🟠 High  |  Source: The Register — Security


A man gained unauthorised access to private medical records by using social engineering — specifically, talking disparagingly about a doctor to manipulate staff into granting him entry to a records room. No technical exploit or stolen credentials were required; human trust was the vulnerability. This incident highlights how physical and social engineering attacks remain a significant threat to sensitive data, even where digital security controls exist.

Security Architect’s Take: Review whether your organisation’s physical access controls and staff security awareness training account for social engineering scenarios, particularly in environments handling sensitive data. Ensure that verbal authorisation alone cannot grant access to records or systems — all access should require verifiable, auditable authentication regardless of how convincing the requester appears.

Original advisory: Talking smack about a doctor got him access to private medical files