SOCIAL ENGINEERING AND THE LIMITS OF CYBERCRIME PREVENTION: A REVIEW OF SOCIAL, EDUCATIONAL, AND TECHNOLOGICAL CHALLENGES
Abstract
Social engineering remains a leading pathway to cyber harm, not primarily because users “lack awareness,” but because attackers exploit common cognitive shortcuts, social norms, and organisational routines – now intensified by rapid, platform-mediated communication. This study aims to clarify why social engineering persists as a prevention challenge and to assess the limitations of current prevention strategies. The paper employs a narrative (critical) literature review. Interdisciplinary research on social engineering and cybercrime prevention is synthesised using a thematic-analytic structure across three strands: (1) social vulnerability and victimisation, (2) educational and organisational prevention (training, awareness, culture, routines, and usable warning/interface design), and (3) technological asymmetry and escalation, including AI-enabled deception and deepfake-enabled impersonation. The reviewed literature converges on four findings. First, susceptibility is contextual and patterned, shaped by roles, routines, socio-emotional dynamics, and platform cues rather than stable individual deficits. Second, training and awareness can help but often show limited transfer and sustainability when gener
Keywords
Full Text:
PDFReferences
Abdulla, R. M., Faraj, H. A., Abdullah, C. O., Amin, A. H., and Rashid, T. A. (2023). Analysis of social engineering awareness among students and lecturers. IEEE Access, 11, 101098–101111. https://doi.org/10.1109/ACCESS.2023.3311708
Akhawe, D., and Felt, A. P. (2013). Alice in Warningland: A large-scale field study of browser security warning effectiveness. In Proceedings of the 22nd USENIX Security Symposium (USENIX Security 13) (pp. 257–272). USENIX Association.
Alahmed, Y., Abadla, R., and Al Ansari, M. J. (2024). Exploring the potential implications of AI-generated content in social engineering attacks. In Proceedings of the 2024 International Conference on Multimedia Computing, Networking and Applications (MCNA) (pp. 64–73). IEEE.
Albladi, S. M., and Weir, G. R. S. (2018). User characteristics that influence judgment of social engineering attacks in social networks. Human-centric Computing and Information Sciences, 8, Article 5. https://doi.org/10.1186/s13673-018-0128-7
Aldawood, H., and Skinner, G. (2019). Reviewing cyber security social engineering training and awareness programs—Pitfalls and ongoing issues. Future Internet, 11(3), 73. https://doi.org/10.3390/fi11030073
Algarni, A. (2019). What message characteristics make social engineering successful on Facebook: The role of central route, peripheral route, and perceived risk. Information, 10(6), Article 211. https://doi.org/10.3390/info10060211
Almaliki, M. (2019). Misinformation-aware social media: A software engineering perspective. IEEE Access, 7, 182451–182459. https://doi.org/10.1109/ACCESS.2019.2960270
Alshammari, S. S., Soh, B., and Li, A. (2025). Understanding social engineering victimisation on social networking sites: A comprehensive review of factors influencing user susceptibility to cyber-attacks. Information, 16(2), 153. https://doi.org/10.3390/info16020153
Alshammari, S. S., Soh, B., and Li, A. (2025). Understanding social engineering victimisation on social networking sites: A comprehensive review of factors influencing user susceptibility to cyber-attacks. Information, 16(2), 153. https://doi.org/10.3390/info16020153
Alsulami, M. H., Alharbi, F., Almutairi, H., Almutairi, B. A. A., Alotaibi, M. B., Alanzi, M. E., Alotaibi, K. D., and Al-Harthi, S. E. (2021). Measuring awareness of social engineering in the educational sector in the Kingdom of Saudi Arabia. Information, 12(5), 208. https://doi.org/10.3390/info12050208
Anderson, B. B., Jenkins, J. L., Vance, A., Kirwan, C. B., and Eargle, D. (2016). Your memory is working against you: How eye tracking and memory explain habituation to security warnings. Decision Support Systems, 92, 3–13. https://doi.org/10.1016/j.dss.2016.09.010
Bada, M., Sasse, A. M., and Nurse, J. R. C. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour? https://arxiv.org/abs/1901.02672
Beautement, A., Sasse, M. A., and Wonham, M. (2008). The compliance budget: Managing security behaviour in organisations. In Proceedings of the 2008 New Security Paradigms Workshop (NSPW ’08) (pp. 47–58). Association for Computing Machinery. https://doi.org/10.1145/1595676.1595684
Birthriya, S. K., Ahlawat, P., and Jain, A. K. (2025). A comprehensive survey of social engineering attacks: Taxonomy of attacks, prevention, and mitigation strategies. Journal of Applied Security Research. https://doi.org/10.1080/19361610.2024.2372986
Blauth, T. F., Gstrein, O. J., and Zwitter, A. (2022). Artificial intelligence crime: An overview of malicious use and abuse of AI. IEEE Access, 10, 77110–77122. https://doi.org/10.1109/ACCESS.2022.3191790
Borkovich, D. J., and Skovira, R. J. (2019). Cybersecurity inertia and social engineering: Who’s worse, employees or hackers? Issues in Information Systems, 20(3), 139–150. https://doi.org/10.48009/3_iis_2019_139-150
Broadhurst, R., Broadhurst, M., Alazab, M., Chon, S., and Jiang, C. (2019). Artificial intelligence and crime. SSRN.
Cialdini, R. B. (2007). Influence: The psychology of persuasion (Rev. ed.). Harper Business.
Cletus, A., Weyory, B., and Opoku, A. (2022). Improving social engineering awareness, training and education (SEATE) using a behavioral change model. International Journal of Advanced Computer Science and Applications, 13(5), 606–613.
Cohen, L. E., and Felson, M. (1979). Social change and crime rate trends: A routine activity approach. American Sociological Review, 44(4), 588–608. https://doi.org/10.2307/2094589
Collier, H. (2025). AI in social engineering: The next generation of offensive cyber operations. In Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025) (pp. 80–83). Academic Conferences International LimitedCross, C. (2018). Cybercrime: Victimisation, offenders and policing. Routledge. https://doi.org/10.4324/9781315644574
Ferrari, R. (2015). Writing narrative style literature reviews. Medical Writing, 24(4), 230–235. https://doi.org/10.1179/2047480615Z.000000000329
Grant, M. J., and Booth, A. (2009). A typology of reviews: An analysis of 14 review types and associated methodologies. Health Information and Libraries Journal, 26(2), 91–108. https://doi.org/10.1111/j.1471-1842.2009.00848.x
Green, B. N., Johnson, C. D., and Adams, A. (2006). Writing narrative literature reviews for peer-reviewed journals: Secrets of the trade. Journal of Chiropractic Medicine, 5(3), 101–117. https://doi.org/10.1016/S0899-3467(07)60142-6
Hadlington, L. (2017). Human factors in cybersecurity; Examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours. Heliyon, 3(7), e00346. https://doi.org/10.1016/j.heliyon.2017.e00346
Hayward, K. J., and Maas, M. (2021). Artificial intelligence and crime: A primer for criminologists. Crime, Media, Culture, 17(2), 209–233.
Hindelang, M. J., Gottfredson, M. R., and Garofalo, J. (1978). Victims of personal crime: An empirical foundation for a theory of personal victimization. Ballinger.
Jayatilaka, A., Beu, N., Baetu, I., Zahedi, M., Babar, M. A., Hartley, L., and Lewinsmith, W. (2021). Evaluation of security training and awareness programs: Review of current practices and guidelines. https://doi.org/10.48550/arXiv.2112.06356
Khan, N. F., Ikram, N., Murtaza, H., and Javed, M. (2023). Evaluating protection motivation based cybersecurity awareness training on Kirkpatrick’s model. Computers and Security, 125, 103049. https://doi.org/10.1016/j.cose.2022.103049
Kirwan, C. B., Bjornn, D. K., Anderson, B. B., Vance, A., Eargle, D., and Jenkins, J. L. (2020). Repetition of computer security warnings results in differential repetition suppression effects as revealed with functional MRI. Frontiers in Psychology, 11, 528079. https://doi.org/10.3389/fpsyg.2020.528079
Klimburg-Witjes, N., and Wentland, A. (2021). Hacking humans? Social engineering and the construction of the “deficient user” in cybersecurity discourses. Science, Technology, and Human Values, 46(6), 1316–1339. https://doi.org/10.1177/0162243921992844
Kumar, N., and Muhammad Salman. (2025). RTBTS: A Real-Time Behavioural Training System to Mitigate Psychological Vulnerabilities in Social Engineering Attacks. International Journal of Electrical, Computer, and Biomedical Engineering, 3(1), 188–211. https://doi.org/10.62146/ijecbe.v3i1.103
Leukfeldt, E. R. (2014). Cybercrime and social ties. Trends in Organized Crime, 17(4), 231–249. https://doi.org/10.1007/s12117-014-9223-2
Leukfeldt, E. R., and Yar, M. (2016). Applying routine activity theory to cybercrime: A theoretical and empirical analysis. Deviant Behavior, 37(3), 263–280. https://doi.org/10.1080/01639625.2015.1012409
Li, T., Song, C., and Pang, Q. (2023). Defending against social engineering attacks: A security pattern-based analysis framework. IET Information Security, 17(4), 703–726. https://doi.org/10.1049/ise2.12125
Matecas, A.-R., Kieseberg, P., and Tjoa, S. (2025). Social engineering with AI. Future Internet, 17(11), 515. https://doi.org/10.3390/fi17110515
Mitnick, K. D., and Simon, W. L. (2002). The art of deception: Controlling the human element of security. Wiley.
Montañez, R., Golob, E., and Xu, S. (2020). Human cognition through the lens of social engineering cyberattacks. Frontiers in Psychology, 11, 1755. https://doi.org/10.3389/fpsyg.2020.01755
Muhanad, A., Abuelezz, I., Haris, R., Khan, K. M., and Ali, R. (2025). Personality traits as predictors of vulnerability to persuasion in social engineering amongst risk-aware targets. Computing, 107, Article 168. https://doi.org/10.1007/s00607-025-01521-z
Nowakowski, W. (2025). Social engineering analysis framework: A comprehensive playbook for human hacking. IEEE Access, 13, 18827–18849. https://doi.org/10.1109/ACCESS.2025.3532999
Pakina, R., Kejriwal, D., Pujari, R., and Rane, A. (2025). Adversarial AI in social engineering attacks. International Journal of Science and Technology, 4(1). https://doi.org/10.56127/ijst.v4i1.1964
Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A., and Zwaans, T. (2017). The Human Aspects of Information Security Questionnaire (HAIS-Q): Two further validation studies. Computers and Security, 66, 40–51. https://doi.org/10.1016/j.cose.2017.01.004
Pedersen, K. T., Pepke, L., Stærmose, T., Papaioannou, M., Choudhary, G., and Dragoni, N. (2025). Deepfake-driven social engineering: Threats, detection techniques, and defensive strategies in corporate environments. Journal of Cybersecurity and Privacy, 5(2), 18. https://doi.org/10.3390/jcp5020018
Prümmer, J., van Steen, T., and van den Berg, B. (2024). A systematic review of current cybersecurity training methods. Computers and Security, 136, 103585. https://doi.org/10.1016/j.cose.2023.103585
Prümmer, J., van Steen, T., and van den Berg, B. (2025). Assessing the effect of cybersecurity training on end-users: A meta-analysis. Computers and Security, 150, 104206. https://doi.org/10.1016/j.cose.2024.104206
Rahwan, I., Cebrian, M., Obradovich, N., Bongard, J., Bonnefon, J.-F., Breazeal, C., … Wellman, M. (2019). Machine behaviour. Nature, 568, 477–486. https://doi.org/10.1038/s41586-019-1138-y
Schmitt, M., and Flechais, I. (2024). Digital deception: Generative artificial intelligence in social engineering and phishing. Artificial Intelligence Review, 57, 324. https://doi.org/10.1007/s10462-024-10973-2
Siddiqi, M. A., Pak, W., and Siddiqi, M. A. (2022). A study on the psychology of social engineering-based cyberattacks and existing countermeasures. Applied Sciences, 12(12), 6042. https://doi.org/10.3390/app12126042
Stoica, A. (2021). Social engineering as the new deception game. Romanian Journal of Information Technology and Automatic Control, 31(3), 57–68. https://doi.org/10.33436/v31i3y202105
Syafitri, W., Shukur, Z., Mokhtar, U. A., Sulaiman, R., and Ibrahim, M. A. (2022). Social engineering attacks prevention: A systematic literature review. IEEE Access, 10, 39325–39343. https://doi.org/10.1109/ACCESS.2022.3162594 OUCI
Tariq, S., Singh, A., Chhetri, S. R., Nepal, S., and Paris, C. (2025). Bridging expertise gaps: The role of LLMs in human-AI collaboration for cybersecurity.
Tiwari, S. (2025). Social engineering attacks: Trends, psychological triggers, and defense mechanisms (preprint). Preprints.org.
Tversky, A., and Kahneman, D. (1974). Judgment under uncertainty: Heuristics and biases. Science, 185(4157), 1124–1131. https://doi.org/10.1126/science.185.4157.1124
Venkatesha, S., Reddy, K. R., and Chandavarkar, B. R. (2021). Social engineering attacks during the COVID-19 pandemic. SN Computer Science, 2, 78. https://doi.org/10.1007/s42979-020-00443-1
Vishwanath, A. (2015). Examining the distinct antecedents of e-mail habits and its influence on the outcomes of a phishing attack. Journal of Computer-Mediated Communication, 20(5), 570–584. https://doi.org/10.1111/jcc4.12126
Vishwanath, A., Harrison, B., and Ng, Y. J. (2018). Suspicion, cognition, and automaticity model of phishing susceptibility. Communication Research, 45(8), 1146–1166. https://doi.org/10.1177/0093650215627483
Walklate, S. (2007). Imagining the victim of crime. Open University Press.
Wang, Z., Sun, L., and Zhu, H. (2020). Defining social engineering in cybersecurity. IEEE Access, 8, 85094–85115. https://doi.org/10.1109/ACCESS.2020.2992807
Wang, Z., Zhu, H., and Sun, L. (2021). Social engineering in cybersecurity: Effect mechanisms, human vulnerabilities and attack methods. IEEE Access, 9, 11895–11910. https://doi.org/10.1109/ACCESS.2021.3051633
Wang, Z., Zhu, H., Liu, P., and Sun, L. (2021). Social engineering in cybersecurity: a domain ontology and knowledge graph application examples. Cybersecurity, 4(1), 31. https://doi.org/10.1186/s42400-021-00094-6
Workman, M. (2008). Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security. Journal of the American Society for Information Science and Technology, 59(4), 662–674. https://doi.org/10.1002/asi.20779
Xu, Y., Han, X., Deng, G., Li, J., Liu, Y., and Zhang, T. (2023). SoK: Rethinking sensor spoofing attacks against robotic vehicles from a systematic view. In 2023 IEEE 8th European Symposium on Security and Privacy (EuroSandP) Workshops (pp. 1082–1100). IEEE.
Yar, M. (2005). The novelty of “cybercrime”: An assessment in light of routine activity theory. European Journal of Criminology, 2(4), 407–427. https://doi.org/10.1177/147737080556056
Yu, J., Yu, Y., Wang, X., Lin, Y., Yang, M., Qiao, Y., and Wang, F. Y. (2024). The shadow of fraud: The emerging danger of ai-powered social engineering and its possible cure. arXiv preprint arXiv:2407.15912.
Zaaba, Z. F., Yi, C. L. X., Amran, A., and Omar, M. A. (2021). Harnessing the challenges and solutions to improve security warnings: A review. Sensors, 21(21), 7313. https://doi.org/10.3390/s21217313
Zaoui, M., Yousra, B., Sadqi, Y., Maleh, Y., and Ouazzane, K. (2024). A comprehensive taxonomy of social engineering attacks and defense mechanisms: Toward effective mitigation strategies. IEEE Access, 12, 72224–72241. https://doi.org/10.1109/ACCESS.2024.3403197
DOI: https://doi.org/10.22190/TEME260223036D
Refbacks
- There are currently no refbacks.
© University of Niš, Serbia
Creative Commons licence CC BY-NC-ND
Print ISSN: 0353-7919
Online ISSN: 1820-7804