Research, however, indicates that people
perform poorly on detecting lies and deception (Qin and
Burgoon, 2007; Marett et al., 2004). The infamous attacks of
Kevin Mitnick (Mitnick and Simon, 2002) showed how devastating
sophisticated social engineering attacks are for the information
security of both companies and governmental
organizations. When social engineering is discussed in the
information and computer security field, it is usually by way of
examples and stories (such as Mitnick's)