The Evolution of Social Engineering Attacks: A Cybersecurity Engineering Perspective

Hussein Jassim Akeiber · Al Rafidain Journal of Engineering Sciences · 2025

Social engineering attacks have become one of the most sophisticated threats for modern cybersecurity, where social engineering itself is the best weapon for attackers. This is different from the conventional methods of cyber-attacks such as software and hardware through which the attackers deceived people and took their precious information through manipulation. From a cybersecurity engineering point of view, this paper presents the historical evolution, current trends, and implication of social engineering attacks. Various attack methods are examined: from phishing, vishing, baiting, pretexting to the tailgating, all them is analyzed in the context of their ability to bypass the security measure. It makes clear where the cybercriminals take advantage of technological advances like artificial intelligence (AI) these days, as well as deepfake technology to increase the precision and scalability of social engineering campaigns. AI driven reconnaissance tools helps attackers tailor their messages towards victors online behavior, enabling more deceptive try and more convincing. The study also assesses the consequences and impacts of social engineering attacks on the organizations by looking at possibilities of financial losses and reputation damage, among other things. In addition, this paper has detailed mitigation strategies; these include employee-training programs, multi factor authentication (MFA), email-filtering technologies and AI based threat detection systems. Case studies such as the Google and Facebook financial fraud scheme will show you how even well secured business are still susceptible to the social engineering tactics. Out of the findings numerous are there which urges for a multi layered approach towards the cybersecurity – both technological and human aspect. Recent studies with the rapid technology advancement suggest that cybersecurity experts collaborating with psychologists are urged to create more resilient defense systems against social engineering for a better resilience against cyber threats. Knowing what psychological manipulation techniques attackers use in order to attack is how organizations can proactively implement security by reducing the chance of a breach caused by human error.

Read the paper · More papers on PaperTik