Social Engineering Attackes
Social Engineering Attackes
This is opportunity to express my heartfelt words for the people who were
part of this seminar in numerous ways, people who gave me unending
support right from beginning of the seminar.
I want to give sincere thanks to the principal Dr. Rekha Mehra for her
valuable support.
I extend my thanks to Dr. Jyoti Gajrani Head of the Department for his
constant support.
I express my deep sense of gratitude for continuous cooperation
encouragement towards my guide Dr. Deepak Gupta.
Chitransh Bhatnagar
22EEACY016
ABSTRACT
This is to certify that the Seminar Report entitled "Social Engineering Attacks"
has been submitted by "Chitransh Bhatnagar" in partial in fulfillment for the
requirement of the degree of [Link] in Computer Science & Engineering
(Cyber Security) for the academic Session 2025-2026.
He has undergone the requisite work as prescribed by Bikaner Technical
University, Bikaner (Rajasthan).
Place:
Date : 11/03/26
Table of Contents
1. Introduction .............................................................................................................. 1
1.5.1 Computer-Based............................................................................................... 4
2. Purpose .................................................................................................................... 9
3. Method ................................................................................................................... 10
4. Results.................................................................................................................... 13
5. Discussion .............................................................................................................. 16
6. Conclusion ............................................................................................................. 20
References...................................................................................................................... 21
List of Tables
Table 1. Key Concept. …………………………………………………………..…
Table 2. Human-based attack techniques ............................................................. 6
Table 3. Search strategy for literature review ..................................................... 10
Table 4. Overview of results from literature study ............................................. 13
Table 5. Comparison between sources that propose a framework ........................ 15
List of Figures
Figure 1. Flowchart for article selection strategy for literature review ................. 12
Key Concepts
Table 1. Key concepts.
Term Description
Baiting is a trick where the attacker leaves
physical or digital bait in a common area, to lure
a victim into picking it up out of curiosity. The
Baiting bait contains malicious software or virus to
compromise the victim’s device (Chetioui et al.,
2022).
In 2017, a data breach dating back to 2014 exposed all three billion Yahoo user
accounts. The attackers gained access through a spear-phishing attack,
compromising employee logins and infiltrating Yahoo's network. This breach
resulted in unauthorized access to sensitive information such as names, email
addresses, phone numbers, birthdates, encrypted passwords, and
encrypted/unencrypted security questions (Williams, 2017).
The Yahoo data breach highlights the need for robust protection against social
engineering attacks, which exploits human vulnerabilities through psychological
manipulation and deception (Aldawood & Skinner, 2019). It showed the severe
consequences of insufficient vigilance, compromising the sensitive data of
millions of users. This serves as an introduction to our bachelor thesis on The
Human Element of Cybersecurity: A Literature Review of Social Engineering
Attacks and Countermeasures, emphasizing the importance of social engineering
awareness programs and strong security measures.
1
1.1. The Impact of a Social Engineering Attack against an
Organization
The article "The Sony hacker indictment: 5 lessons for IT security" by Strom
(2018) describes how the FBI identified the North Korean hackers responsible for
the 2014 Sony Pictures hack. The attackers used a combination of spear-phishing
emails, malware, and other targeted elements to penetrate Sony's network. The
malware had thousands of hard-coded host names that suggested the hackers had
conducted extensive reconnaissance before the attack. The consequences of the
attack were significant, with Sony losing millions of dollars in revenue and facing
legal and regulatory challenges, while thousands of employees' personal
information was stolen. The North Korean hackers also targeted other
organizations, including banks and US corporations, using similar tactics. The
FBI's analysis of the malware used in the Sony hack and other attacks also
revealed links to the WannaCry ransomware attacks (Strom, 2018).
Despite the use of high-security defense systems, such as firewalls and secure file
transfers, the human element is still the cause of vulnerabilities for attacks (Ghafir
et al., 2016). Social engineering is a type of hacking attack that involves
manipulating the weakest link in an information system, which is often human
behavior, to gain unauthorized access to data or to profit financially. Social
engineering attacks can compromise the confidentiality, integrity, and availability
of data, either directly or indirectly. Examples of human behavior that social
engineering attacks exploit include authority, reciprocation, moral duty, and
overloading (Mann, 2008; Mohammed & Apeh, 2016).
According to Shlyakhtunov (2021), the three most common types of hackers are
white, gray, and black hats. White hat hackers, also known as ethical hackers,
work for the good guys and use their skills to find vulnerabilities and improve
security. They are often employed by large software corporations, the military, and
other organizations to test their security systems and find weaknesses. They may
2
earn significant sums of money from "bug bounties" for finding and reporting
vulnerabilities.
Gray hat hackers operate in a legal gray area, exposing vulnerabilities in systems
without permission from their owners. They may request a fee for not disclosing
the vulnerability and may publicly disclose it if the organization does not fix the
problem quickly enough (Shlyakhtunov, 2021).
Black hat hackers are the most malicious type of hacker. They use their skills to
gain unauthorized access to systems, steal data, and cause damage. They may do
this for financial gain, political or ideological reasons, or simply for the thrill of it.
Their activities are illegal and can cause significant harm to individuals and
organizations alike (Shlyakhtunov, 2021).
3
is part of the plan, which includes the necessary steps, resources, and timeline to
execute the attack successfully. The choice of plan and technique are crucial in
determining the success of the attack, as it relies heavily on the ability to exploit
the target's trust and reveal sensitive information (Algarni et al., 2013; Ghafir et
al., 2016).
Ghafir et al. (2016) describes that social engineering techniques can be divided
into two main categories: attacks that rely on physical locations (computer-based
attacks) and attacks that use psychological manipulation (human-based attacks).
1.5.1 Computer-Based
4
methods include impersonation, tailgating, and masquerading. Once the attacker
gains access, they can exploit any weak security measures in place to obtain
sensitive information, passwords, or even access to the network (Ghafir et al.,
2016; Mann, 2008).
[Link] Telephone
Attackers commonly use social engineering through phones to gain access to
sensitive information from an organization by targeting its help desk or customer
care helplines. They pretend to be calling from within the organization, allowing
them to remain anonymous while obtaining valuable information (Ghafir et al.,
2016).
[Link] Online
Online attacks are carried out using a range of platforms, including social media,
instant messaging, and email. The attacker may trick the target into installing
malware, send personal information through phishing or obtain information
through web searches. Attackers may also use social engineering techniques in
social networks, such as reverse social engineering attacks that abuse features
provided by the platform to launch automated attacks. The attacker can attract
large numbers of legitimate users without actively sending any friend requests,
making these attacks a feasible threat in real life (Ghafir et al., 2016; Irani et al.,
2011).
1.5.2 Human-Based
5
Table 2. Human-based attack techniques.
Attack Description
This technique involves a social engineer
portraying themselves as an authority
figure to elicit compliance from the
target. The fear of punishment, if they
Authority undermine the authority figure's
legitimacy, can make the target more
vulnerable to this technique (Chantler &
Broadhurst, 2008; Ghafir et al., 2016).
6
their actions or invoking a sense of moral
duty (Chantler & Broadhurst, 2008).
7
persuasive axioms, triggers a
psychological response that causes them
to become mentally passive and absorb
information without evaluating it, leading
to compliance. This is achieved through a
time element and can be referred to as
overloading (Chantler & Broadhurst,
2008).
It is a technique to manipulate an
individual's decision-making abilities,
often in the context of phishing attacks.
This technique involves triggering strong
8
2. Purpose
The purpose of this thesis is to investigate the current state of research on social
engineering methods, along with how they are being used and how they can be
prevented. The paper should then be able to be used as a basis for organizations
designing their social engineering prevention framework or policies.
The following research questions have been formulated to achieve the purpose of
this thesis, which is to investigate:
9
3. Method
3.1. Literature Review
To develop our search strategy, we began with brainstorming search terms related
to our research question. Then test searches were conducted to get an overview of
the research situation and to verify if the search terms were relevant to our
research question. By refining our search strategy, we found relevant keywords
that aligned with our research question, including social engineering, employee
awareness, attacks, and policy. This formed the basis for deciding whether we
could obtain relevant results based on our search terms.
To obtain relevant results that align with our research questions and purpose, we
minimized irrelevant hits by using the keywords we had identified. By combining
these keywords using the "and" operator, we were able to conduct a more targeted
search. This was to obtain a more focused and informative set of results that were
most suitable for our research question. Since different databases have different
search methods, the search string was different between databases. The search
strategy is presented in Table 3.
10
To achieve a more reliable and semi-comprehensive analysis, the Preferred
Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) method
was used. PRISMA is a four-part process consisting of identification, screening,
eligibility, and inclusion. The PRISMA-flowchart is described in figure 1.
3.1.1. Identification
We summarized the number of search results from the two databases we used,
which each have their own unique collection of publications. Since we did not find
any duplicates across the databases, we did not need to remove any at this stage.
3.1.2. Screening
This means reading titles and abstracts. To ensure relevance to our literature
review, we conducted a thorough screening of article titles and abstracts based on
our chosen keywords. Specifically, we checked each article to decide if it had
relevant material related to keywords.
3.1.3. Eligibility
Here, the search results were filtered to show only results that had open access and
full texts that we have access to via Dalarna University's various subscriptions to
different databases. We included articles that supplied information on preventing
employees from being deceived by various types of social engineering attacks and
creating policies to prevent them. We excluded articles where the context was not
organizational or employee oriented.
3.1.4. Inclusion
After applying these inclusion and exclusion criteria, we were left with a total of 9
articles that contained valuable information related to our research topic. These
articles were considered eligible and were included in our systematic review.
11
Figure 1. Flowchart for article selection strategy for literature review.
Since a literature study does not involve any physical or psychological impact on
the research participants, it is considered ethically unproblematic.
12
4. Results
This study resulted in 13 included articles and two tables. Table 4 is an overview
of the included studies and their results according to seven categories. Each
category is clearly defined at the bottom of the table.
PF, Proposed framework or model for social engineering prevention; ETP, Proposed employee
training programs or initiatives related to social engineering; RA, Methods/tools used for assessing
the risk of social engineering attacks; CC, Building a cybersecurity culture to prevent social
engineering attacks; RWP, Adapting policies and procedures related to remote work and their
impact on social engineering; OS, Using OSINT for conducting risk assessments related to social
engineering; BS, BEC scams and their impact on organizations.
Lee (2021), Alghenaim et al. (2021), and Annarelli et al. (2020) all proposed
formal frameworks for preventing social engineering attacks. While they all had
unique approaches, there were several similarities between them. Lee (2021)
emphasized the importance of educating employees about social engineering
techniques, utilizing secure access control mechanisms, and implementing two-
factor authentication where possible. Similarly, Alghenaim et al. (2021) found that
employee awareness and training were crucial in detecting and reporting social
13
engineering attacks, and recommended implementing security awareness programs
as part of an organization’s security strategy.
Annarelli et al. (2020) had more of a holistic approach, focusing on four key
components: organizational culture, employee training, incident management, and
awareness-raising activities. Additionally, Aldawood and Skinner (2019),
Alshaikh (2020), Alghenaim et al. (2021), and Mansfield-Devine (2016) all
highlighted the need for conducting employee awareness training.
Aldawood and Skinner (2020) suggest that education and training programs should
aim to raise awareness among employees about the different types of social
engineering attacks, along with the tactics used by attackers, as well as the
consequences that follow when an attacker is successful in their attack. Other
studies, such as the one by Ling Li, Li Xu, and Wu He (2020), suggest that
simulated phishing exercises can be an effective way to train employees to
recognize and respond to phishing attacks. These involve sending fake phishing
emails to employees and analyzing their responses to identify areas where they
may need additional training. Aldawood and Skinner (2020) suggest a similar
approach, effectively simulating social engineering attack scenarios and having
employees practice responding to the attacks in a safe and controlled environment.
Table 5 provides an overview and comparison of the results from the sources that
proposed frameworks. All the sources agree on the importance of employee
awareness and training in preventing social engineering attacks.
14
Table 5. Comparison between sources that propose a formal framework or model.
Source Result
Found that employees with high levels of awareness and training were
Alghenaim et more likely to detect and report social engineering attacks. Highlights
al. (2021) the importance of employee awareness programs to help prevent those
attacks.
Lee (2021) and ways to prevent them. Use access control mechanisms and two-
factor authentication.
15
5. Discussion
The aim of this bachelor thesis was to provide a foundation for organizations that
design frameworks or policies to prevent social engineering, by examining the
current state of research on social engineering practices and their prevention. To
identify relevant articles, a search string based on the keywords was created, and a
literature review was conducted using the databases ScienceDirect and IEEE
Xplore, resulting in 13 articles.
The study sought to identify common social engineering attack methods, effective
ways to reduce employee susceptibility, and the need for awareness training. Table
4 gives an overview of the 13 articles, while table 5 compares the results from the
articles that formally present a framework and highlights the importance of
employee awareness in preventing social engineering attacks.
The report from Verizon (2022) that was mentioned in the introduction highlights
that 82 % of all breaches involve the human element, with social engineering
being the primary method. The report identifies phishing as the most used social
engineering attack, followed by pretexting. It suggests several effective ways to
reduce employee susceptibility, including employee awareness and training,
building a cybersecurity culture, using risk assessment methods or tools, adapting
policies for remote work, and using OSINT for risk assessments. Simulated
phishing exercises, gamification, and incident management were also identified as
effective training tools. The study highlights the need for employee awareness
training in the prevention of social engineering attacks. Various training methods
were proposed including simulated phishing exercises and interactive and
engaging training materials. Lastly, all sources that suggested a framework to
prevent social engineering attacks agreed on the significance of employee
awareness and education.
Overall, this study provides valuable insights into social engineering methods and
their prevention, which can be used by organizations to design effective prevention
frameworks and policies.
16
5.1. Contributions to the Field
According to the findings in the IBM Security (2023) X-Force Threat Intelligence
Index report of 2023, there was a significant decrease in spear-phishing links as
the infection vector targeting European organizations. In the report from the
previous year, with data from 2021, spear-phishing links accounted for a
substantial 42 % of the infection vectors, whereas in the year after, that number
dropped to 14 %. It is believed that this is a result from several different factors,
including improved user awareness, stronger email security defenses, and other
effective defense mechanisms capable of catching malware post-installation.
The report suggests that organizations are becoming increasingly aware and
knowledgeable about the risks associated with social engineering attacks and
indicates that they are doing more than before to educate their employees on
attacks and ways to prevent them from occurring. Subsequently, this may lead to
employees being more cautious when interacting with emails and attachments of
suspicious characters, reducing their susceptibility to becoming a victim in the first
place.
Additionally, the report indicates that organizations may have increased their email
security defenses that can detect and block phishing attempts more effectively.
Furthermore, it seems that improvements have been made when it comes to post-
malware detection and response. All these security advancements seem to indicate
that a holistic solution with multiple layers should be used to prevent social
engineering attacks most effectively in the organizational context.
17
5.3. Limitations
The literature review conducted in this bachelor thesis has several limitations.
Initially, the study relied on data that was collected from two databases, which
might not cover all available research regarding the subject. The limited sample
size may affect the extensiveness of the result.
The search strategy that was formed for this literature review was based on
brainstorming relevant search terms and through conducting test-searches. Despite
our efforts to enhance the search strategy there is a possibility that some relevant
articles could have been missed or excluded due to our chosen search term or
criteria.
Worth noting is that during our review a similar article published 2022 was
discovered. Although their topic had resemblance to our subject it was not
included in this review, because they used keywords that did not match our search
criteria.
Articles that did not have open access or were not available through Dalarna
University were filtered out from the review, to ensure that only relevant articles
with full text appeared in the results. It is possible that relevant articles were
excluded, as they did not match the search criteria.
Lastly, there is a possibility that new relevant literature has been published that we
have not been able to include in the review.
To ensure the reliability and validity of our research in this bachelor thesis, we
emphasized a strict and systematic review method for evaluation, specifically
PRISMA. By conducting this approach, we efficiently minimized the inclusion of
irrelevant findings, which enhanced the overall quality of our study.
18
5.5. Recommendations for Future Research
The findings of this study provide valuable insights that can be leveraged to dive
deeper into the subject in various ways. One area of focus for future research could
involve implementing certain social engineering prevention frameworks in specific
industries, such as in the banking sector or real estate sector. The studies could be
of longitudinal form, to track the retention of knowledge and changes in employee
behavior over a long period of time. This will enable a better understanding of
whether the measures proposed in the frameworks continue to deliver good results
in the long term. For this to work, the implemented frameworks would consistently
need to be updated and maintained, to be adapted to the most recent and current
social engineering threats.
19
6. Conclusion
This thesis has emphasized the escalating threat of social engineering attacks in
organizational settings. The Yahoo and Sony data breaches serve as epitomes for
the financial losses, legal challenges, stolen personal information, and many other
serious consequences that can result from one of these attacks.
20
References
Aldawood, H., & Skinner, G. (2019). Reviewing Cyber Security Social
Engineering Training and Awareness Programs-Pitfalls and Ongoing Issues.
Future Internet, 11(3), Article 73. [Link]
Algarni, A., Xu, Y., Taizan, C., & Yu-Chu, T. (2013). Social engineering in social
networking sites: Affect-based model. In 8th International Conference for Internet
Technology and Secured Transactions (ICITST-2013), December 9-12, 2013 (pp.
508-515). IEEE. [Link]
Annarelli, A., Nonino, F., & Palombi, G. (2020). Understanding the management
of cyber resilient systems. Computers & Industrial Engineering, 149, 106829.
[Link]
Chantler, N., & Broadhurst, R. (2008). Social engineering and crime prevention in
cyberspace. Proceedings of the Korean Institute of Criminology, 65-92.
[Link]
Chetioui, K., Bah, B., Alami, A. O., & Bahnasse, A. (2022). Overview of Social
Engineering Attacks on Social Networks. Procedia Computer Science, 198, 656-
661. [Link]
21
Ghafir, I., Prenosil, V., Alhejailan, A., & Hammoudeh, M. (2016). Social
engineering attack strategies and defense approaches. In 4th IEEE International
Conference on Future Internet of Things and Cloud (FiCloud), August 22-24,
2016, Vienna, Austria (pp. 147-151). IEEE.
[Link]
Hayes, D. R., & Cappa, F. (2018). Open-source intelligence for risk assessment.
Business Horizons, 61(5), 689-697. [Link]
Irani, D., Balduzzi, M., Balzarotti, D., Kirda, E., & Pu, C. (2011). Reverse social
engineering attacks in online social networks. In Detection of Intrusions and
Malware, and Vulnerability Assessment (pp. 55-74). Springer, Berlin, Heidelberg.
[Link]
Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social
engineering attacks. Journal of Information Security and Applications, 22, 113-
122. [Link]
Luo, W., Liu, J., Liu, J., & Fan, C. (2009). An analysis of security in social
networks. In 2009 Eighth IEEE International Conference on Dependable,
Autonomic and Secure Computing (pp. 648-651). IEEE.
[Link]
22
Mohammed, S., & Apeh, E. (2016). A model for social engineering awareness
program for schools. In 2016 10th International Conference on Software,
Knowledge, Information Management & Applications (SKIMA) (pp. 392-397).
IEEE. [Link]
Nwankpa, J. K., & Datta, P. M. (2023). Remote Vigilance: The Roles of Cyber
Awareness and Cybersecurity Policies Among Remote Workers. Computers &
Security, 103266. [Link]
Rocha Flores, W., & Ekstedt, M. (2016). Shaping intention to resist social
engineering through transformational leadership, information security culture and
awareness. Computers & Security, 59, 26-44.
[Link]
IBM Security. (2023). X-Force Threat Intelligence Index 2023. Annual Report.
Retrieved from [Link]
Sharma, A., Breeden II, J., & Fruhlinger, J. (2021, June 28). 15 top open-source
intelligence tools. CSO. Retrieved May 13, 2023, from
[Link]
[Link]
Strom, D. (2018, September 25). The Sony hacker indictment: 5 lessons for IT
security. CSO. Retrieved April 11, 2023, from
[Link]
[Link]
23
Verizon. (2022). 2022 Data Breach Investigations Report (DBIR) (T124). Verizon.
[Link]
[Link]
Williams, M. (2017, October 4). Inside the Russian hack of Yahoo: How they did
it. CSO. Retrieved April 21, 2017, from
[Link]
[Link]
24