22/07/2026
🚨 The Threat Isn't Always Behind a Screen — It Could Be Standing Right Beside You.
Cybersecurity කියන්නේ Strong Passwords, Firewalls, Antivirus Software සහ MFA ගැන විතරක්ද?
ඇත්තටම නැහැ.
සමහර වෙලාවට attacker කෙනෙකුට ඔබේ software එකේ vulnerability එකක් exploit කරන්නවත් අවශ්ය නැහැ.
ඔවුන්ට අවශ්ය වන්නේ මිනිස් හැසිරීම (Human Behavior) exploit කිරීම විතරයි.
Text message එකකින්, phone call එකකින්, fake email එකකින්, හෝ සරල conversation එකකින් පවා attack එකක් ආරම්භ වෙන්න පුළුවන්.
ඒ වගේම, authorized employee කෙනෙක් පිටුපසින් restricted area එකකට ඇතුළු වීම වැනි Physical Security සම්බන්ධ දුර්වලතා හරහාත් ආරක්ෂාව බිඳ වැටෙන්න පුළුවන්.
අපි බලමු හැමෝම දැනගෙන සිටිය යුතු Physical සහ Digital Threat Vectors 10ක් ගැන. 👇
📱 1. Smishing
SMS + Phishing = Smishing
Attacker කෙනෙක් ඔබට fake SMS එකක් එවනවා.
ඒක bank එකකින්, delivery service එකකින්, government organization එකකින් හෝ ඔබ දන්නා service එකකින් ආවා වගේ පෙනෙන්න පුළුවන්.
ඉලක්කය?
🔹 Malicious link එකක් click කරවීම
🔹 Login credentials ලබාගැනීම
🔹 Personal information ලබාගැනීම
🔹 Malware download කරවීම
👉 Red Flag: "දැන්ම ක්රියා කරන්න", "Account එක block වෙනවා", "Prize එකක් දිනාගත්තා" වගේ urgent messages ගැන සැලකිලිමත් වෙන්න.
🎯 2. Spear Phishing
සාමාන්ය Phishing attack එකකට වඩා Spear Phishing කියන්නේ highly targeted attack එකක්.
Attacker කෙනෙක් target කරන පුද්ගලයා ගැන කලින් research කරලා, ඔහුට හෝ ඇයට ගැලපෙන විදිහට convincing message එකක් හදනවා.
ඒක ඔබේ Manager, Colleague, Customer කෙනෙක් හෝ ඔබ විශ්වාස කරන organization එකකින් ආවා වගේ පෙනෙන්න පුළුවන්.
👉 Red Flag: Message එක legitimate වගේ පෙනුණත්, unusual request එකක් තියෙනවා නම් Verify first.
🗑️ 3. Dumpster Diving
ඔබට අවශ්ය නැති document එකක් කුණු කූඩයට දැම්මා කියලා ඒක automatically secure වෙන්නේ නැහැ.
Attackers විසින් discarded documents, notes, labels, storage devices වගේ දේවල් සොයාගෙන sensitive information එකතු කරන්න පුළුවන්.
👉 Lesson: "Deleted" කියන්නේ හැමවිටම "Secure" කියන එක නෙවෙයි.
Sensitive documents properly shred කරන්න. Storage devices dispose කරන විටත් secure data destruction procedures follow කරන්න.
☎️ 4. Vishing
Voice + Phishing = Vishing
මෙහිදී attacker කෙනෙක් phone call එකක් හරහා trusted person කෙනෙක් හෝ organization එකක් ලෙස පෙනී සිටිනවා.
ඔවුන් Bank Officer කෙනෙක්, IT Support කෙනෙක්, Police Officer කෙනෙක් හෝ ඔබේ organization එකේ employee කෙනෙක් ලෙස පෙනී සිටිය හැකියි.
👉 Red Flag: Confidential information, OTP, Password හෝ වෙනත් sensitive details ඉල්ලන phone calls ගැන විශේෂයෙන් සැලකිලිමත් වෙන්න.
මතක තියාගන්න: OTP එකක් කිසිම කෙනෙකුට share කරන්න එපා.
💧 5. Watering Hole
මේක ටිකක් වෙනස් ආකාරයේ attack එකක්.
Attackers විසින් ඔවුන් target කරන victims ලා නිතර visit කරන websites compromise කරනවා.
ඒ කියන්නේ victim ව direct attack කරනවා වෙනුවට, victim විශ්වාස කරන digital destination එකක් attack කරනවා.
👉 Lesson: අපි නිතර භාවිතා කරන website එකක් වුණත්, security ගැන අවධානයෙන් සිටීම වැදගත්.
👀 6. Shoulder Surfing
Attacker කෙනෙකුට malware හෝ hacking tools අවශ්යම නැහැ.
සමහර වෙලාවට ඔබ Password එකක් type කරන විදිහ, PIN එකක් enter කරන විදිහ හෝ sensitive information එකක් screen එකක බලන විදිහ observe කිරීමෙන්ම information ලබාගන්න පුළුවන්.
Public places, airports, cafés, offices වගේ තැන්වලදී මේ අවදානම වැඩියි.
👉 Lesson: ඔබේ screen එක සහ keyboard එක අවට සිටින අයට පෙනෙනවාද කියලා සැලකිලිමත් වෙන්න.
🐋 7. Whaling
Whaling කියන්නේ සාමාන්යයෙන් executives, senior managers සහ high-value individuals වැනි ඉහළ මට්ටමේ පුද්ගලයන් target කරන highly targeted phishing attack එකක්.
මෙවැනි accounts වලට වැඩි privileges සහ authority තිබෙන නිසා, එක account එකක් compromise වීමෙන් organization එකකට විශාල බලපෑමක් ඇතිවෙන්න පුළුවන්.
👉 Lesson: Higher privilege = Higher responsibility
විශේෂයෙන් financial transactions, sensitive data access සහ unusual requests සඳහා additional verification process එකක් තිබීම වැදගත්.
🎭 8. Pretexting
Pretexting කියන්නේ attacker කෙනෙක් believable story එකක් හදලා, victim ව manipulate කරලා information හෝ action එකක් ලබාගැනීමට උත්සාහ කිරීම.
Attacker කෙනෙක් IT Technician කෙනෙක්, Employee කෙනෙක්, Customer කෙනෙක් හෝ Supplier කෙනෙක් වගේ පෙනී සිටින්න පුළුවන්.
👉 Lesson: Convincing story එකක් කියනවා කියලා request එක automatically legitimate වෙන්නේ නැහැ.
Always verify the identity.
🚪 9. Tailgating
මේක Physical Security එකට සම්බන්ධ threat එකක්.
Unauthorized person කෙනෙක්, authorized person කෙනෙක් පිටුපසින් restricted area එකකට ඇතුළු වෙනවා.
සමහරවිට ඒක,
"Could you hold the door for me?"
වගේ ඉතාම සාමාන්ය request එකකින් පටන් ගන්න පුළුවන්.
👉 Lesson: Access Control Systems තිබුණාට විතරක් Security එක සම්පූර්ණ වෙන්නේ නැහැ.
Security Procedures follow කිරීම හැමෝගෙම වගකීමක්.
🎧 10. Eavesdropping
Sensitive information එකක් leak වෙන්න computer එකක් හෝ network එකක් hack කරන්නම අවශ්ය නැහැ.
Confidential conversation එකක් public place එකකදී කෙනෙකුට ඇහෙන්න පුළුවන්.
Office එකක, café එකක, airport එකක හෝ elevator එකකදී කතා කරන sensitive information එකක් වෙනත් කෙනෙක් අහගෙන ඉන්න පුළුවන්.
👉 Lesson: Information Security කියන්නේ ඔබ store කරන දේවල් විතරක් නෙවෙයි — ඔබ කියන දේවල් ගැනත් අවධානයෙන් සිටීමයි.
🔐 අවසානයේ වැදගත්ම දේ...
මේ Threat Vectors 10 එකිනෙකට වෙනස් වුණත්, බොහෝ අවස්ථාවලදී ඒවා exploit කරන්නේ එකම දෙයක්.
TRUST — විශ්වාසය.
Attackers exploit කරන්නේ,
🔹 People
🔹 Technology
🔹 Organizations
🔹 Physical Spaces
🔹 Familiar Websites
🔹 Authority
🔹 Urgency
වගේ දේවල්.
ඒ නිසා Cybersecurity කියන්නේ technology එකකින් විතරක් විසඳන්න පුළුවන් දෙයක් නෙවෙයි.
අපි හැමෝටම තියෙන්න ඕනේ:
Awareness + Verification + Good Security Habits
Click කරන්න කලින්... STOP.
Information share කරන්න කලින්... THINK.
Unknown person කෙනෙක් trust කරන්න කලින්... VERIFY.
Door එක open කරන්න කලින්... CHECK.
🛡️ මතක තියාගන්න:
Cybersecurity වල weakest link එක හැමවිටම technology එක නෙවෙයි.
සමහර වෙලාවට අපි ප්රශ්න නොකර විශ්වාස කරන ඒ මොහොත තමයි attacker කෙනෙකුට අවශ්යම අවස්ථාව.
💬 මේ Threat Vectors 10 අතරින් ඔබට හිතෙන විදිහට වැඩිපුරම underestimate කරන threat එක මොකක්ද?
👇 Comment එකකින් අපිත් එක්ක share කරන්න.
📌 මේ Post එක Save කරගන්න.
📤 ඔබේ Friends, Colleagues සහ Team Members සමඟ Share කරන්න.
Cybersecurity Awareness එක හැමෝගෙම වගකීමක්.
🔵 NextGenCircuit
Tech. Trends. Transformation.
------------------------------------------------------------------------------------------
Think cybersecurity is just about strong passwords, firewalls, antivirus software, and MFA?
Think again.
Attackers don't always need to exploit a vulnerability in your software. Sometimes, the vulnerability is human behavior.
A successful attack can begin with a text message, a phone call, a fake email, a conversation, or simply walking through a door behind an authorized employee.
Here are 10 physical and digital threat vectors everyone should understand 👇
📱 1. Smishing
SMS + Phishing = Smishing
Attackers send deceptive text messages designed to trick victims into clicking malicious links, revealing credentials, or sharing sensitive information.
👉 Red flag: Unexpected messages demanding urgent action.
🎯 2. Spear Phishing
Unlike generic phishing, spear phishing is highly targeted.
The attacker researches the victim and creates a convincing message that appears to come from a trusted colleague, manager, customer, or organization.
👉 Red flag: A personalized request that seems legitimate—but asks for something unusual.
🗑️ 3. Dumpster Diving
Sometimes, sensitive information doesn't disappear when you throw it away.
Attackers may search discarded documents, notes, labels, or storage devices for information that can help them launch an attack.
👉 Lesson: "Deleted" doesn't always mean "secure."
☎️ 4. Vishing
Voice + Phishing = Vishing
An attacker uses a phone call or voice communication to impersonate a trusted person or organization.
👉 Red flag: Someone pressuring you to reveal confidential information or bypass normal procedures.
💧 5. Watering Hole
Attackers compromise websites that their intended victims are likely to visit.
Instead of attacking the victim directly, they target a trusted digital destination.
👉 Lesson: Even familiar websites can become part of an attack chain.
👀 6. Shoulder Surfing
Sometimes an attacker doesn't need malware.
They simply observe someone entering a password, PIN, or sensitive information on a screen.
👉 Lesson: Be aware of who can see your screen in public and shared spaces.
🐋 7. Whaling
Whaling is a form of targeted phishing aimed at high-value individuals, such as executives or senior decision-makers.
Because these accounts often have significant authority, a successful attack can have serious consequences.
👉 Lesson: The higher the privilege, the greater the need for verification.
🎭 8. Pretexting
The attacker creates a believable story—or pretext—to manipulate someone into providing information or taking an action.
The attacker may pretend to be an employee, IT technician, customer, supplier, or other trusted party.
👉 Lesson: A convincing story doesn't automatically make a request legitimate.
🚪 9. Tailgating
An unauthorized person follows an authorized individual into a restricted physical area.
It can be as simple as someone asking, "Could you hold the door?"
👉 Lesson: Physical access controls are only effective when people follow them.
🎧 10. Eavesdropping
Sensitive information can be overheard in conversations, meetings, phone calls, or public places.
A confidential conversation in a café, airport, elevator, or open office could unintentionally expose valuable information.
👉 Lesson: Information security includes what you say—not just what you store.
🔐 The Big Picture
These threats may look different, but they often share one common target:
TRUST.
Attackers exploit trust in:
🔹 People
🔹 Technology
🔹 Organizations
🔹 Physical spaces
🔹 Familiar websites
🔹 Authority
🔹 Urgency
The most effective defense is not just technology.
It's awareness + verification + good security habits.
Before clicking.
Before sharing.
Before opening the door.
Before trusting the caller.
STOP. THINK. VERIFY.
Because in cybersecurity, the weakest link isn't always the device—sometimes it's the moment we stop questioning.
💬 Which of these 10 threat vectors do you think is the most underestimated?
Drop your answer in the comments 👇
📌 Save this post for future reference.
📤 Share it with your team—because cybersecurity awareness is everyone's responsibility.
NextGenCircuit | Tech. Trends. Transformation.