privileges.

For roughly six hours they moved through the network unnoticed.

By the evening, critical servers were being encrypted.

The next day, production stopped.

Orders could not be processed.

Customer deliveries were delayed.

The organisation lost more than a few servers: it lost time, reputation and customer trust.

The forensic investigation found no critical gap in the security products in use.

The problem was that the vulnerabilities the attacker used had never been tested against realistic attack scenarios.

Following the incident, the organisation launched a comprehensive security programme covering regular penetration testing, privileged account management, network segmentation and security awareness training.

### A Social Engineering Scenario

There were fifteen minutes left in the working day.

Ayşe, who works in the finance department, answered her phone.

**"Good afternoon Ayşe, it's Ahmet from IT. We've had a synchronisation problem on your account during the Microsoft 365 migration. We need to verify it."**

The caller was entirely calm.

He knew her name.

He knew which email system the company used.

He even named the IT manager.

Trust was established.

"You don't need to tell me your password. You'll receive a verification code — just read it back to me."

A few seconds later, a verification code really did arrive.

Ayşe read it out.

The call ended.

Everything seemed normal.

About half an hour later, the attacker signed into the Microsoft 365 account.

They read the mailbox.

They read management correspondence.

They obtained supplier invoices.

The following day, fraudulent payment instructions began going out in the company's name.

#### The social engineering techniques used in this scenario

- Building trust
- Posing as an insider (pretexting)
- Creating a sense of urgency
- Capturing the MFA verification code
- Phishing over the telephone (vishing)

#### Measures that would have helped

- IT teams should never ask for an MFA code by telephone.
- Employees should receive regular social engineering awareness training.
- Suspicious requests should be verified through a second channel.
- Awareness of MFA fatigue and verification-code fraud should be raised.

Cyber attacks rarely rely on a single vulnerability. They usually run as attack chains, where several small weaknesses are used one after another.

The purpose of a professional penetration test is therefore not simply to find individual vulnerabilities, but to show how an attacker could combine them — and so reveal the organisation's real level of risk.

### Why This Scenario Matters

At first glance the cause looks like one small mistake by one employee. In reality, successful cyber attacks usually come not from a single vulnerability but from attack chains in which technical weaknesses and the human factor are used together.

Social engineering does not attack the technical controls directly; it exploits human psychology. Building trust, manufacturing urgency, imitating authority and provoking curiosity are all used to win an employee's confidence.

Capturing a user's credentials is usually only the beginning. The real risk starts afterwards. If access controls inside the organisation are weak, if network segmentation is poorly configured, or if privileged accounts are inadequately protected, the attacker can reach critical systems very quickly.

This is why penetration tests today are planned to cover not only technical systems but social engineering scenarios and employee awareness. A strong security culture is built by protecting technology and people together.

### The SecureSys View

Social engineering cannot be prevented entirely, but regular awareness training, controlled phishing simulations, multi-factor authentication (MFA), [privileged access management](/en/services/pam-mfa-solutions) (PAM) and regular penetration testing significantly reduce the success rate of these attacks.

Successful organisations do not only invest in security products; they set out to make their people the strongest link in the security chain.

---

**← Previous chapter:** [How Is the Scope of a Penetration Test Determined?](/en/learning/penetration-testing/how-to-define-penetration-test-scope)

**Next chapter →** [Black Box, Gray Box and White Box Penetration Testing](/en/learning/penetration-testing/black-box-gray-box-white-box-penetration-testing)
