Kiran Barakoti, Krishna Kumar Rai, Raj Kumar Thakur, Sagar Sitaula, Drona Prasad Acharya and Gopal Ghimire
Social engineering attacks are not limited to technical vulnerabilities, but happen through human judgment, trust and common digital actions. The study analyzes reported exposure, awareness of cybersecurity, protective practices and selected impacts for students, working adults, small business owners, and elderly respondents in Nepal. A mixed methodology was used, which included a structured survey of 100 respondents and analysis of documented cyber-fraud and social-engineering cases. The survey data was analyzed using descriptive statistics, cross-tabulation, chi-square test of independence and logistic regression, and the case material was analyzed thematically. Phishing emails were the most common type of attack reported, followed by impersonation scams and fraudulent calls. There were also differences among the four groups in terms of awareness and reported exposures. The study finds that there is a significant disconnect between what participants knew about cybersecurity and the protective behaviors they actually practice: less were using multi-factor authentication or changing their passwords regularly than were aware of or suspicious of. The results suggest that Nepal's cybersecurity programs need to focus more on hands-on verification practices, contextual training, organizational security measures, and safer digital payment habits.
Social Engineering; Phishing; Cybersecurity Awareness; Human Factors; Protective Behavior;