Your Interns, Your New Hires and Even Your TA Teams Are Putting Your Company at Risk


As human resources teams onboard their summer interns, they’ll notice that many are eager to celebrate their first day by sharing photos online. It may even be tempting for social media teams to post a picture on the company’s social media pages to officially welcome the new interns. But before posting that #CompanyName, #WorkLife, or #FirstDayofWork photo, consider the security risks that might pose for your company.
When an intern posts a photo of their desk or company badge or streams a “day in the life” video, sensitive information is often inadvertently revealed and can be used by hackers to cause harm to an organization. Using these social media posts, these hackers may find passwords on sticky notes, software systems on desktop screens and other confidential company data lurking in the background that helps them plan their attacks. They can also replicate security badges to walk into companies, unchallenged, and obtain access to valuable information. I would know — I’m a hacker myself. The difference is, the “victim” company has hired me to do it.
In my role as “Chief People Hacker” for IBM X-Force Red, companies hire us to test their security. I spend my days discovering information about our target via research, and often, using that information to break into their office space. Social media is my first stop for finding information that can help get me through the doors of a company.
Interns’ social media accounts are a goldmine of intelligence as I prepare for an attack. In fact, around 75% of the sensitive information I find on social media comes from interns or new hires. Generation Z’s tendency to overshare online combined with lax security training during internship onboarding is a recipe for disaster when it comes to security and business risks. Fortunately, once you understand what these risks are, there are simple steps you can take to prevent them.
Gen Z is the most avid generation of social media users to enter the workforce to date. Among those who are between the ages of 18 and 24, 75% use Instagram, 73% use Snapchat, 76% use Facebook and 90% use YouTube, according to Pew Research. Introducing this group of users to their first workplace experience without social media security guidelines is a huge risk that most companies are not considering.
However, interns aren’t the only target for hackers looking to steal this information. New full-time hires pose a risk as well. For companies that don’t include social media security awareness training as part of new hire onboarding, these employees may never be trained on proper social media use. Excited about their first day, they’ll often post a hash-tagged selfie or show off their new desk in a post without realizing that sensitive company information may be in the background.
It’s also too easy for HR and social media teams themselves to put the organization at risk by posting photos and videos that expose sensitive content as they showcase all the fun things that make their workspaces and programs look exciting and alluring to attract new talent.
For example, take the case of a “day in the life” video I recently saw posted by an organization’s social media team. They followed one intern with a camera from the start of their day to the end. In the first scene, our team went frame by frame until we found one that showed the intern logging into their laptop at their cubicle. A sticky note was stuck to the laptop with that intern’s new password. This seemingly friendly video contained content that could be used to compromise the organization’s security.
Security awareness programs are generally not the most exciting part of a new job. As a result, this part of the onboarding process is often rushed or forgotten altogether. Even in the most thorough security training, it’s easy to gloss over social media habits to focus on issues like password strength and phishing emails.
Here are a few takeaways to ensure that your interns, new hires and even longtime employees don’t let their enthusiasm for social media expose content that could help a hacker in their quest to infiltrate a company:
While social networks are a great way to attract new talent and promote personal success, they are also the perfect place for adversaries to look up information and create risks for organizations. Fortunately, by implementing a few simple rules for HR teams, new hires and especially Gen Z interns, these platforms can still safely be used by those who are eager to share.