Skip to main content
Have a personal or library account? Click to login
From Mitnick to Modern Database Threats: Evolution of Social Engineering Tactics and Their Impact on Data Integrity Cover

From Mitnick to Modern Database Threats: Evolution of Social Engineering Tactics and Their Impact on Data Integrity

Open Access
|Jul 2025

References

  1. Akati, J., & Conrad, M. (2021, October). Anti-tailgating solution using biometric authentication, motion sensors and image recognition. 2021 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress, 825830. DOI: 10.1109/DASC-PICom-CBDCom-CyberSciTech52372.2021.00137
  2. Aldawood, H., & Skinner, G. (2020). Analysis and findings of social engineering industry experts explorative interviews: Perspectives on measures, tools, and solutions. IEEE Access, 8, 6732167329. DOI: 10.1109/access.2020.2983280
  3. Algarni, A. M., & Malaiya, Y. K. (2016). A consolidated approach for estimation of data security breach costs. 2016 2nd International Conference on Information Management (ICIM), 2639. DOI: 10.1109/infoman.2016.7477530
  4. Al-Hamar, Y., Kolivand, H., Tajdini, M., Saba, T., & Ramachandran, V. (2021). Enterprise credential spear-phishing attack detection. Computers & Electrical Engineering, 94, 107363. DOI: 10.1016/j.compeleceng.2021.107363
  5. Allen, J., Yang, Z., Landen, M., Bhat, R., Grover, H., Chang, A., Ji, Y., Perdisci, R., & Lee, W. (2020). Mnemosyne: An effective and efficient postmortem watering hole attack investigation system. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, 787802. DOI: 10.1145/3372297.3423355
  6. Ashfaq, S., Chandre, P., Pathan, S., Mande, U., Nimbalkar, M., & Mahalle, P. (2024). Defending against vishing attacks: A comprehensive review for prevention and mitigation techniques. Lecture Notes in Networks and Systems, 896, 411422. DOI: 10.1007/978-981-99-9811-1_33
  7. Bansal, M., Grover, D., & Sharma, D. (2019). Storage and query over encrypted sensitive association rules in database. International Journal of Internet Technology and Secured Transactions, 9(3), 242259. DOI: 10.1504/IJITST.2019.101818
  8. Becue, A., Praça, I., & Gama, J. (2021). Artificial intelligence, cyber-threats and Industry 4.0: challenges and opportunities. Artificial Intelligence Review, 54. DOI: 10.1007/s10462-020-09942-2
  9. Beerman, J., Berent, D., Falter, Z., & Bhunia, S. (2023, May). A review of colonial pipeline ransomware attack. 2023 IEEE/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops, 815. DOI: 10.1109/CCGridW59191.2023.00017
  10. Benavides-Astudillo, E., Fuertes, W., Sanchez-Gordon, S., Nuñez-Agurto, D., & Rodríguez-Galán, G. (2023). A phishing-attack-detection model using natural language processing and deep learning. Applied Sciences, 13(9), 5275. DOI: 10.3390/app13095275
  11. Boussios, E. (2021). Because of Snowden? The three leakers and privacy issues in the cyber matrix. Research and Innovation Forum, 2021, 513528. Springer International Publishing. DOI: 10.1007/978-3-030-84311-3_47
  12. Butt, U. A., Amin, R., Aldabbas, H., Mohan, S., Alouffi, B., & Ahmadian, A. (2022). Cloud-based email phishing attack using machine and deep learning algorithm. Complex & Intelligent Systems, 9, 30433070. DOI: 10.1007/s40747-022-00760-3
  13. Chan-Tin, E., & Stalans, L. J. (2023). Phishing for profit. Edward Elgar Publishing EBooks (pp. 5471). DOI: 10.4337/9781800886643.00011
  14. Chetioui, K., Bah, B., Alami, A. O., & Bahnasse, A. (2022). Overview of social engineering attacks on social networks. Procedia Computer Science, 198(1877–0509), 656661. DOI: 10.1016/j.procs.2021.12.302
  15. Chheda, H. (2024, July 29). 75+ Social engineering statistics for 2024. Sprinto. https://sprinto.com/blog/social-engineering-statistics/
  16. Coffey, J. W. (2019). Difficulties in determining data breach impacts. Systemics, Cybernetics and Informatics, 17(5).
  17. Erdoğan, B. (2021). Data protection around the world: Turkey. In E. Kiesow Cortez (Ed.), Data protection around the world: Privacy laws in action (pp. 203230). T.M.C. Asser Press.DOI: 10.1007/978-94-6265-407-5
  18. Fakieh, A., & Akremi, A. (2022). An effective blockchain-based defense model for organizations against vishing attacks. Applied Sciences, 12(24), 13020. DOI: 10.3390/app122413020
  19. Falade, P. (2023). Decoding the threat landscape: ChatGPT, FraudGPT, and WormGPT in social engineering attacks. IJSRCSEIT, 9(5), 185198. DOI: 10.32628/CSEIT2390533
  20. Girinoto, D. F. P., Yulita, T., Muhammad, A., Rifqi, A. F., & Putri, A. S. (2022, October). OmeTV pretexting phishing attacks: A case study of social engineering. In 2022 7th International Workshop on Big Data and Information Security (IWBIS), 119124. IEEE. DOI: 10.1109/IWBIS56557.2022.9924801
  21. Haggard, S., & Lindsay, J. R. (2015). North Korea and the Sony hack: Exporting instability through cyberspace. JSTOR, 117.
  22. Hathaway, M., & Klimburg, A. (2012). Preliminary considerations: on national cyber security. National Cyber Security Framework Manual. NATO Cooperative Cyber Defence Centre of Excellence, Tallinn.
  23. Hoofnagle, C. J., Sloot, B. V. D., & Borgesius, F. Z. (2019). The European Union general data protection regulation: what it is and what it means. Information & Communications Technology Law, 28(1), 6598. DOI: 10.1080/13600834.2019.1573501
  24. Irani, D., Balduzzi, M., Balzarotti, D., Kirda, E., & Pu, C. (2011). Reverse social engineering attacks in online social networks. Detection of Intrusions and Malware, and Vulnerability Assessment. Lecture Notes in computer Science, 6739, 5574. DOI: 10.1007/978-3-642-22424-9_4
  25. Ismail, K. A., Singh, M. M., Mustaffa, N., Keikhosrokiani, P., & Zulkefli, Z. (2017). Security strategies for hindering watering hole cyber crime attack. Procedia Computer Science, 124, 656663. DOI: 10.1016/j.procs.2017.12.202
  26. Jain, A. K., & Gupta, B. B. (2021). A survey of phishing attack techniques, defense mechanisms and open research challenges. Enterprise Information Systems, 16(4), 139. DOI: 10.1080/17517575.2021.1896786
  27. Jakala, M., & Pekkola, S. (2007). From technology engineering to social engineering. ACM SIGMIS Database: The DATABASE for Advances in Information Systems, 38(4), 1116. DOI: 10.1145/1314234.1314238
  28. John, S., Ravichandran, N., & Khan, M. F. (2018). Electronic medical record for deliverance of effective healthcare delivery: Ethical issues and challenges of digitalization in clinical information and electronic medical records (EMR) management. IOSR Journal of Business and Management, 20(3), 106112. DOI: 10.9790/487X-2003020106
  29. Kamruzzaman, A., Thakur, K., Ismat, S., Ali, M. L., Huang, K., & Thakur, H. N. (2023, March 1). Social engineering incidents and preventions. 2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC), 04940498. DOI: 10.1109/CCWC57344.2023.10099202
  30. Kathiravan, M., Rajasekar, V., Parvez, S. J., Durga, V. S., Meenakshi, M., & Gowsalya, S. (2023, February). Detecting Phishing websites using Machine Learning Algorithm. In 2023 7th International Conference on Computing Methodologies and Communication. DOI: 10.1109/ICCMC56507.2023.10083999
  31. Kekulluoglu, D., Magdy, W., & Vaniea, K. (2020, July). Analysing privacy leakage of life events on twitter. Proceedings of the 12th ACM Conference on Web Science, 287294. DOI: 10.1145/3394231.3397919
  32. Kiesow Cortez, E. (2020). Data Breaches and GDPR. The Palgrave Handbook of International Cybercrime and Cyberdeviance, 239256. DOI: 10.1007/978-3-319-78440-3_39
  33. Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22(1), 113122. DOI: 10.1016/j.jisa.2014.09.005
  34. Kwak, Y., Lee, S., Damiano, A., & Vishwanath, A. (2020). Why do users not report spear phishing emails? Telematics and Informatics, 48, 101343. DOI: 10.1016/j.tele.2020.101343
  35. Li, G., Zhou, X., & Cao, L. (2021). AI Meets Database: AI4DB and DB4 AI. Proceedings of the 2021 International Conference on Management of Data. DOI: 10.1145/3448016.3457542
  36. Mehta, A., Vora, D., & Sachala, H. (2021). A review of social engineering attacks and their mitigation solutions. International Journal of Engineering Research & Technology, 10(10).
  37. Mitnick, K. D., & Simon, W. L. (2003). The art of deception: controlling the human element of security. New York; Chichester: Wiley.
  38. Montanez, R., Atyabi, A., & Xu, S. (2022). Social engineering attacks and defenses in the physical world vs. cyberspace: a contrast study. Cybersecurity and Cognitive Science, 341. DOI: 10.1016/B978-0-323-90570-1.00012-7
  39. Morse, E. A., Raval, V., & Wingender, J. R. (2011). Market price effects of data security breaches. Information Security Journal: A Global Perspective, 20(6), 263273. DOI: 10.1080/19393555.2011.611860
  40. Neto, N. N., Madnick, S., Paula, A. M. G. D., & Borges, N. M. (2021). Developing a global data breach database and the challenges encountered. Journal of Data and Information Quality, 13(1), 133. DOI: 10.1145/3439873
  41. Novak, A. N., & Vilceanu, M. O. (2019). “The internet is not pleased”: Twitter and the 2017 Equifax data breach. The Communication Review, 22(3), 196221. DOI: 10.1080/10714421.2019.1651595
  42. Orlando, A. (2021). Cyber risk quantification: Investigating the role of cyber value at risk. Risks, 9(10), 184. DOI: 10.3390/risks9100184
  43. Paganini, P. (2020, March 31). Holy Water targets religious figures and charities in Asia. Security Affairs. https://securityaffairs.com/100818/hacking/holy-water-watering-hole-attacks.html
  44. Patrick, H., van Niekerk, B., & Fields, Z. (2019). Developing cybersecurity resilience in the provincial government. Cyber Law, Privacy, and Security: Concepts, Methodologies, Tools, and Applications, 870897. DOI: 10.4018/978-1-5225-8897-9.ch041
  45. Perera, S., Jin, X., Maurushat, A., & Opoku, D.-G. J. (2022). Factors affecting reputational damage to organisations due to cyberattacks. Informatics, 9(1), 28. DOI: 10.3390/informatics9010028
  46. Pitman, L., & Crosier, W. (2024). On the scale from ransomware to cyberterrorism: the cases of JBS USA, colonial pipeline and the wiperware attacks against Ukraine. Journal of Cyber Policy, 121. DOI: 10.1080/23738871.2024.2377670
  47. Presthus, W., & Sønslien, K. F. (2021). An analysis of violations and sanctions following the GDPR. International Journal of Information Systems and Project Management, 9(1), 3853. DOI: 10.12821/ijispm090102
  48. Prevezianou, M. F. (2021). Beyond ones and zeros: Conceptualizing cyber crises. Risk, Hazards & Crisis in Public Policy, 12(1), 5172. DOI: 10.1002/rhc3.12204
  49. Quader, F., & Janeja, V. P. (2021). Insights into organizational security readiness: Lessons learned from cyber-attack case studies. Journal of Cyber security and Privacy, 1(4), 638659. DOI: 10.3390/jcp1040032
  50. Roberts, P. (2010, August 26). Thumb drive attack in 2008 compromised classified U.S. networks. Threatpost. https://threatpost.com/thumb-drive-attack-2008-compromised-classified-us-networks-082610/74385
  51. Salahdine, F., El Mrabet, Z., & Kaabouch, N. (2021, December). Phishing attacks detection a machine learning-based approach. 2021 IEEE 12th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference, 02500255. DOI: 10.1109/UEMCON53757.2021.9666627
  52. Salahdine, F., & Kaabouch, N. (2019). Social engineering attacks: A survey. Future Internet, 11(4), 89. DOI: 10.3390/fi11040089
  53. Shu, X., Tian, K., Ciambrone, A., & Yao, D. (2017). Breaking the target: An analysis of target data breach and lessons learned. ArXiv.org. DOI: 10.48550/arXiv.1701.04940
  54. Siadati, H., Nguyen, T., Gupta, P., Jakobsson, M., & Memon, N. (2017). Mind your SMSes: Mitigating social engineering in second factor authentication. Computers & Security, 65, 1428. DOI: 10.1016/j.cose.2016.09.009
  55. Sicard, S. (2015). North Korean cyber attack on Sony poses tough security questions. National Defense, 99(736), 2425.
  56. Smith, M., & Mulrain, G. (2017). Equi-failure: The national security implications of the Equifax hack and a critical proposal for reform. Journal of National Security Law and Policy, 9, 549.
  57. Soni, S., & Mathew, R. (2020). Database security: Attacks and solutions. Proceeding of the International Conference on Computer Networks, Big Data and IoT (ICCBI-2019) (pp. 917925). Springer International Publishing. DOI: 10.1007/978-3-030-43192-1_100
  58. Sonowal, G., Sharma, A., & Kharb, L. (2021). Spear-phishing emails verification method based on verifiable secret sharing scheme. Journal of Information Assurance & Security, 16(3).
  59. Thomas, J. E. (2018). Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. International Journal of Business Management, 12(3), 123. DOI: 10.5539/ijbm.v13n6p1
  60. Tulkarm, P. (2021). A survey of social engineering attacks: Detection and prevention tools. Journal of Theoretical and Applied Information Technology, 99(18).
  61. Vadrevu, P., & Perdisci, R. (2019). What you see is not what you get. Proceedings of the Internet Measurement Conference, 308321. DOI: 10.1145/3355369.3355600
  62. Wang, Z., Sun, L., & Zhu, H. (2020). Defining social engineering in cybersecurity. IEEE Access, 8, 8509485115. DOI: 10.1109/ACCESS.2020.2992807
  63. Weaver, B. W., Braly, A. M., & Lane, D. M. (2021). Training users to identify phishing emails. Journal of Educational Computing Research, 59(6), 073563312199251. DOI: 10.1177/0735633121992516
DOI: https://doi.org/10.21061/jts.438 | Journal eISSN: 1541-9258
Language: English
Page range: 14 - 29
Submitted on: Feb 10, 2025
Accepted on: Jun 17, 2025
Published on: Jul 4, 2025
Published by: Virginia Tech Publishing
In partnership with: Paradigm Publishing Services

© 2025 Ndubuisi Ukwadinachi, published by Virginia Tech Publishing
This work is licensed under the Creative Commons Attribution 4.0 License.