---
title: Hacker Kevin Mitnick on the dangers of human factors for health data security
description: Hacker Kevin Mitnick on the dangers of human factors for health data security
---

# Hacker Kevin Mitnick on the dangers of human factors for health data security

[Social Engineering](https://www.mitnicksecurity.com/in-the-news/tag/social-engineering), [Speaking Engagements](https://www.mitnicksecurity.com/in-the-news/tag/speaking-engagements), [Trojan Infection](https://www.mitnicksecurity.com/in-the-news/tag/trojan-infection), [Fake Software Updates](https://www.mitnicksecurity.com/in-the-news/tag/fake-software-updates), [Penetration Testing](https://www.mitnicksecurity.com/in-the-news/tag/penetration-testing), [Healthcare Organizations](https://www.mitnicksecurity.com/in-the-news/tag/healthcare-organizations), [Hillary Clinton](https://www.mitnicksecurity.com/in-the-news/tag/hillary-clinton), [John Podesta](https://www.mitnicksecurity.com/in-the-news/tag/john-podesta), [Russell Branzell](https://www.mitnicksecurity.com/in-the-news/tag/russell-branzell), [Security Training](https://www.mitnicksecurity.com/in-the-news/tag/security-training), [Usb Drives](https://www.mitnicksecurity.com/in-the-news/tag/usb-drives), [Chime Ceo](https://www.mitnicksecurity.com/in-the-news/tag/chime-ceo), [Data Breach](https://www.mitnicksecurity.com/in-the-news/tag/data-breach), [Phishing](https://www.mitnicksecurity.com/in-the-news/tag/phishing), [Kevin Mitnick](https://www.mitnicksecurity.com/in-the-news/tag/kevin-mitnick)

[ Mitnick Security| ](https://www.mitnicksecurity.com/in-the-news/author/mitnick-security)  02.19.2017| 2 MIN READ TIME

**At the CHIME-HIMSS CIO Forum, the infamous former black-hat showed how social engineering puts systems at risk -- and how to build a human firewall to protect against it.**

**Kevin Mitnick**, former black-hat hacker, now works as a white-hat security consultant. He spoke at the CIO Forum in Orlando about the need key for healthcare organizations to shore up their defenses by developing social engineering resistance training programs and performing penetration tests.

Legendary hacker Kevin Mitnick, who spent nearly three years as a fugitive from the FBI before being arrested in 1995, had some valuable advice for the healthcare chief information officers at the CHIME-HIMSS CIO Forum on Sunday.

Mitnick, who penetrated the networks of companies such as Sun Microsystems, Nokia and Motorola during the '80s and '90s and spent five years in prison, now works as a white-hat security consultant. With a series of amusing but sobering demonstrations, he showed just how easy it is for cybercriminals to take advantage of human error to create near-endless opportunities for data breaches.

Shrewd hackers don't have to be technology savants. They can make use of social engineering – manipulation, deception, trust-building – to trick unsuspecting users. And it's much "easier than executing a technical exploit," said Mitnick.

Just ask John Podesta, chair of the 2016 Hillary Clinton campaign, whose trove of emails was accessed thanks to a spear phishing attack and subsequently posted to Wikileaks. You're probably familiar with the rest of the story.

With a series of live demos, Mitnick showed how laughably easy it is to trick people into inserting trojan-infected USB drives into their computers and enable a remote hacker to gain access to operating systems and webcams. He also showed how unsuspecting employees can be duped into joining spoofed wireless networks, which enable large-scale credential harvesting; and how hackers can "weaponize" fake software updates to gain free reign over a system, undetected.

Back in his black-hat days, Mitnick was able to get hold of source code from Motorola simply by calling an 800 number and using some tech-jargony sweet talk to convince a security staffer there to transfer it to a separate server. That type of employee trust – that susceptibility to a well-played confidence game – can be just as dangerous as any brute force attack.

He said it was key for healthcare organizations to shore up their defenses by developing social engineering resistance training programs and performing penetration tests to discover which employees might be most likely to take the bait, helping build a "human firewall" by educating employees about the dangers of too much trust or too little vigilance.

Mitnick's keynote came just as a new survey was published on Feb. 19 by CHIME and KLAS, revealing findings that CHIME CEO Russell Branzell called "stark and concerning." Just 42 percent of the healthcare organizations polled have a vice president or C-level official in charge of cybersecurity, it found; only 62 percent discuss security at quarterly board meetings.

And only 16 percent of the providers surveyed (primarily large hospitals and integrated delivery networks) say they have "fully functional" security programs in place, according to CHIME.

Essential to the success of any such program is to focus as much on social engineering as much as technology protections, said Mitnick: "The human factor is the weakest link."

Read this cool event review and other articles [here](http://www.healthcareitnews.com/news/hacker-kevin-mitnick-dangers-human-factors-health-data-security).

Source: [Healthcare IT News](http://http://www.healthcareitnews.com/news/hacker-kevin-mitnick-dangers-human-factors-health-data-security)

# Related Resources

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Screen%20Shot%202020-08-14%20at%203.48.55%20PM.png?width=350&name=Screen%20Shot%202020-08-14%20at%203.48.55%20PM.png)

by Mitnick Security  | 08.16.2019  | 1 min

#### Advice from Kevin Mitnick Featured in the Wall Street Journal Op-Ed

Kevin Mitnick was interviewed by Mr. Maniloff who is an attorney at White and Williams LLP in Philadelphia and an adjunct professor at Temple University’s Beasley School of Law.

 Continue Reading

Knowbe4, Cybercrime, Kevin Mitnick, Wsj, Op-ed 

](https://www.mitnicksecurity.com/in-the-news/advice-from-kevin-mitnick-featured-in-the-wall-street-journal-op-ed)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Images/Events/In%20The%20News/kevin-ku-w7ZyuGYNpRQ-unsplash.jpg?width=350&name=kevin-ku-w7ZyuGYNpRQ-unsplash.jpg)

by Mitnick Security  | 12.12.2018  | 3 min

#### 12 Ways to Defeat Two-Factor Authentication

Everyone knows that two-factor authentication (2FA) is more secure than a simple login name and password, but too many people think that 2FA is a perfect, unhackable solution. It isn't!

 Continue Reading

Speaking Engagements, Tw-factor Authentication - Roger A. Grimes, Chief Hacking Officer, Data-driven Defense Evangelist, Security Awareness Training, Knowbe4, Simulated Phishing Platform, 2Fa Solution, Kevin Mitnick 

](https://www.mitnicksecurity.com/in-the-news/12-ways-to-defeat-two-factor-authentication)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Images/Events/In%20The%20News/simon-abrams-k_T9Zj3SE8k-unsplash.jpg?width=350&name=simon-abrams-k_T9Zj3SE8k-unsplash.jpg)

by Mitnick Security  | 11.26.2018  | 1 min

#### We Need to Talk About NIST’s Dropped Password Management Recommendations

Passwords and their protection are among the most fundamental, essential aspects of enterprise data security. They also make up the bane of most users’ relationships with their enterprise devices, res...

 Continue Reading

Speaking Engagements, 2Fa, Biometric Security, Two-factor Authentication, Fraud Prevention, Password, Password Management, Kevin Mitnick Security Awareness Training, Multifactor Authentication (Mfa, Password Reuse, Kevin Mitnick 

](https://www.mitnicksecurity.com/in-the-news/we-need-to-talk-about-nists-dropped-password-management-recommendations)