Social Engineering in the Shadow of COVID-19: A Deep Dive into Pandemic-Era Cyber Threats
A Multivocal Literature Review on Growing Social Engineering Based Cyber-Attacks/Threats During the COVID-19 Pandemic: Challenges and Prospective Solutions
This paper presents a Multivocal Literature Review (MLR) on the surge of social engineering (SE) cyber-attacks during the COVID-19 pandemic. It synthesizes 52 studies from formal and grey literature to identify core attack vectors like phishing (35%) and socio-technical methods, concluding that healthcare infrastructure became a primary target for ransomware and trojans.
TL;DR
The COVID-19 pandemic did more than disrupt global health; it provided the perfect "hook" for cybercriminals. This Multivocal Literature Review (MLR) reveals a massive shift toward socio-technical attacks, where psychological manipulation meets technical exploitation. With phishing (35%) and ransomware leading the charge, the study highlights how hospitals and remote workers became the frontline of a new digital war.
The Human Firewall is Breached
The core insight of this research is that humans remain the "weakest link" in the cybersecurity chain. While companies spend billions on firewalls, attackers found a simpler way in: exploiting fear and urgency. The sudden transition to remote work removed the safety net of corporate internal networks, leaving employees vulnerable to home-network exploits and sophisticated "corona-themed" scams.
Methodology: Bridging Academia and Industry
One of the paper's strengths is its Multivocal approach. Cybersecurity moves faster than the academic peer-review cycle. By including Grey Literature (white papers from firms like McAfee, Microsoft, and Interpol), the authors captured real-time data that traditional reviews might miss.
Figure 1: The Social Engineering Lifecycle - from Information Gathering to Post-Exploitation.
Key Findings: The Anatomy of a Pandemic Attack
The review categorized the threats into several critical dimensions:
- Techniques: Phishing reigned supreme (35%), followed by spam (16%) and scams (14%).
- Platforms: Email is the most dangerous vector (52 studies), but fake mobile apps and "Zoom-bombing" on teleconferencing tools emerged as significant new threats.
- Payloads: Ransomware was the weapon of choice for financial gain, with families like MAZE and Netwalker targeting the medical sector specifically.
Figure 2: Distribution of Social Engineering techniques used during the pandemic.
The Economic Toll
The numbers are staggering. Cyber breaches increased by 67% over the last five years. During the pandemic, the University of California San Francisco (UCSF) paid $1.14 million to recover data, while localized shopping scams in the UK cost victims over £17 million.
Figure 3: Detailed taxonomy of ransomware, trojans, and bots deployed during 2020.
Looking Ahead: Prospective Solutions
The authors don't just list problems; they propose a technological roadmap for resilience:
- AI and Machine Learning: Moving beyond static filters to behavioral analysis of zero-day threats.
- Blockchain: Using decentralized ledgers to secure medical IoT devices, ensuring that healthcare data cannot be easily altered or held hostage.
- Big Data Analytics: Correlating historical attack patterns to forecast and preempt future social engineering campaigns.
Conclusion
This paper serves as a critical reminder that cybersecurity is as much about psychology as it is about code. As we move into a permanent hybrid-work era, the recommendation is clear: technical defenses must be paired with continuous "human-centric" training and emerging tech like AI to close the gap that social engineers so effectively exploit.
Limitations: The study is limited to English-language sources and is heavily weighted toward the initial 2020 outbreak period. Future research should examine the "long-tail" of these attacks as they evolve into more targeted spear-phishing campaigns.
