An Analysis of the Impact of Psychological Factors and Techniques Across Different Types of Social Engineering
This exploratory laboratory study involving 12 participants analyzes the effectiveness of various social engineering attack types (such as phishing, vishing, and smishing) combined with different psychological factors, revealing that spear-phishing leveraging greed is the most successful combination, while certain pairings like pop-ups or smishing with authority and vishing with curiosity proved entirely ineffective.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Every day, people make choices about what to click, what to open, and what to trust. In the world of cybersecurity, these choices are the front line of defense. Attackers do not always need to break through complex computer code; often, they simply need to trick a person into handing over a password or downloading a virus. This method of manipulation is called social engineering. It relies on exploiting how the human mind works, using specific psychological triggers to bypass caution. Some of these triggers are familiar emotions like fear or the promise of a reward, while others are social habits like obeying a boss or trusting a well-known brand. Understanding which emotional trigger works best on which type of message is crucial, because it helps organizations teach their employees how to spot the trap before it springs.
A team of researchers in Germany set out to map these traps. They wanted to know if certain emotional triggers worked better with specific types of messages. For instance, does the promise of free money work better in a text message or an email? Does the fear of a frozen bank account work better over the phone or in a pop-up window? To find the answers, the researchers conducted a controlled experiment in a laboratory. They gathered twelve volunteers and showed them a series of simulated attacks. Each participant saw twenty-five different scenarios. These scenarios were created by mixing five different types of messages with five different psychological triggers. The message types included standard emails, targeted emails that looked like they came from a specific person, text messages, voice calls, and pop-up windows that appear on a screen. The psychological triggers were curiosity, greed, trust, fear, and the feeling of obeying an authority figure.
The researchers did not ask the volunteers to actually click on links or give away real information. Instead, they showed them pictures of the messages or played recordings of the calls and asked a simple question: would you respond to this? The volunteers also explained their thinking out loud as they looked at the scenarios. This allowed the researchers to see not just what people did, but why they made those choices. The study was small and took place in a quiet room, so the results are a first look at how these factors interact rather than a final rule for the entire world.
The results revealed a clear pattern in how people react. The most successful combination for tricking the volunteers was a targeted email that promised a financial reward. When an email looked like it came from a specific person and offered a deal, three out of four participants said they would respond. This suggests that the combination of personal attention and the promise of money is a powerful lure. The second most effective method was a standard email that either promised a reward or asked the recipient to trust the sender, such as a message claiming to be from a streaming service. In these cases, more than half of the volunteers said they would engage with the message.
However, not all combinations worked. The researchers found that some methods failed almost entirely. When the attackers tried to use the authority of a boss to demand an urgent action, it rarely worked, especially if the message came through a phone call, a text, or a pop-up window. In fact, when a voice call tried to use curiosity to get a person to listen, it failed completely; none of the volunteers said they would respond to that specific scenario. The volunteers explained that they found these channels inappropriate for the type of request. For example, they felt that a boss would not call to ask for a file download, or that a company would not send a text message about a shared folder.
The study also showed that the type of emotion mattered. Fear was a strong motivator, but it had a double edge. When a message claimed that a bank account was frozen, many people felt the urge to fix it, but an even larger group felt suspicious and refused to click because they were worried about security. Greed, on the other hand, was a more straightforward driver. When a message offered a discount or a deal, people were more likely to act on it, provided the message looked legitimate. Trust also played a major role; when a message seemed to come from a familiar company like a streaming service, people were willing to click, but only if the message arrived in a format they expected, like an email.
Interestingly, the researchers found that a person's confidence in their own digital safety did not always match their behavior. Some volunteers who said they were very secure in handling digital risks still fell for the traps, while others who said they were insecure were actually more cautious. This suggests that feeling safe does not always mean being safe. The study also highlighted that voice calls and text messages were generally less effective than emails. The volunteers were naturally more suspicious of phone calls and text messages, often citing that these channels felt wrong for the type of request being made.
In the end, the research paints a picture of human vulnerability that is specific and situational. It is not just about being gullible; it is about the context. A message that works in one format might fail in another, and a promise of money works better than a command from a boss. The most effective attacks were those that combined a familiar, trusted format with a strong emotional hook. While the study was small, it provides a clear map of which psychological triggers are most dangerous in which digital environments, offering a guide for how to build better defenses and awareness training for the future.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.