Sherlock Holmes was the “OG” Social Engineer

Sherlock Holmes: The Original Social Engineer

In a fascinating display of how timeless social engineering techniques remain, Professor Elizabeth Rasnick has drawn parallels between the fictional detective Sherlock Holmes and modern-day tactics used by threat actors. Her session at DEF CON 34 highlighted the importance of prioritizing human element security awareness training in organizations.

Holmes’s playbook is essentially the same as that used by today’s threat actors: know the target, become believable, create a reason to act, exploit emotion, observe behavior, and adapt. This may seem like an outdated concept, but Rasnick emphasized that “social engineering didn’t start with the internet.” The underlying psychology behind these tactics remains the same – fear and curiosity drive human behavior.

Threat actors exploit user trust, creating a sense of urgency and taking advantage of human curiosity through distraction tactics. They use open-source intelligence to gather information about their targets, often scanning social media for details on where someone works. Once gathered, this intel is used to create a reason for the target to act, leveraging manipulation tactics that play up emotions.

Rasnick compared Holmes’s “Know the Target” stage to current threat actors’ methods of gathering information through open-source intelligence. This information determines how successful a social engineering campaign will be. She also pointed out that modern-day tactics such as fake job posting scams – where threat actors send phishing links to applicants – are reminiscent of Holmes’s story, “Sherlock Holmes: The Red-Headed League,” in which an organization pretends to be real.

Rasnick went on to compare the line between ethical hackers and cybercriminals, drawing a parallel with the fictional characters of Sherlock Holmes and James Moriarty. While Holmes was a skilled penetration tester who used his six-rule playbook to achieve results within the bounds of the law, Moriarty acted with nefarious intent as the head of a secret criminal syndicate.

The session served as a reminder that social engineering tactics have evolved but remain rooted in human psychology. As Rasnick noted, “predictable behavior is what makes social engineering possible.” This highlights the importance of continually prioritizing security awareness training and education for organizations to mitigate the risks associated with these tactics.

In conclusion, the session at DEF CON 34 underscored the timeless relevance of social engineering techniques, emphasizing that organizations must adapt their approach to address this evolving threat. By understanding the psychology behind these tactics and recognizing the parallels between Holmes’s playbook and modern-day threat actor methods, we can better prepare ourselves for the challenges ahead.

Practical takeaway: Organizations should continually prioritize security awareness training, focusing on the human element of social engineering tactics. This includes educating employees about recognizing red flags in phishing attempts, being cautious when sharing personal information online, and reporting suspicious behavior to prevent potential attacks.


Source: Dark Reading — 2026-08-10