The Age-Old Art of Social Engineering: Lessons from Sherlock Holmes’ Playbook
Sherlock Holmes, the iconic detective created by Sir Arthur Conan Doyle, was long before his time. But what if we told you that this fictional character’s techniques are still being used today? In a fascinating session at DEF CON 34, University of West Florida’s Center for Cybersecurity and Artificial Intelligence (AI) assistant professor Elizabeth Rasnick drew parallels between current social engineering tactics and Holmes’ own playbook.
Rasnick argued that Holmes was the original social engineer, using deception to gather information and solve mysteries. She highlighted how important it is for organizations to prioritize human element security awareness training, despite the challenges in doing so historically. Social engineering tactics have evolved dramatically with technology, but the underlying psychology remains the same: exploiting fear and curiosity.
Threat actors today use various techniques to trick users into handing over sensitive information. They exploit user trust, create a sense of urgency, take advantage of human curiosity, and deploy distraction tactics. This mirrors Holmes’ playbook, which involved knowing the target, becoming believable, creating a reason to act, exploiting emotion, observing behavior, and adapting.
Rasnick pointed out that threat actors use real-life examples to gain trust. They utilize open-source Intelligence, like scanning social media for details on where someone works. Information gathered before an attack determines how successful a social engineering campaign is. Once information is gathered, threat actors create a reason for their target to act, often manipulating emotions to achieve their goal.
This technique of using manipulation tactics to play up emotion is nothing new. Holmes used similar tactics in his detective tales, creating distractions and instilling urgency to solve cases. Rasnick compared “Sherlock Holmes: The Red-Headed League” story to current fake job posting scams where threat actors send phishing links to applicants once they’ve lured them into the trap.
The fine line between ethical hackers and cybercriminals is also explored in this session, with Rasnick comparing Holmes and his fictional archnemesis, James Moriarty. In true professor fashion, she began the talk with a three-question “Is it Sherlock or is it Moriarty?” quiz, highlighting how difficult it can be to distinguish between good and bad intentions.
The takeaway from this session is that social engineering didn’t start with the internet; it’s been around for centuries. Holmes was essentially a modern-day penetration tester, using a six-rule playbook to achieve results. He conducted reconnaissance, built trust, created distractions, instilled urgency, analyzed reactions, and adapted his tactics when necessary.
For organizations, this means continually prioritizing human element security awareness training. By understanding the psychology behind social engineering attacks, we can better prepare ourselves for the threats that lurk online. Remember, trust is the real attack surface, and predictable behavior makes social engineering possible. So, what can you do to protect yourself? Stay vigilant, be aware of your surroundings (both physical and digital), and never click on suspicious links or download attachments from unknown sources. Only time will tell if we can outsmart the modern-day Moriartys lurking in the shadows.
Source: Dark Reading — 2026-08-10