06/08/2026
Attackers research your practice before calling.
Before a social engineering attempt, a sophisticated attacker already knows:
→ Your software vendors (from your website and job postings) → Your staff names and roles (from LinkedIn and your own team page) → Your recent technology investments (from press releases and conference attendance) → The name of your IT company (often listed in vendor directories)
This reconnaissance takes less than 20 minutes. The attack call takes less than 5.
When the caller knows your systems, your vendor relationships, and the name of someone on your leadership team, the call sounds completely legitimate. That's the point.
Security awareness training needs to account for this reality. Staff need to understand that knowledge of internal details doesn't verify identity — only a confirmed callback does.
Learn how Black Talon helps dental organizations defend against targeted social engineering at https://blacktalon.co/49MzFiI