The Psychology of Deception: How Facebook Attackers Build "Credible" Profiles
Measuring Source Credibility of Social Engineering Attackers on Facebook
This study proposes a comprehensive 24-item measurement scale to evaluate the source credibility of social engineering attackers on Facebook. By identifying four critical dimensions—Perceived Sincerity, Competence, Attraction, and Worthiness—the researchers establish a robust framework for predicting an individual's susceptibility to deceptive online requests.
TL;DR
In the battle against social engineering, the attacker's most potent weapon isn't a zero-day exploit, but their source credibility. This paper identifies four pillars—Sincerity, Competence, Attraction, and Worthiness—that allow attackers to bypass our intuition. By validating a new 24-item measurement scale, the authors provide a scientific roadmap for predicting who will fall for a "friend's" malicious link.
The Motivation: Why We Click Even When We Shouldn't
Traditional cybersecurity focuses on the "What"—the malicious link or the phishing email. However, social engineering is inherently about the "Who." Despite years of awareness training, users continue to fall for attacks on Facebook. The authors argue this is because credibility is context-dependent. A profile that looks "expert" in a professional setting might fail on Facebook, where Sincerity (trustworthiness) and Worthiness (what's in it for me?) carry more weight.
Methodology: Deciphering the Attacker's Persona
The researchers moved beyond simple surveys, utilizing a Between-Method Triangulation (interviews and observations) to map out how users actually perceive strangers online.
The Four Dimensions of Malicious Credibility
- Perceived Sincerity: Does the profile look "real"? Users check for common friends, account activity, and the use of real names over nicknames.
- Perceived Competence: Is the source authoritative? Wealth, qualifications, or celebrity status can blind users to risk.
- Perceived Attraction: Visual aesthetics and "good writing" create a halo effect, making attractive attackers seem more trustworthy.
- Perceived Worthiness (The New Frontier): This is the degree to which a user feels interaction will benefit them. Factors like authority (a boss), sexual compatibility, or reciprocity (they "liked" your photo first) drive this dimension.

The Fractional Factorial Experiment
To test these dimensions, the authors used a Fractional Factorial Design to create 20 synthetic Facebook profiles. This allowed them to meticulously control variables—making a profile "wealthy but insincere" or "attractive but incompetent"—to see exactly which trait triggered a click on a malicious request.
Experimental Results: Sincerity is King
The experiment involved 120 participants and 2,400 observations. The results were striking:
- Sincerity (β=0.48) is the single most important factor. If an attacker's profile feels authentic and "safe," victims are nearly twice as likely to comply with a request compared to other traits.
- Worthiness (β=0.31) proved to be a critical unique find. We are highly susceptible to those we perceive as "useful" or "obligated to," such as social authorities or potential romantic interests.

Deep Insight: Beyond Technical Defenses
This study highlights a major gap in modern security: System-level trust. Users often trust a person simply because the "system" (Facebook) suggested them as a friend. Attackers exploit this psychological shortcut.
The introduction of Perceived Worthiness is particularly insightful. It explains why "Likejacking" or "Who viewed your profile" scams work; they play on the user's desire for reciprocity and social standing.
Conclusion & Future Outlook
The validated 24-item scale provides a rigorous tool for future researchers to measure "vulnerability surface area" in human networks. While the study used role-play scenarios due to ethical constraints, the high correlation between perceived credibility and susceptibility to social engineering (SE) suggests that these findings are highly applicable to real-world defense.
Takeaway: To stop social engineering, we must train users to audit the Sincerity and Worthiness of the requester, not just the technical markers of the request.

