← Back to blog

DVG Systems Social Engineering

5 Social Engineering Tactics Hitting Northern Ontario Businesses Right Now

9 min read
On this page

Firewalls, antivirus, and endpoint protection matter. But the most effective way into your business still isn’t through your technology — it’s through your people.

Social engineering is the art of manipulating someone into giving up access, credentials, or information they shouldn’t. It works because it exploits trust, urgency, and routine — not software vulnerabilities. And the tactics have evolved well beyond the “Nigerian prince” emails of a decade ago.

The 2024 Verizon Data Breach Investigations Report found that 68% of breaches involved a human element — whether through social engineering, credential misuse, or simple error. For businesses in Northern Ontario, where teams are often small and trust runs high, the risk is real.

Here are five social engineering tactics actively being used against Canadian businesses right now — and what your team can do about each one.

1. Out-of-Office Reply Exploitation

How It Works

When your staff set an out-of-office auto-reply, they’re telling the world exactly when they’ll be unavailable, who’s covering for them, and often who to contact instead. Attackers use this information to craft convincing follow-up messages.

For example: an attacker emails your accounts payable clerk and gets an auto-reply saying “I’m out until April 25 — please contact Sarah for urgent requests.” The attacker now knows the clerk’s schedule, Sarah’s name, and that Sarah is handling financial matters. They send Sarah an email impersonating the absent employee — or impersonating a vendor — referencing specific details from the auto-reply.

Real-World Example

Barracuda Networks documented this technique in their 2024 Email Threats Report, noting that attackers routinely harvest out-of-office replies at scale to map organizational structures and identify the best targets for follow-up phishing and business email compromise (BEC) attacks.

What to Do

  • Keep out-of-office replies vague for external senders — avoid naming specific colleagues or sharing project details
  • Use separate internal and external auto-replies (Microsoft 365 supports this natively)
  • Never include direct phone numbers or personal emails in external out-of-office messages
  • Brief your team before busy travel or vacation seasons

2. Deepfake Voice Calls Impersonating Executives

How It Works

AI-generated voice cloning has become disturbingly accessible. With just a few minutes of sample audio — often pulled from conference recordings, YouTube videos, or podcast appearances — an attacker can create a convincing voice clone of a company executive.

The attacker calls a staff member, impersonating the CEO or owner, and makes an urgent request: authorize a wire transfer, share login credentials, or send a file. The voice sounds right. The caller ID may be spoofed. The request comes with urgency: “I’m in a meeting and need this handled now.”

Real-World Example

In 2024, a finance worker in Hong Kong was tricked into transferring $25 million USD after a video call in which every other participant — including the CFO — was a deepfake, according to reporting by CNN and the Hong Kong Police. The UK’s National Cyber Security Centre (NCSC) issued guidance in 2024 specifically warning businesses about AI voice cloning in social engineering attacks.

What to Do

  • Establish a verification policy for any financial request or sensitive action — even if it appears to come from an executive
  • Use a separate, pre-agreed channel to confirm (e.g., if the request comes by phone, verify by Teams message or in person)
  • Never authorize wire transfers, credential changes, or data sharing based solely on a phone call
  • Make sure staff know that urgency is the attacker’s primary weapon — a legitimate request can always wait five minutes for verification

3. QR Code Phishing (Quishing)

How It Works

Quishing uses QR codes to direct victims to phishing sites. The codes appear in emails, printed flyers, or even physical signs posted in shared spaces. Because QR codes are opaque — you can’t see where they lead before scanning — they bypass the instinct to hover over a link and check the URL.

The phishing page behind the QR code typically mimics a Microsoft 365 login, a payment portal, or a Wi-Fi setup page. Once credentials are entered, the attacker has access.

Real-World Example

HP’s 2024 Threat Insights Report documented a significant rise in QR code phishing, with campaigns embedding malicious QR codes in PDF attachments sent via email — a format that bypasses many email security filters, since the malicious URL is encoded within an image rather than appearing as a clickable link. Abnormal Security’s 2025 Email Threat Report found that QR code attacks increased by 89% year-over-year.

What to Do

  • Train staff to treat QR codes from unknown sources the same way they’d treat unknown links — with suspicion
  • If a QR code appears in an email, question why a simple link wasn’t used instead
  • Use your phone’s QR scanner preview (both iOS and Android show the URL before opening) to check the destination
  • Report any unexpected QR codes posted in your office to IT immediately
  • Consider DNS filtering, which blocks the malicious destination regardless of how the link was delivered — learn more about how this works on our network security page

4. LinkedIn Reconnaissance for Targeted Spear-Phishing

How It Works

Spear-phishing is phishing tailored to a specific person. To make it convincing, attackers need to know details about the target — their role, their projects, their colleagues, their vendors. LinkedIn is a goldmine for all of this.

An attacker identifies key employees at your company through LinkedIn. They note job titles, reporting structures, recent posts about projects or events, and connections to vendors and partners. They then craft an email that references real details — a conference the target attended, a tool the company uses, a recent hire — making the phishing attempt far more convincing than a generic email blast.

Real-World Example

Microsoft’s Digital Defense Report 2024 highlighted that nation-state threat actors and financially motivated groups routinely use LinkedIn for reconnaissance before launching targeted attacks against businesses. The report specifically noted that small and mid-sized organizations are increasingly targeted because their employees’ LinkedIn profiles often reveal the entire organizational structure.

What to Do

  • Encourage staff to limit the operational detail they share on LinkedIn — job title is fine, but naming specific tools, vendors, or internal projects creates risk
  • Be skeptical of connection requests from people you don’t know, especially if they quickly follow up with a request or a link
  • If an email references details that could have come from LinkedIn, treat it with extra caution
  • Consider our email security guide for practical steps on identifying and handling suspicious messages

5. IT Helpdesk Impersonation

How It Works

An attacker calls your front desk, reception, or a general employee line and impersonates an IT support technician — either from your internal team or from a vendor. They claim there’s a security issue, an expired password, or an urgent system update, and ask the employee to provide credentials, install remote access software, or approve an MFA prompt.

This works particularly well in organizations that use third-party IT support, where employees may not know every technician by name or voice.

Real-World Example

This is exactly how the Scattered Spider group breached MGM Resorts in September 2023 — a breach that cost the company over $100 million USD, according to MGM’s own SEC filing. The attackers called the MGM IT helpdesk, impersonated an employee (whose details they found on LinkedIn), and convinced a helpdesk technician to reset the employee’s MFA. From there, they gained access to the company’s identity provider and moved laterally through the entire network. CISA and the FBI jointly published an advisory on Scattered Spider’s techniques in November 2023, warning that the group specifically targets helpdesks as an entry point.

What to Do

  • Establish a verification process for any IT support request — legitimate technicians will not be offended by being asked to verify their identity
  • Never share passwords, MFA codes, or install software at the request of an unsolicited caller
  • Define a clear process: if someone calls claiming to be from IT, hang up and call back using a known, verified number
  • Make sure staff know who your actual IT support contacts are and how to reach them through official channels

Building a Culture That Catches Social Engineering

These five tactics share a common thread: they exploit trust, urgency, and assumptions. No single technical control stops all of them. What does work is a combination of:

Awareness training — not a once-a-year compliance checkbox, but regular, scenario-based training that covers real tactics like the ones above. The SANS Institute’s 2024 Security Awareness Report found that organizations running monthly security awareness activities saw a 50% reduction in phishing susceptibility compared to those running annual training alone.

Clear policies — documented procedures for verifying financial requests, credential changes, and IT support interactions remove the ambiguity that attackers exploit.

A no-blame reporting culture — if an employee suspects they clicked something they shouldn’t have, or gave out information they shouldn’t have, you want them to report it immediately — not hide it out of fear of consequences. Speed of response is the difference between a contained incident and a breach.

Technical controls as a safety net — email filtering, DNS filtering, conditional access policies, and endpoint protection catch what humans miss. They don’t replace training, but they limit the blast radius when an attack gets through.

Next Steps

Social engineering is not going away — it’s getting more sophisticated with AI-generated content, voice cloning, and data harvested from professional networks. The businesses that stay ahead are the ones that invest in their people, not just their technology.

DVG Systems helps Northern Ontario businesses implement security awareness programs, email protection, and the technical controls that catch what training alone cannot. If you’d like to talk about how your team would handle any of the scenarios above — or if you want to test them with a simulated phishing exercise — reach out to us today.

Ask AI

Accessibility