Experience in Social Engineering by eCommerce Platforms in Kenya

Mwasambo, Lawrence and Moturi, Christopher (2016) Experience in Social Engineering by eCommerce Platforms in Kenya. British Journal of Applied Science & Technology, 18 (2). pp. 1-12. ISSN 22310843

[thumbnail of Mwasambo1822016BJAST30312.pdf] Text
Mwasambo1822016BJAST30312.pdf - Published Version

Download (175kB)

Abstract

eCommerce systems have been targeted by cyber criminals as they receive and use the money, rely on technology, outsourced services and use of payment technologies like mobile money and online banking channels to carry out their day-to-day transactions. This study sought to investigate social engineering and its mitigation in eCommerce platforms in Kenya. An existing Social Engineering Defensive Framework was adopted and its dimensions were used to create questionnaires and interview guides. The study used 30 out of the 34 pure-play eCommerce firms operating in Nairobi, Kenya. The results indicate that phishing/spear phishing as the leading threat followed by baiting/Trojan Horse, social media/fraudulent websites, search engine poisoning among others. Mitigation measures indicate organizations need to regularly check their website listing in hacking sites (such as pastebin.com and ghostbin.com) and periodically document and update new policies regarding social engineering and information security. This paper proposes social engineering mitigation best practices, emphasizing the need for organizations using the derived best practices and incorporating security culture.

Item Type: Article
Subjects: Journal Eprints > Multidisciplinary
Depositing User: Managing Editor
Date Deposited: 01 Jun 2023 06:31
Last Modified: 11 Jan 2024 04:22
URI: http://repository.journal4submission.com/id/eprint/2146

Actions (login required)

View Item
View Item