An Analysis of the Impact of Psychological Factors and Techniques Across Different Types of Social Engineering
cs.CR
Submitted: 2026-08-26
Updated: 2026-08-26
Journal ref: Availability, Reliability and Security. ARES 2026 International Workshops
DOI: 10.1007/978-3-032-35576-8_27
License: http://creativecommons.org/licenses/by/4.0/
The gist: Phishing is a well-known social engineering (SE) type used to trick individuals into revealing personal information or performing desired actions, like downloading and installing malware.
Terminology
Abstract
Phishing is a well-known social engineering (SE) type used to trick individuals into revealing personal information or performing desired actions, like downloading and installing malware. Other SE types, like vishing and smishing, have emerged and are increasingly being used. As SE continues to successfully persuade victims into actions, the questions arise of which SE attack types are most effective for specific psychological factors (PFs) and, conversely, which PFs are most effective for particular attack types. To answer these questions, we conducted a laboratory study with n=12 participants, in which each participant was shown all 25 stimuli (five PFs and five SE types). The results of this exploratory study show that the most effective SE attack type for authority, trust, and greed was spear-phishing. The most successful combination of PF and attack type was spear-phishing using greed. The least successful combinations were pop-ups using authority, smishing using authority, and vishing using curiosity, each having had no success at all.
Sources
- Breaching the Human Firewall: Social engineering in Phishing and Spear-Phishing Emails
- Phishing, Personality Traits and Facebook
- Users really do respond to smishing
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs