Source-linked AI summary
An Analysis of the Impact of Psychological Factors and Techniques Across Different Types of Social Engineering
Helin Omer, Daniela Pöhn
TL;DR
The paper examines which psychological factors and social-engineering attack types are most effective, addressing limited comparative evidence across their combinations. It conducts a qualitative laboratory study with 12 participants exposed to 25 stimuli. Exploratory results identify spear-phishing as especially effective for authority, greed, and trust, with spear-phishing using greed the strongest combination.
Problem
Few studies compare psychological factors and techniques across different social-engineering attack types, despite the need to understand their influence for awareness campaigns and cybersecurity measures.
Method
A qualitative within-subject laboratory study exposed 12 participants to 25 randomized stimuli combining five psychological factors with five social-engineering attack types.
Results
Spear-phishing was the most effective attack type for authority, greed, and trust; spear-phishing using greed was the strongest combination, at a 75 % success rate.
Takeaways & Limitations
Comparing psychological factors across attack types can identify the combinations most relevant to social-engineering awareness campaigns and other cybersecurity measures.
Takeaways & Limitations
The small sample and laboratory setting limit generalizability and ecological validity, while single standardized scenarios restrict psychological-factor diversity.
Abstract
from arXiv · showhide
Phishing is a well-known social engineering (SE) type used to trick individuals into revealing personal information or performing desired actions, like downloading and installing malware. Other SE types, like vishing and smishing, have emerged and are increasingly being used. As SE continues to successfully persuade victims into actions, the questions arise of which SE attack types are most effective for specific psychological factors (PFs) and, conversely, which PFs are most effective for particular attack types. To answer these questions, we conducted a laboratory study with n=12 participants, in which each participant was shown all 25 stimuli (five PFs and five SE types). The results of this exploratory study show that the most effective SE attack type for authority, trust, and greed was spear-phishing. The most successful combination of PF and attack type was spear-phishing using greed. The least successful combinations were pop-ups using authority, smishing using authority, and vishing using curiosity, each having had no success at all.
1 Introduction
Social engineering exploits human psychological factors to obtain sensitive information or induce actions, while emerging channels such as smishing and vishing expand the attack landscape. The paper addresses limited comparative evidence by testing psychological factors across multiple attack types.
- Human factors influence how individuals manage cybersecurity issues and affect the effectiveness of cybersecurity measures.
- Social engineering exploits psychological factors to persuade individuals to reveal sensitive information or perform desired actions.
- Smishing and vishing attacks are growing in frequency and sophistication as attackers may focus on channels beyond email.
- Few studies compare psychological factors and techniques across different social-engineering attacks, limiting evidence for designing awareness campaigns and other measures.
- The study compares five psychological factors and five attack types using 25 stimuli, examining within-attack, within-factor, and best- or worst-combination patterns.
2 Social Engineering and Psychology
Social engineering comprises psychologically manipulative methods that exploit human vulnerabilities across email, mobile, social-network, and website channels. Psychological factors and persuasion techniques provide the conceptual basis for understanding these attacks.
- Psychological factors are individual characteristics that attackers can exploit by adapting methods to a person’s psychological susceptibilities.
- Social psychology examines influence and requests, while Cialdini’s persuasion principles include authority, reciprocation, consistency, social validation, liking, and scarcity.
- Prior work identified 16 psychological techniques, including persuasion, impersonation, pretexting, urgency, visual deception, personalization, and incentive-based tactics.
- Social engineering includes email attacks such as phishing and spear-phishing, mobile attacks such as vishing and smishing, and attacks through social networks and websites.
3 Related Work
Related work examines social-engineering models, psychological tactics, persuasion principles, personality, and susceptibility, but does not provide a comprehensive comparison of psychological factors across attack types. This study targets that stated gap.
- Existing publications include general social-engineering discussions and structured attack models extending Mitnick’s attack cycle.
- Prior research reports that attackers exploit more psychological elements than existing defences addressed and that authority is frequently used in social-engineering attacks.
- Other studies connect personality traits and information-processing differences with susceptibility to persuasion and judgments of email-link safety.
- Research using real-world datasets and literature reviews identifies commonly combined tactics, while noting that experiments only partially reproduce real attacks.
- The authors identify no prior study examining psychological factors and techniques across different social-engineering attack types.
4 Study Design
The laboratory study used a within-subject 5 x 5 design in which 12 participants evaluated 25 randomized, non-interactive stimuli covering five psychological factors and five social-engineering attack types. Responses combined yes/no behavioural intentions, ratings, and think-aloud explanations.
- Each of 12 participants viewed 25 stimuli formed from five psychological factors and five attack types in randomized order.
- The study used one standardized scenario per psychological factor, presented in different formats such as email, SMS, voice message, or pop-up.
- Participants were recruited in Munich, Germany, were over 18, received no compensation, and had ages ranging from 20 to 50 years.
- Individual sessions lasted approximately 30–60 minutes and used German-language stimuli and questions, with think-aloud responses collected for qualitative insight.
- After each stimulus, participants reported whether they would respond, explained why, and rated appeal and urgency on 1–4 Likert scales.
Post-Stimulus Questionnaire:
After all 25 stimuli, participants completed a post-stimulus questionnaire, answered reflective questions, and were debriefed about the simulated materials. The laboratory setup standardized presentation across participants using a tablet.
- Post-Stimulus Questionnaire:: After all 25 stimuli were shown, the questionnaire assessed participants’ socio-demographics, technological affinity, experience, and handling of unusual messages.
- Debriefing:: Participants then answered reflective questions about their impressions and suspicions.
- Debriefing:: The study debriefed participants about its purpose and informed them that all materials were simulated.
- 4.3 Experimental Setup: All sessions used a testing room and tablet to present the stimuli, stimulus questions, and post-stimulus questionnaire under consistent conditions.
- 4.3 Experimental Setup: The psychological-factor materials used impersonations and pretexts involving authority, curiosity, greed, fear, and updated account details.
- 4.3 Experimental Setup: Authority was represented by a purported CFO requesting urgent action on an attached financial report.
– Trust:
The materials included a trust-themed Netflix account-update message and simulated phishing-related attack examples presented through email or smartphone layouts. These examples were designed as SE materials rather than interactive attacks.
- – Trust:: The trust-themed example impersonated Netflix and stated that the user’s account details had been updated.
- – Trust:: Users were instructed to click a provided button to view the purported updated account details.
- – Trust:: The attack examples included simulated phishing emails shown as screenshots in an email inbox.
- – Trust:: SMS messages were created with iFake and displayed as screenshots in a smartphone layout.
– Vishing:
The study created vishing audio with a consistent text-to-speech voice and used standardized pop-up screenshots. Figure 1 illustrated SE examples paired with different psychological factors.
- – Vishing:: Vishing materials used ElevenLabs to generate text-to-speech audio.
- – Vishing:: One voice type was used across vishing examples to maintain consistency and avoid responses driven by voice differences.
- – Vishing:: Pop-up examples placed self-created windows over the Wikipedia main page.
- – Vishing:: The same background was used for all pop-up examples so behavioral intentions could be attributed to the psychological factor rather than the background.
- – Vishing:: The materials were noninteractive screenshots or short audio recordings simulating realistic but harmless SE attacks.
- – Vishing:: Figure 1 presented SE examples involving different psychological factors.
4.4 Measurements
The study combined questionnaire responses and think-aloud data to measure behavioral intention, appeal, urgency, and reasoning patterns. Its small sample and laboratory setting constrain generalizability and ecological validity.
- 4.4 Measurements: Questionnaires assessed both quantitative and qualitative information.
- 4.4 Measurements: The post-stimulus questionnaire collected demographic, educational, phishing-exposure, and digital-communication familiarity information.
- 4.4 Measurements: Behavioral intention was measured by whether participants would respond, while appeal and urgency were rated separately.
- 4.4 Measurements: Think-aloud verbalizations and written explanations were analyzed for risk awareness, cue utilization, emotional reactions, and personal reactions.
- 4.5 Limitations: The small sample size and laboratory setting reduce the generalizability of the findings.
- 4.5 Limitations: Because stimuli were screenshots or audio without real consequences, ecological validity was limited.
5 Results
Across the 25 stimuli, spear-phishing and phishing generally achieved the highest success, while authority was comparatively ineffective and several combinations produced no successful interactions.
- Authority: 13.3% was authority’s overall success rate, with spear-phishing highest at 33%.Vishing, smishing, and pop-ups each had success rates below 10%.
- Fear: 41.6% was the success rate for both phishing and spear-phishing using fear.Smishing achieved 25%, pop-ups 16.6%, and vishing 8.3% for fear.
- Greed: 75% was the success rate for spear-phishing using greed, compared with 66.6% for phishing using greed.Pop-ups achieved 33.3%, smishing 16.6%, and vishing 8.3% using greed.
- Trust: 66.6% was the success rate for spear-phishing using trust, while phishing using trust achieved 58.3%.Pop-ups and smishing each achieved 16.6%, and vishing 8.3%.
- Overall results: 75% was the highest success rate, achieved by spear-phishing using greed.Phishing using greed and spear-phishing using trust each achieved 66.6%.
- Overall results: 53.3% was the overall success rate for spear-phishing, followed by 48.3% for phishing.The three most effective psychological factors overall were greed at 40%, trust at 33.3%, and fear at 26.6%.
- Least successful combinations: 0 successful interactions occurred for pop-ups using authority, smishing using authority, and vishing using curiosity.These were the least successful psychological-factor and attack-type combinations.
- Self-rated risk awareness: 37 yes-votes came from participants rating themselves secure in digital-risk management, versus 3 from the very-secure group.The medium group had 33 yes-votes and the insecure group had 9.
6 Discussion
The discussion compares how psychological factors performed across social engineering channels and relates outcomes to participants’ explanations and self-rated risk awareness. Spear-phishing and phishing generally produced the strongest responses, while authority, vishing, pop-ups, and smishing were less successful in this study.
- Within-PF Design: Authority achieved 13.3% overall success, with spear-phishing highest at 33%, while inappropriate channels, illegitimate designs, and distrust commonly discouraged interaction.The study’s authority result contrasts with prior findings that identified authority as highly persuasive in phishing and scam compliance.
- Within-PF Design: Curiosity produced a 23.3% total yes-vote, reaching 50% success in both spear-phishing and phishing, while skepticism and lack of interest drove many refusals.Curiosity or interest was the most common reason for yes-votes, whereas skepticism or distrust was the most common reason for no-votes.
- Within-PF Design: Fear achieved 26.6% overall success, but security concerns sometimes prevented interaction rather than prompting it, showing that fear influenced decisions in opposite directions.Participants cited fear about account or financial consequences both as a reason to interact and as a reason to avoid the stimulus.
- Within-PF Design: Greed reached 40% overall success, including 75% for spear-phishing and 66.6% for phishing, with financial motivation the most common reason for yes-votes.The authors also report that apparently legitimate stimulus designs supported interaction with greed-based scenarios.
- Within-PF Design: Trust reached 33.3% overall success and was strongest in spear-phishing at 66.6% and phishing at 58.3%, whereas smishing, pop-ups, and vishing elicited more skepticism.“Seems legitimate” contributed 65% of reasons for interacting with trust stimuli.
7 Conclusion
The paper examines how psychological factors shape susceptibility across five social engineering attack types using an exploratory laboratory study. It finds that spear-phishing and phishing were most successful overall, with spear-phishing using greed the strongest combination, while future work should broaden the study.
- 7 Conclusion: Human factors are exploited in social engineering attacks, including through channels beyond email, motivating analysis of attack and psychological-factor effectiveness.The authors connect this analysis to developing countermeasures such as awareness campaigns.
- 7 Conclusion: Spear-phishing was most effective for authority, greed, and trust, while phishing and spear-phishing were most effective for curiosity and fear.Authority had 13.3% success, compared with 40% for greed and 33.3% for trust.
- 7 Conclusion: Spear-phishing achieved 53.3% overall success and phishing 48.3%; spear-phishing with greed was the strongest combination at 75% success.Phishing with greed and spear-phishing with trust each achieved 66.6% success.
- 7 Conclusion: The authors identify larger samples, additional social engineering attacks, and more psychological factors or techniques as priorities for future work.The supplied conclusion passage begins this future-work statement but does not provide further details.