
From Mitnick to Modern Database Threats: Evolution of Social Engineering Tactics and Their Impact on Data Integrity
References
- Akati, J., & Conrad, M. (2021, October). Anti-tailgating solution using biometric authentication, motion sensors and image recognition. 2021 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress, 825–830. DOI: 10.1109/DASC-PICom-CBDCom-CyberSciTech52372.2021.00137
- Aldawood, H., & Skinner, G. (2020). Analysis and findings of social engineering industry experts explorative interviews: Perspectives on measures, tools, and solutions. IEEE Access, 8, 67321–67329. DOI: 10.1109/access.2020.2983280
- Algarni, A. M., & Malaiya, Y. K. (2016). A consolidated approach for estimation of data security breach costs. 2016 2nd International Conference on Information Management (ICIM), 26–39. DOI: 10.1109/infoman.2016.7477530
- Al-Hamar, Y., Kolivand, H., Tajdini, M., Saba, T., & Ramachandran, V. (2021). Enterprise credential spear-phishing attack detection. Computers & Electrical Engineering, 94,
107363 . DOI: 10.1016/j.compeleceng.2021.107363 - Allen, J., Yang, Z., Landen, M., Bhat, R., Grover, H., Chang, A., Ji, Y., Perdisci, R., & Lee, W. (2020). Mnemosyne: An effective and efficient postmortem watering hole attack investigation system. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, 787–802. DOI: 10.1145/3372297.3423355
- Ashfaq, S., Chandre, P., Pathan, S., Mande, U., Nimbalkar, M., & Mahalle, P. (2024). Defending against vishing attacks: A comprehensive review for prevention and mitigation techniques. Lecture Notes in Networks and Systems, 896, 411–422. DOI: 10.1007/978-981-99-9811-1_33
- Bansal, M., Grover, D., & Sharma, D. (2019). Storage and query over encrypted sensitive association rules in database. International Journal of Internet Technology and Secured Transactions, 9(3), 242–259. DOI: 10.1504/IJITST.2019.101818
- Becue, A., Praça, I., & Gama, J. (2021). Artificial intelligence, cyber-threats and Industry 4.0: challenges and opportunities. Artificial Intelligence Review,
54 . DOI: 10.1007/s10462-020-09942-2 - Beerman, J., Berent, D., Falter, Z., & Bhunia, S. (2023, May). A review of colonial pipeline ransomware attack. 2023 IEEE/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops, 8–15. DOI: 10.1109/CCGridW59191.2023.00017
- Benavides-Astudillo, E., Fuertes, W., Sanchez-Gordon, S., Nuñez-Agurto, D., & Rodríguez-Galán, G. (2023). A phishing-attack-detection model using natural language processing and deep learning. Applied Sciences, 13(9),
5275 . DOI: 10.3390/app13095275 - Boussios, E. (2021).
Because of Snowden? The three leakers and privacy issues in the cyber matrix . Research and Innovation Forum, 2021, 513–528. Springer International Publishing. DOI: 10.1007/978-3-030-84311-3_47 - Butt, U. A., Amin, R., Aldabbas, H., Mohan, S., Alouffi, B., & Ahmadian, A. (2022). Cloud-based email phishing attack using machine and deep learning algorithm. Complex & Intelligent Systems, 9, 3043–3070. DOI: 10.1007/s40747-022-00760-3
- Chan-Tin, E., & Stalans, L. J. (2023). Phishing for profit. Edward Elgar Publishing EBooks (pp. 54–71). DOI: 10.4337/9781800886643.00011
- Chetioui, K., Bah, B., Alami, A. O., & Bahnasse, A. (2022). Overview of social engineering attacks on social networks. Procedia Computer Science, 198(1877–0509), 656–661. DOI: 10.1016/j.procs.2021.12.302
- Chheda, H. (2024, July 29). 75+ Social engineering statistics for 2024. Sprinto.
https://sprinto.com/blog/social-engineering-statistics/ - Coffey, J. W. (2019). Difficulties in determining data breach impacts. Systemics, Cybernetics and Informatics, 17(5).
- Erdoğan, B. (2021).
Data protection around the world: Turkey . In E. Kiesow Cortez (Ed.), Data protection around the world: Privacy laws in action (pp. 203–230). T.M.C. Asser Press.DOI: 10.1007/978-94-6265-407-5 - Fakieh, A., & Akremi, A. (2022). An effective blockchain-based defense model for organizations against vishing attacks. Applied Sciences, 12(24),
13020 . DOI: 10.3390/app122413020 - Falade, P. (2023). Decoding the threat landscape: ChatGPT, FraudGPT, and WormGPT in social engineering attacks. IJSRCSEIT, 9(5), 185–198. DOI: 10.32628/CSEIT2390533
- Girinoto, D. F. P., Yulita, T., Muhammad, A., Rifqi, A. F., & Putri, A. S. (2022, October). OmeTV pretexting phishing attacks: A case study of social engineering. In 2022 7th International Workshop on Big Data and Information Security (IWBIS), 119–124.
IEEE . DOI: 10.1109/IWBIS56557.2022.9924801 - Haggard, S., & Lindsay, J. R. (2015). North Korea and the Sony hack: Exporting instability through cyberspace. JSTOR, 117.
- Hathaway, M., & Klimburg, A. (2012).
Preliminary considerations: on national cyber security . National Cyber Security Framework Manual. NATO Cooperative Cyber Defence Centre of Excellence, Tallinn. - Hoofnagle, C. J., Sloot, B. V. D., & Borgesius, F. Z. (2019). The European Union general data protection regulation: what it is and what it means. Information & Communications Technology Law, 28(1), 65–98. DOI: 10.1080/13600834.2019.1573501
- Irani, D., Balduzzi, M., Balzarotti, D., Kirda, E., & Pu, C. (2011). Reverse social engineering attacks in online social networks. Detection of Intrusions and Malware, and Vulnerability Assessment. Lecture Notes in computer Science, 6739, 55–74. DOI: 10.1007/978-3-642-22424-9_4
- Ismail, K. A., Singh, M. M., Mustaffa, N., Keikhosrokiani, P., & Zulkefli, Z. (2017). Security strategies for hindering watering hole cyber crime attack. Procedia Computer Science, 124, 656–663. DOI: 10.1016/j.procs.2017.12.202
- Jain, A. K., & Gupta, B. B. (2021). A survey of phishing attack techniques, defense mechanisms and open research challenges. Enterprise Information Systems, 16(4), 1–39. DOI: 10.1080/17517575.2021.1896786
- Jakala, M., & Pekkola, S. (2007). From technology engineering to social engineering. ACM SIGMIS Database: The DATABASE for Advances in Information Systems, 38(4), 11–16. DOI: 10.1145/1314234.1314238
- John, S., Ravichandran, N., & Khan, M. F. (2018). Electronic medical record for deliverance of effective healthcare delivery: Ethical issues and challenges of digitalization in clinical information and electronic medical records (EMR) management. IOSR Journal of Business and Management, 20(3), 106–112. DOI: 10.9790/487X-2003020106
- Kamruzzaman, A., Thakur, K., Ismat, S., Ali, M. L., Huang, K., & Thakur, H. N. (2023, March 1). Social engineering incidents and preventions. 2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC), 0494–0498. DOI: 10.1109/CCWC57344.2023.10099202
- Kathiravan, M., Rajasekar, V., Parvez, S. J., Durga, V. S., Meenakshi, M., & Gowsalya, S. (2023, February). Detecting Phishing websites using Machine Learning Algorithm. In 2023 7th International Conference on Computing Methodologies and Communication. DOI: 10.1109/ICCMC56507.2023.10083999
- Kekulluoglu, D., Magdy, W., & Vaniea, K. (2020, July). Analysing privacy leakage of life events on twitter. Proceedings of the 12th ACM Conference on Web Science, 287–294. DOI: 10.1145/3394231.3397919
- Kiesow Cortez, E. (2020). Data Breaches and GDPR. The Palgrave Handbook of International Cybercrime and Cyberdeviance, 239–256. DOI: 10.1007/978-3-319-78440-3_39
- Krombholz, K., Hobel, H., Huber, M., & Weippl, E. (2015). Advanced social engineering attacks. Journal of Information Security and Applications, 22(1), 113–122. DOI: 10.1016/j.jisa.2014.09.005
- Kwak, Y., Lee, S., Damiano, A., & Vishwanath, A. (2020). Why do users not report spear phishing emails? Telematics and Informatics, 48,
101343 . DOI: 10.1016/j.tele.2020.101343 - Li, G., Zhou, X., & Cao, L. (2021). AI Meets Database: AI4DB and DB4 AI. Proceedings of the 2021 International Conference on Management of Data. DOI: 10.1145/3448016.3457542
- Mehta, A., Vora, D., & Sachala, H. (2021). A review of social engineering attacks and their mitigation solutions. International Journal of Engineering Research & Technology, 10(10).
- Mitnick, K. D., & Simon, W. L. (2003). The art of deception: controlling the human element of security. New York; Chichester: Wiley.
- Montanez, R., Atyabi, A., & Xu, S. (2022). Social engineering attacks and defenses in the physical world vs. cyberspace: a contrast study. Cybersecurity and Cognitive Science, 3–41. DOI: 10.1016/B978-0-323-90570-1.00012-7
- Morse, E. A., Raval, V., & Wingender, J. R. (2011). Market price effects of data security breaches. Information Security Journal: A Global Perspective, 20(6), 263–273. DOI: 10.1080/19393555.2011.611860
- Neto, N. N., Madnick, S., Paula, A. M. G. D., & Borges, N. M. (2021). Developing a global data breach database and the challenges encountered. Journal of Data and Information Quality, 13(1), 1–33. DOI: 10.1145/3439873
- Novak, A. N., & Vilceanu, M. O. (2019). “The internet is not pleased”: Twitter and the 2017 Equifax data breach. The Communication Review, 22(3), 196–221. DOI: 10.1080/10714421.2019.1651595
- Orlando, A. (2021). Cyber risk quantification: Investigating the role of cyber value at risk. Risks, 9(10),
184 . DOI: 10.3390/risks9100184 - Paganini, P. (2020, March 31). Holy Water targets religious figures and charities in Asia. Security Affairs.
https://securityaffairs.com/100818/hacking/holy-water-watering-hole-attacks.html - Patrick, H., van Niekerk, B., & Fields, Z. (2019). Developing cybersecurity resilience in the provincial government. Cyber Law, Privacy, and Security: Concepts, Methodologies, Tools, and Applications, 870–897. DOI: 10.4018/978-1-5225-8897-9.ch041
- Perera, S., Jin, X., Maurushat, A., & Opoku, D.-G. J. (2022). Factors affecting reputational damage to organisations due to cyberattacks. Informatics, 9(1),
28 . DOI: 10.3390/informatics9010028 - Pitman, L., & Crosier, W. (2024). On the scale from ransomware to cyberterrorism: the cases of JBS USA, colonial pipeline and the wiperware attacks against Ukraine. Journal of Cyber Policy, 1–21. DOI: 10.1080/23738871.2024.2377670
- Presthus, W., & Sønslien, K. F. (2021). An analysis of violations and sanctions following the GDPR. International Journal of Information Systems and Project Management, 9(1), 38–53. DOI: 10.12821/ijispm090102
- Prevezianou, M. F. (2021). Beyond ones and zeros: Conceptualizing cyber crises. Risk, Hazards & Crisis in Public Policy, 12(1), 51–72. DOI: 10.1002/rhc3.12204
- Quader, F., & Janeja, V. P. (2021). Insights into organizational security readiness: Lessons learned from cyber-attack case studies. Journal of Cyber security and Privacy, 1(4), 638–659. DOI: 10.3390/jcp1040032
- Roberts, P. (2010, August 26). Thumb drive attack in 2008 compromised classified U.S. networks. Threatpost.
https://threatpost.com/thumb-drive-attack-2008-compromised-classified-us-networks-082610/74385 - Salahdine, F., El Mrabet, Z., & Kaabouch, N. (2021, December). Phishing attacks detection a machine learning-based approach. 2021 IEEE 12th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference, 0250–0255. DOI: 10.1109/UEMCON53757.2021.9666627
- Salahdine, F., & Kaabouch, N. (2019). Social engineering attacks: A survey. Future Internet, 11(4),
89 . DOI: 10.3390/fi11040089 - Shu, X., Tian, K., Ciambrone, A., & Yao, D. (2017). Breaking the target: An analysis of target data breach and lessons learned. ArXiv.org. DOI: 10.48550/arXiv.1701.04940
- Siadati, H., Nguyen, T., Gupta, P., Jakobsson, M., & Memon, N. (2017). Mind your SMSes: Mitigating social engineering in second factor authentication. Computers & Security, 65, 14–28. DOI: 10.1016/j.cose.2016.09.009
- Sicard, S. (2015). North Korean cyber attack on Sony poses tough security questions. National Defense, 99(736), 24–25.
- Smith, M., & Mulrain, G. (2017). Equi-failure: The national security implications of the Equifax hack and a critical proposal for reform. Journal of National Security Law and Policy, 9,
549 . - Soni, S., & Mathew, R. (2020). Database security: Attacks and solutions. Proceeding of the International Conference on Computer Networks, Big Data and IoT (ICCBI-2019) (pp. 917–925).
Springer International Publishing . DOI: 10.1007/978-3-030-43192-1_100 - Sonowal, G., Sharma, A., & Kharb, L. (2021). Spear-phishing emails verification method based on verifiable secret sharing scheme. Journal of Information Assurance & Security, 16(3).
- Thomas, J. E. (2018). Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. International Journal of Business Management, 12(3), 1–23. DOI: 10.5539/ijbm.v13n6p1
- Tulkarm, P. (2021). A survey of social engineering attacks: Detection and prevention tools. Journal of Theoretical and Applied Information Technology, 99(18).
- Vadrevu, P., & Perdisci, R. (2019). What you see is not what you get. Proceedings of the Internet Measurement Conference, 308–321. DOI: 10.1145/3355369.3355600
- Wang, Z., Sun, L., & Zhu, H. (2020). Defining social engineering in cybersecurity. IEEE Access, 8, 85094–85115. DOI: 10.1109/ACCESS.2020.2992807
- Weaver, B. W., Braly, A. M., & Lane, D. M. (2021). Training users to identify phishing emails. Journal of Educational Computing Research, 59(6), 073563312199251. DOI: 10.1177/0735633121992516
DOI: https://doi.org/10.21061/jts.438 | Journal eISSN: 1541-9258
Language: English
Page range: 14 - 29
Submitted on: Feb 10, 2025
Accepted on: Jun 17, 2025
Published on: Jul 4, 2025
Published by: Virginia Tech Publishing
In partnership with: Paradigm Publishing Services
Keywords:
© 2025 Ndubuisi Ukwadinachi, published by Virginia Tech Publishing
This work is licensed under the Creative Commons Attribution 4.0 License.