top of page

One Convincing Conversation Can Bypass a Lot of Cybersecurity

Sep 7
4 min read
Team in an office working at computers, overlaid with colorful social media and chat icons, suggesting digital communication and collaboration

We spend a lot of time worrying about hackers breaking into computers…but sometimes, they simply convince someone with legitimate access to let them in.

Insider threats like these occur worldwide. Employees can accidentally or intentionally share protected information with others. It happened in a recent cyberattack against the cardiac monitoring company iRhythm.

The attackers did not need to exploit the company’s medical devices or break through some previously unknown technical vulnerability. They used social engineering.

So what effect does a breach like this have on a company’s cybersecurity? What does it mean for the customer data they manage, and how does any of this relate to cyber-compliance?

What Happened to the PHI?

On June 8, iRhythm discovered unauthorized activity involving information stored in third-party-hosted business applications. The following day, the company received communications from a threat actor claiming to have stolen sensitive information and demanding payment to prevent its release. Following appropriate cyber-compliance protocols, they filed the incident with the SEC.

Keep in mind, iRhythm produces heart monitoring patches and devices. So what kind of information could the manufacturer possibly have at risk?

Stolen information included proprietary company data, personal information, and patient Protected Health Information (PHI).

So how did the attackers get access? It started with social engineering.

Social Engineering Isn’t Just Phishing Anymore

When you hear “social engineering,” you probably picture a badly written phishing email asking you to click a suspicious link. Unfortunately for the targets, modern social engineering has become much more convincing with the help of artificial intelligence.

For example, an attacker might pretend to be an employee who cannot access an account. They could impersonate someone from IT, call a help desk, send a text message, or claim that they urgently need a password reset. These tactics create fear and urgency, which often prompts people to forgo their usual best practices and react.

AI helps these threat actors study particular targets much more quickly and efficiently, helping them craft more specific and convincing scam messages. They may already know your name, job title, coworkers, company, and other seemingly insider information when they contact you.

That makes these attacks difficult to spot and avoid, because the person on the other end tends to genuinely sound like they belong. In 2026, social engineering was the third most common cause of data breaches. Attackers are increasingly expanding beyond traditional email phishing into mobile devices and other communication channels, often using AI to help exfiltrate private data from otherwise informed and well-meaning employees.

Where Cyber-compliance Comes In

Controlling access to sensitive information is a staple of maintaining proper data compliance. Organizations establish passwords, multi-factor authentication, access permissions, and other safeguards so that only authorized people can reach the protected data.

Social engineering attacks target the people responsible for maintaining those safeguards, or those with legitimate access past them.

Let’s imagine someone calls, claiming to be a coworker who has gotten locked out of an important account. They know the employee’s full name, mention the specific department, and even know the name of the latest project and its lead manager.

In this scenario, the “coworker” is known as the mask. The mask is essentially the false persona they put on to trick their victims.

Now pretend that the fake coworker also says they have an important deadline in 15 minutes. Would you help them?

That sense of urgency is exactly what attackers hope for when they target you.

How Can Helpfulness Threaten Cyber-Safety?

Most employees are not trying to violate security policies at work. In fact, in many cases it’s quite the opposite.

People try to help a frustrated coworker, quickly resolve a customer issue, or keep an important project moving. Unfortunately, attackers take advantage of those very instincts.

If company policy requires you to verify someone’s identity before resetting a password, sharing information, changing an account, or granting access, then you need to do it every time.

It doesn’t matter whether you recognize their voice, because AI can now replicate people’s speech patterns by analyzing prior recordings. Even if they know information that “only an employee would know,” they could have gleaned that from prior data leaks, online posts, or another insider mistake.

No matter how urgent they claim the situation to be, you should always prioritize cybersecurity and ensure the message is genuine.

Trust the Process, Not the Person

Verification procedures exist because appearances can be convincing. Here are a few best practices that will better protect your data and keep you cyber-compliant every day:

  • Follow the approved process before sharing sensitive information or changing an account.

  • Never give someone your password or MFA code.

  • Never approve an MFA request that you didn’t initiate yourself.

  • Double-check odd requests by contacting the person through a company-approved channel that you already know is legitimate. For example, if you receive a suspicious call from “IT,” hang up and contact your IT department using its normal internal number instead of a number the caller provides.

If someone pressures you to bypass normal procedures, that should make you more cautious, instead of less. One extra minute of caution can completely derail a social engineering attack!

Conclusion

Although the iRhythm incident involved leaked healthcare information, social engineering does not only affect PHI. It can happen at a bank, retailer, law firm, accounting office, school, small business, or virtually anywhere else.

Cybersecurity systems are designed to determine who should have access to sensitive information. Social engineering attempts to convince an authorized person to override those protections. For this and many other reasons, compliance procedures matter even when they feel inconvenient.

Attackers can sound professional. They can even sound like someone you trust. Even knowing surprisingly specific information about your company doesn't necessarily mean the requester matches the mask.

You must always verify, regardless. Many people can give you a convincing story, but it should never be enough to hand over access to sensitive information.

Comments


bottom of page