Cybersecurity Capstone • Threat Intelligence & Information Sharing

Social engineering is evolving. Awareness must evolve too.

Cybercriminals adapt to new technology and human behavior—moving beyond traditional phishing into text messages, voice calls, AI-assisted impersonation, social-media targeting, fake search results, and QR-code scams. This interactive hub shows how the tactics change and how people can recognize them sooner.

Prepared by Sunshray Devunuri ss.devunuri@gmail.com (816) 603-0005
Why this matters

Human behavior remains a major target.

Technical defenses matter, but attackers often try to persuade a person to click, respond, trust, pay, sign in, or reveal information. The research behind this project shows why training and updated threat awareness are necessary.

60%

of breaches in Verizon's 2025 research involved some type of human element.

40%

higher reported success rate for mobile-focused social engineering than traditional email phishing in the cited 2026 Verizon research.

$2.1B

reported consumer losses to scams that started on social media in 2025, according to the cited FTC data.

Threat evolution

How the attacks keep changing

The pattern is consistent: when users learn one warning sign, attackers shift the channel, improve the realism, or use personal information to make the message more believable.

FOUNDATION

1. Traditional phishing

Email messages try to persuade users to reveal credentials, open harmful content, or take an unsafe action.

Why it works: urgency, authority, fear, curiosity, or convenience.
CHANNEL SHIFT

2. Texts & voice calls

Attackers move to phones because people may react faster to messages, calls, and alerts they see as immediate.

Adaptation: the attack follows the user to a more personal device.
AI-ASSISTED

3. AI voice & realistic messages

Artificial intelligence can make impersonation and phishing content more convincing and harder to recognize at a glance.

Adaptation: fewer obvious writing or authenticity clues.
PERSONALIZATION

4. Social-media targeting

Publicly shared details can help scammers create messages that feel personal, relevant, or trustworthy.

Adaptation: attackers use context about the target.
DISCOVERY ABUSE

5. Fake search advertisements

Fraudulent ads can direct users to websites designed to look like legitimate companies or government services.

Adaptation: the victim may start the search, making the result feel safer.
PHYSICAL + DIGITAL

6. QR-code scams

A QR code can hide the destination until after it is scanned, creating another path to fake websites, information requests, or malicious downloads.

Adaptation: a familiar convenience tool becomes the lure.
Interactive awareness training

Can you spot the warning sign?

These are fictional, safe training examples inspired by the types of tactics described in the research. Choose the strongest reason each message should be treated cautiously.

Scenario 1

Unexpected account warning

Innovative solution

Turn threat intelligence into a learning loop.

The capstone's central solution is not just “be careful.” It is to continually collect reliable warnings, translate them into simple examples, share them quickly, practice recognition, and update the training when tactics change.

01

Discover

Watch trusted agencies and security organizations for new scam tactics and alerts.

02

Verify

Confirm the information with reliable sources before spreading an alert.

03

Translate

Turn technical reports into clear warning signs that students, families, and employees understand.

04

Practice

Use short simulations, quizzes, and realistic examples to build recognition skills.

05

Update

Replace outdated examples as attackers change channels, technology, and impersonation methods.

Why this is stronger than one-time training

Attack methods change. A continuously updated awareness hub can keep lessons tied to current scam patterns and can make threat-sharing useful to everyday users, not only security professionals.

Prevention

A simple verification mindset

The goal is to create a short routine people can remember even when a message feels urgent or convincing.

1
Slow down when urgency appears.Pressure can be a social-engineering tactic. Give yourself time to verify.
2
Verify through a separate channel.Use a known official website, saved contact, or trusted method instead of relying only on the message.
3
Inspect requests, not just appearance.A polished email, familiar voice, or realistic website is not proof that the request is legitimate.
4
Be cautious with links, downloads, payments, and sensitive information.These are common actions attackers try to trigger.
5
Treat unexpected QR codes carefully.Pause before scanning and verify why the code was sent or placed there.
6
Report suspicious activity.Clear reporting procedures help organizations learn from attempts and warn others sooner.