A vertical timeline presents 20 calls between columns titled Researcher observation and reactions and Interpretation and reaction of recipients. Call one is successful. R 1 states that the attacker was uncomfortable before and during the call. I 1 states that the recipient ignored pop ups and external numbers. Call two is unsuccessful. R 2 states that the attacker tried to make it seem that a boss had assigned the calls. I 2 states that the recipient referred to normally used I T Sec support methods and regarded email as secure. Call three is successful. R 3 states that the attacker realised humour could leverage data and make calls less stressful. I 3 states that the recipient tried to avoid the work by questioning its necessity. Call four is successful. R 4 states that the attacker began asking recipients to spell their full names because calls provoked no reports. I 4 states that the recipient was scared of losing access to her virtual desktop and complied with all demands. Call five is unsuccessful. R 5 states that the attacker observed that a vishing attack with a spoofed mail might have an immense success rate. I 5 states that the recipient did not hesitate to share personal information but insisted on an email for security reasons. Call six is unsuccessful. R 6 states that the attacker gained insight into the virtual desktop design through constant recipient feedback. I 6 states that the recipient could not comply because of lacking knowledge. Call seven is unsuccessful. R 7 states that the attacker made it appear that a spoofed phone number was used for the vishing attack. I 7 states that the recipient was suspicious of the caller, wanted to check with I T Sec, and called after 2 days but was persuaded that a wrong number had been called. Call eight is unsuccessful. R 8 states that the attacker said the number was on a list and that he did not check numbers beforehand. I 8 states that the recipient said the called number was a non-personal extension and personal numbers should be called. Call nine is successful. R 9 states that the attacker stopped relaying further numbers and said they would be called later, with no further call to that department to provoke a report. I 9 states that the recipient wanted to relay the security numbers of present workers. Call 10 is successful. R 10 states that the attacker conducted an attack on the forwarded person and was successful. I 10 states that the recipient did not know about the calls and forwarded the researcher to the department head. Call 11 is successful. R 11 states that the attacker began determining whether a call would succeed before fully describing the matter. I 11 states that the recipient had no questions or suspicion and immediately relayed all requested information. Call 12 is successful. R 12 states that the attacker used humour to leverage a worrying amount of personal data. I 12 states that the recipient questioned suspicious parts of the reasoning but was easily persuaded with humour. Call 13 is successful. R 13 states that the attacker could guide the recipient through the website without seeing the virtual desktop by using previously acquired knowledge. I 13 states that the recipient said this was not the normally used support method but relayed all information anyway. Call 14 is successful. R 14 states that the attacker prolonged the call even when the test subject was stressed to leverage more personal data. I 14 states that the recipient repeatedly mentioned being stressed but still had time to joke. Call 15 is successful. R 15 states that the attacker began recognising test-subject patterns and how to leverage data quickly. I 15 states that the recipient did not seem to understand what was happening or what the researcher requested but complied. Call 16 is successful. R 16 states that the attacker blocked the number immediately after the call to provoke a report, but no report was filed. I 16 states that the recipient insisted on a call back after asking I T Sec. Call 17 is unsuccessful. R 17 states that the attacker tried humour and sympathy without success. I 17 states that the test subject was non-compliant because of workload and stress. Call 18 is successful. R 18 states that the attacker used time pressure to make the person ignore the pop up. I 18 states that the recipient read the pop up aloud but ignored its warning. Call 19 is successful. R 19 states that the attacker acquired enough information to provide recipients with step-by-step instructions for navigating the virtual desktop. I 19 states that the recipient had difficulty following orders and wanted other present workers to do the same. Call 20 is unsuccessful. Additional notes state Start: December. 04; after call four, more personal data was asked for; by call nine, the attacker could make calls comfortably and without stress; later, the attacker could easily leverage data from calls and make test subjects relay the security code without discomfort; and calls were stopped on December. 20 after an incident reduced a department's efficiency and ethical risks were elaborated.Timeline of calls conducted in the study and general observations
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.