IMPACT OF PHISHING AND SOCIAL ENGINEERING ATTACKS ON DIGITAL FINANCIAL SERVICES IN NIGERIA
Keywords:
Cybersecurity awareness, digital competence, security behavior, cyber threats, digital safety, Nigeria.Abstract
The increasing adoption of digital financial services in Nigeria has heightened concerns about phishing and social engineering attacks, which pose significant risks to users and the wider digital financial ecosystem. This study examined the influence of cybersecurity awareness, digital competence, and security behavior on users’ exposure and susceptibility to phishing and social engineering attacks in Nigeria’s digital financial services sector. Primary data were collected using a structured questionnaire and analyzed through Cronbach’s Alpha, Pearson Product Moment Correlation, and Multiple Regression techniques. The reliability analysis showed acceptable internal consistency across the study constructs, with security behavior recording the highest reliability. Correlation results revealed a weak but statistically significant positive relationship between cybersecurity awareness and users’ exposure and susceptibility to attacks (r = 0.131, p = 0.049). Digital competence showed a weak positive but statistically insignificant relationship (r = 0.123, p = 0.066), while security behavior demonstrated the strongest weak positive and statistically significant relationship (r = 0.178, p = 0.007). Multiple regression analysis indicated that the three predictors jointly had a statistically significant influence on users’ exposure and susceptibility (F = 3.084, p = 0.028). However, the model explained only 4% of the variance (R² = 0.040), suggesting that other behavioral, technological, and contextual factors contribute to vulnerability. The study recommends strengthening cybersecurity awareness, practical digital security education, safe online practices, and complementary institutional and technological safeguards to reduce users’ vulnerability and improve the security of Nigeria’s digital financial services ecosystem.