From Digital Footprints to Cognitive Compromise: A Behavioural Architecture of Social Engineering and Psychological Manipulation in Sub-Saharan Africa: A scoping review
This scoping review synthesizes existing knowledge on social engineering in Sub-Saharan Africa, revealing how cybercriminals exploit digital footprints and collectivistic cultural values through psychological manipulation, and proposes localized education, AI-driven intercepts, and improved UI/UX design to enhance user resilience.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the digital age, security has long been viewed as a battle of locks and keys, where the goal was to build stronger walls around computer systems to keep intruders out. For decades, the focus was on technical defenses: firewalls, encryption, and complex passwords designed to stop hackers from breaking into code. However, a different kind of threat has risen to prominence, one that does not try to break the lock at all but instead convinces the person holding the key to open the door willingly. This approach, known as social engineering, relies entirely on human psychology rather than software vulnerabilities. It exploits the natural ways people think, feel, and interact, turning trust, fear, and a desire to help others into tools for deception. While this phenomenon is studied globally, the specific cultural and behavioral landscape of Sub-Saharan Africa presents a unique set of challenges and opportunities for these attackers, a region where rapid digital growth has outpaced the development of digital safety habits.
A recent scoping review by Rose Nabi Deborah Karimi Muthuri from the Catholic University of Eastern Africa seeks to map this hidden terrain. Rather than testing new software or running a single experiment, the author gathered and analyzed a wide range of existing studies, reports, and data from across the continent. The goal was to understand how cybercriminals in Sub-Saharan Africa have evolved from simple tricksters into sophisticated manipulators who use the very fabric of local culture and the psychology of fear to steal information and money. The review brings together findings from countries including Kenya, Nigeria, South Africa, and the Democratic Republic of the Congo to paint a picture of how these attacks work, what makes people vulnerable, and what can be done to protect them.
The investigation reveals that the journey of an attack often begins long before a victim receives a fraudulent message. It starts with the routine, everyday act of sharing life online. In many African communities, platforms like WhatsApp and Facebook are not just for communication but are central to social life, where people frequently post updates about their daily routines, financial transactions, and personal relationships. The review found that cybercriminals treat this openness as a goldmine of information. By observing these digital footprints, attackers can build detailed profiles of their targets, learning their habits, their emotional triggers, and who they trust. This process, known as reconnaissance, allows scammers to craft messages that feel incredibly personal and real. Instead of sending a generic warning to everyone, they can send a message that references a specific recent event in the victim's life, making the deception far more convincing and difficult to spot.
Once the attacker has gathered enough information, they move to the second stage, where they weaponize the deep-seated cultural values that hold many African societies together. The review highlights how concepts like Ubuntu in South Africa or Harambee in Kenya, which emphasize community, mutual support, and collective well-being, are twisted into tools for exploitation. Scammers impersonate trusted figures, such as religious leaders, family members, or community organizers, to create a sense of urgency and moral obligation. They might claim that a relative is in trouble and needs immediate money, or that a religious offering is required to save a community project. Because these appeals align with the victim's desire to help and their respect for authority, the natural instinct to be generous overrides the instinct to be suspicious. The review notes that this manipulation is particularly effective because it targets the heart of the community's identity, turning a strength into a weakness.
The third and perhaps most dangerous layer of these attacks involves the weaponization of fear and authority. In a region where digital regulations, such as SIM card registrations or tax audits, can be complex and sometimes abruptly enforced, citizens often live with a low-level anxiety about compliance. Cybercriminals exploit this by posing as government officials or bank representatives who claim the victim's account will be suspended or their SIM card deactivated unless they act immediately. The review explains that these threats create a state of panic that shuts down logical thinking. When people are frightened and believe they are facing an irreversible penalty, they stop questioning the request and simply comply to resolve the crisis. This psychological bypass allows attackers to override even the most basic skepticism, leading victims to hand over passwords or transfer funds without verifying the source of the message.
The findings of this review suggest that the current methods of teaching cybersecurity are often insufficient for this specific context. Traditional warnings that focus on technical details or generic advice do not account for the powerful influence of communal trust or the specific fears related to local regulations. The author argues that effective protection requires a shift in strategy. Instead of relying solely on automated systems or telling people to be more careful, security measures need to be redesigned to fit the local reality. This includes creating educational programs that use interactive simulations to help people practice recognizing these emotional traps, and designing mobile applications that introduce small delays or "friction" when a user is asked to make a sudden, urgent transfer. By understanding that the attack is psychological rather than technical, the review concludes that the path to safety lies in building defenses that respect human nature and local culture, rather than trying to fight them with code alone.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.