Probing into the efforts in establishing trust over relationship commitment: the case of pretexting a social engineering attack
DOI:
https://doi.org/10.51247/8wys1v42Keywords:
pretexting,, social engineering, trust, attack cycleAbstract
Social engineering represents one of the main threats to information security, exploiting psychological and behavioral factors to gain access to confidential data. Among its forms, the pretext attack stands out for its deliberate construction of credible scenarios designed to build trust and persuade victims to reveal sensitive information. The objective of this study was to analyze the influence of trust-building efforts through pretext and their relationship to the vulnerability of Information Systems and Technology students at the University of KwaZulu-Natal (UKZN) to this type of attack. The research adopted a quantitative approach, with a non-experimental, explanatory design, using a survey to collect data from Information Systems and Technology students. The data obtained were analyzed using statistical procedures to evaluate the relationship between communication quality, persuasive efforts, trust, relational commitment, and susceptibility to pretext attacks. The results showed that communication quality did not have a statistically significant influence on participants' trust. In contrast, persuasive efforts significantly increased trust, strengthening commitment in relationships and increasing vulnerability to social engineering attacks based on pretexts. It is concluded that persuasive mechanisms are a determining factor in the effectiveness of pretexts, highlighting the need to strengthen security awareness training and develop skills to identify social manipulation strategies
Downloads
References
Abdullah, Z., & Musa, R. (2014). The effect of trust and information sharing on relationship commitment in supply chain management. Procedia-Social and Behavioral Sciences, 130, 266-272.
Adams, J. S., & Freedman, S. (1976). Equity theory revisited: Comments and annotated bibliography. In Advances in experimental social psychology (Vol. 9, pp. 43-90). Elsevier.
Adu, E. O., Ojo, O., & Adu, K. O. (2019). Evaluation of South Africa University Lecturers Accessibility and Utilization of E-Learning Infrastructure for Teaching. EdMedia+ Innovate Learning,
Aiden, M. K., Chhabra, S., Sabharwal, S. M., & Hameed, A. A. (2025). Social Engineering Attacks: Detection and Prevention. Emerging Threats and Countermeasures in Cybersecurity, 349-387.
Alabdan, R. (2020). Phishing attacks survey: Types, vectors, and technical approaches. Future Internet, 12(10), 168.
Albladi, S. M., & Weir, G. R. (2018). User characteristics that influence judgment of social engineering attacks in social networks. Human-centric Computing and Information Sciences, 8(1), 5.
Aliyu, M., Abdallah, N. A., Lasisi, N. A., Diyar, D., & Zeki, A. M. (2010). Computer security and ethics awareness among IIUM students: An empirical study. Proceeding of the 3rd International Conference on Information and Communication Technology for the Moslem World (ICT4M) 2010,
Alseadoon, I. M. A. (2014). The impact of users' characteristics on their ability to detect phishing emails Queensland University of Technology].
Ball, D., Coelho, P. S., & Machás, A. (2004). The role of communication and trust in explaining customer loyalty. European journal of marketing.
Benavides-Astudillo, E., Silva-Ordoñez, L., Rocohano-Rámos, R., Fuertes, W., Fernández-Peña, F., Sanchez-Gordon, S., & Bastidas-Chalan, R. (2021). Analysis of Vulnerabilities Associated with Social Engineering Attacks Based on User Behavior. International Conference on Applied Technologies,
Bhattacherjee, A., & Sanford, C. (2006). Influence processes for information technology acceptance: An elaboration likelihood model. MIS quarterly, 805-825.
Broadhurst, R., Skinner, K., Sifniotis, N., Matamoros-Macias, B., & Ipsen, Y. (2018). Phishing and Cybercrime Risks in a University Student Community. Available at SSRN 3176319.
Bryman, A., & Bell, E. (2011). Business Research Methods.
Butavicius, M., Parsons, K., Pattinson, M., & McCormac, A. (2016). Breaching the human firewall: Social engineering in phishing and spear-phishing emails. arXiv preprint arXiv:1606.00887.
Chandarman, R., & Van Niekerk, B. (2017). Students' cybersecurity awareness at a private tertiary educational institution. African Journal of Information and Communication, 20, 133-155.
Conteh, N. Y. (2021). The dynamics of social engineering and cybercrime in the digital age. In Ethical Hacking Techniques and Countermeasures for Cybercrime Prevention (pp. 144-149). IGI Global.
Cropanzano, R., Anthony, E. L., Daniels, S. R., & Hall, A. V. (2017). Social exchange theory: A critical review with theoretical remedies. Academy of Management Annals, 11(1), 479-516.
Daniel, W. W., & Cross, C. L. (2018). Biostatistics: a foundation for analysis in the health sciences. Wiley.
Garcia, T. A., Fairlie, A. M., Litt, D. M., Waldron, K. A., & Lewis, M. A. (2018). Perceived vulnerability moderates the relations between the use of protective behavioral strategies and alcohol use and consequences among high-risk young adults. Addictive behaviors, 81, 150-156.
Hameed, M. A., & Arachchilage, N. A. G. (2019). On the Impact of Perceived Vulnerability in the Adoption of Information Systems Security Innovations. arXiv preprint arXiv:1904.08229.
Hargie, O. (2016). Skilled interpersonal communication: Research, theory and practice. Routledge.
Huo, B., Zhang, C., & Zhao, X. (2015). The effect of IT and relationship commitment on supply chain coordination: A contingency and configuration approach. Information & management, 52(6), 728-740.
Information & Communication Services. (2019). Phishing and spam awareness. University of KwaZulu-Natal. Retrieved 13 February from https://ics.ukzn.ac.za/wp-content/uploads/2018/03/Phishing_4.pdf
Jeong, M., & Oh, H. (2017). Business-to-business social exchange relationship beyond trust and commitment. International Journal of Hospitality Management, 65, 115-124.
Krejcie, R. V., & Morgan, D. W. (1970). Determining sample size for research activities. Educational and psychological measurement, 30(3), 607-610.
Lord, N. (2020). Social engineering attacks: Common techniques & how to prevent an attack. Digital Gurdian.
MacFarland, T. W., & Yates, J. M. (2016). Mann–whitney u test. In Introduction to nonparametric statistics for the biological sciences using R (pp. 103-132). Springer.
Mitnick, K. D., & Simon, W. L. (2003). The art of deception: Controlling the human element of security. John Wiley & Sons.
Mouton, F., Leenen, L., & Venter, H. S. (2016). Social engineering attack examples, templates and scenarios. Computers & Security, 59, 186-209.
Mouton, F., Malan, M. M., Leenen, L., & Venter, H. S. (2014). Social engineering attack framework. 2014 Information Security for South Africa,
Muslah Albladi, S., & Weir, G. R. (2019). A conceptual model to predict social engineering victims.
Ofusori, L. O., & Subramaniam, P. R. (2021). The Influence of Technical and Social Factors in Mitigating Threats in a BYOD-Enabled Environment. International Journal of Information Systems in the Service Sector (IJISSS), 13(1), 1-30.
Perrin, A., & Duggan, M. (2015). Americans’ Internet access: 2000--2015. Retrieved 28 June from http://www.pewinternet.org/2015/06/26/americans-internet-access-2000-2015/
Redmond, M. V. (2015). Social exchange theory.
Rege, A., Williams, K., & Mendlein, A. (2019). A social engineering course project for undergraduate students across multiple disciplines. 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security),
Roy, A. B. (2025). A Review of Understanding the Social Engineering in the Context of Cybersecurity. Unveiling Social Dynamics and Community Interaction in the Metaverse, 357-388.
Sharma, S., Avasthi, A., Kapoor, S. K., Keswani, B., Gupta, S., & Goyal, N. K. (2026). Psychological Dimensions of Social Engineering in Cybercrime. In Cyber Forensic Frameworks for User-Centric Human Threat Intelligence Analysis (pp. 119-148). IGI Global Scientific Publishing.
Stergiou, D. (2013). Social Engineering and Influence: A Study that Examines Kevin Mitnick’s Attacks through Robert Cialdini’s Influence Principles. In.
Tavakol, M., & Dennick, R. (2011). Making sense of Cronbach's alpha. International journal of medical education, 2, 53.
Tian, C., Jensen, M. L., & Durcikova, A. (2018). Phishing Susceptibility across Industries: The Differential Impact of Influence Techniques. Proceedings of the 13th Pre-ICIS Workshop on Information Security and Privacy,
Walker, L. E. (2016). Deception of Phishing: Studying the Techniques of Social Engineering by Analyzing Modern-day Phishing Attacks on Universities.
Zulkurnain, A. U., Hamidy, A., Husain, A. B., & Chizari, H. (2015). Social engineering attack mitigation. Int. J. Math. Comput. Sci, 1(4), 188198.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Lizzy Ofusori, Prabhakar Rontalal-Subramaniam

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.














