Smoking ban "a back door" for hackers
Security company warns that workplace smoking ban provides opportunities for social engineering attacks.


Letting your employees have a sneaky fag outside the building could let hackers sneak in, according to security experts.
As a total ban on smoking in the workplace fast approaches, one company warned that this could literally provide a back door for hackers to gain access to corporate networks.
Tests carried out by penetration testing company NTA Monitor, found that some of its testers were able to gain access to a company network literally through a back door as they spotted workers crowded outside the rear of an office having a cigarette.
The tester simply walked through the door and then asked an employee to take them to a meeting room claiming that the IT department had sent them there. According to the company, the person had not got a pass and was easily able to connect his laptop to a VoIP network through a telephone point.
"It used to be that companies 'left the back door open' in terms of internet security, now they are literally leaving their buildings open to accommodate smokers," said Roy Hills, technical director at NTA Monitor. "We are experiencing a surge in demand for social engineering tests as hackers are turning to social techniques to infiltrate corporate networks."
Hills said that this social engineering test proved that once inside a corporate building, an attacker can use social methods on employees to gain access to restricted areas and information if a rigid staff pass system is not in place.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Using DeepSeek at work is like ‘printing out and handing over your confidential information’
News Thinking of using DeepSeek at work? Think again. Cybersecurity experts have warned you're putting your enterprise at huge risk.
-
Can cyber group takedowns last?
ITPro Podcast Threat groups can recover from website takeovers or rebrand for new activity – but each successful sting provides researchers with valuable data