Security News

Cybersecurity news aggregator

INFO News Dark Reading

Sherlock Holmes was the “OG” Social Engineer

  • What: Sherlock Holmes is highlighted as an early example of social engineering
  • Impact: Historical perspective on cybersecurity tactics
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security Outdated Cybercrime Laws Put Security Researchers at Risk Outdated Cybercrime Laws Put Security Researchers at Risk by Arielle Waldman Aug 10, 2026 5 Min Read Sponsored Content Traditional Firewalls Can't Secure AI. This Can. Traditional Firewalls Can't Secure AI. This Can. Aug 10, 2026 4 Min Read World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Sherlock Holmes was the “OG” Social Engineer The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers. Arielle Waldman , Features Writer , Dark Reading August 10, 2026 3 Min Read Source: Lorado via Getty Images With a green deerstalker cap, a blue and green plaid shawl covering her shoulders and a pipe resting in her right hand right below her mouth, it was almost impossible to tell the difference between Sherlock Holmes and Elizabeth Rasnick. But that was the point— social engineering is all about deception. Holmes was the original social engineer, argued Resnick, assistant professor at the University of West Florida's Center for Cybersecurity and Artificial Intelligence (AI). During DEF CON 34, she drew parallels between current social engineering techniques and Holmes's own playbook as described in the detective tales. Her session highlighted how important it is for organizations to continually prioritize the human element when it comes to social engineering and security awareness training, despite how difficult that's proved historically. Social engineering tactics used to trick users into handing over sensitive information have evolved dramatically with technology. And while AI has enabled threat actors to craft more realistic phishing emails and to scale their attacks, the underlying psychology behind them remains the same: Fear and curiosity still drive human behavior. Related: More Countries Jump on the Social Media 'Ban Wagon' Trust is the "real attack surface," Rasnick said. “Predictable behavior is what makes social engineering possible," she added. Same Playbook, Different Year Threat actors all pull from the same social engineering playbook. They exploit user trust, create a sense of urgency, take advantage of human curiosity, and deploy distraction tactics. That mirrors Holmes playbook: know the target, become believable, create a reason to act, exploit emotion, observe behavior, and adapt, explains Rasnick. Threat actors' idea of impersonation today extends as far as using realistic deepfake videos to trick targets. In the detective tales, Holmes also took drastic measures and actually got engaged to a housemaid to collect information while under disguise, she explained. During the “Know the target” stage, threat actors utilize open-source Intelligence, like scanning social media for details on where someone works. Information gathered before an attack determines how successful a social engineering campaign is, she said. Once information is gathered, threat actors create a reason for their target to act. Manipulation tactics really play up emotion, making targets sad or scared, or offering the potential for an exciting opportunity. "We know how people are going to react, and we plan for the reaction," she said. "That's what it’s all about." Related: Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Rasnick also compared "Sherlock Holmes: The Red-Headed League," a story where an organization pretends to be real, to current fake job posting scams where threat actors send phishing links to applicants once they’ve lured them into the trap. Social engineering “didn't start with the internet," she said. "I know it feels like it." Holmes vs Moriarty, or Blue Hat vs Red Hat? Rasnick went on to compare Holmes and his fictional archnemesis, James Moriarty, to modern day defensive and offensive security professionals, demonstrating the fine line between ethical hackers and cybercriminals. In true professor fashion, Rasnick began the talk with a three-question “Is it Sherlock or is it Moriarty?” quiz. Everyone guessed wrong; Holmes did it all, from reconnaissance to manipulation. His Victorian villain counterpart, in this instance, was innocent. She went on to explain how Holmes was essentially a modern-day penetration tester . Clients hired him to solve mysteries, and he drew from a six-rule playbook to achieve results. He conducted reconnaissance, built trust, created distractions, instilled urgency, analyzed reactions, and adapted his tactics when necessary. But it was all done by the book. Moriarity, on the other hand, was a criminal, acting with nefarious intent. He even ran a secret criminal syndicate. Related: He Thought He Was Secure; His Phone Number Was Stolen Anyway Ethical and non-ethical hackers are all using the same techniques, she said. While teaching ethical hacking to her students, she explains that the difference is paperwork. Blue hats hired to test systems draw up contracts and submit reports at the end of their engagement. Non-ethical hackers don't have to worry about that. "Does it make it better when Holmes does it?" Rasnick posed "The difference is intent and whether you have legitimacy.” About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. See more from Arielle Waldman Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos More Webinars Edge Picks Application Security AI Agents in Browsers Light on Cybersecurity, Bypass Controls AI Agents in Browsers Light on Cybersecurity, Bypass Controls Cyber Risk Browser Extensions Pose Heightened, but Manageable, Security Risks Browser Extensions Pose Heightened, but Manageable, Security Risks Latest Articles in The Edge Cybersecurity Operations From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture Aug 6, 2026 | 4 Min Read Data Privacy DROP Platform Lets Californians Reduce Digital Footprint Jul 31, 2026 | 5 Min Read Cybersecurity Operations Claude Mythos — Hype vs. Reality: What Security Teams Need to Know Jul 30, 2026 Cyberattacks & Data Breaches Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions Jul 29, 2026 Read More The Edge Want more Dark Reading stories in your Google search results? Black Hat Asia | Marina Bay Sands, Singapore Experience cutting-edge cybersecurity insights in this four-day event. Use code DARKREADING for a Free Business Pass or $200 off a Briefings Pass. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us Newsletter Sign-Up Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home | Cookie Policy | Privacy | Terms of Use Your Privacy Choices

Share this article