SupportsField experiment · 2024
Heiding et al. — IEEE Access, 12
Click-through was 19-28% for generic control phishing, 30-44% for GPT-4 generated emails, 69-79% for emails designed by hand using the V-Triad cognitive-bias rules, and 43-81% for GPT-4 combined with the V-Triad. Large language models were also fairly good at detecting phishing intent, sometimes beating humans, and cut attacker costs.
SupportsField experiment · 2024
Heiding et al. — arXiv:2412.00586
Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.
SupportsQualitative · 2020
Wash — Proceedings of the ACM on Human-Computer Interaction (CSCW)
Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.
SupportsLab experiment · 2019
Parsons et al. — International Journal of Human-Computer Studies
In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.
SupportsMixed methods · 2018
Vance et al. — MIS Quarterly, 42(2), 355-380
Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.
SupportsMixed methods · 2018
Williams et al. — International Journal of Human-Computer Studies
Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.
SupportsLab experiment · 2018
Vishwanath et al. — Communication Research, 45(8), 1146-1166
Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.
SupportsQualitative · 2016
Stanton et al. — IT Professional, 18(5)
Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.
SupportsConceptual · 2015
Bada et al. — International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019)
Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.
SupportsSurvey · 2010
Siponen & Vance — MIS Quarterly, 34(3), 487-502
Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
SupportsConceptual · 2009
Herley — Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09)
Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
SupportsMixed methods · 1999
Adams & Sasse — Communications of the ACM, 42(12)
Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.
MixedField experiment · 2025
Tolsdorf et al. — Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)
Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.
MixedMixed methods · 2024
Lain et al. — Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)
Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.
MixedSystematic review · 2019
Renaud & Dupuis — Proceedings of the New Security Paradigms Workshop (NSPW '19)
A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.
MixedLarge-scale observational · 2019
Heijden & Allodi — 28th USENIX Security Symposium (USENIX Security 19), pp. 1309-1326
Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.
ChallengesField experiment · 2014
Caputo et al. — IEEE Security & Privacy
Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.
FoundationalQualitative · 2019
Ferreira & Teles — International Journal of Human-Computer Studies
Merging Cialdini, Gragg and Stajano & Wilson into one set of social-engineering persuasion principles, the authors found authority, strong affect, integrity and reciprocation were the most common in phishing subject lines. Strong-affect and authority emails leaned on 'you/your' wording, reciprocation on 'we/us/our'.
FoundationalField experiment · 2010
Lally et al. — European Journal of Social Psychology, 40(6), 998-1009
Repeating a chosen behavior daily in a consistent context made it more automatic along an asymptotic curve. Time to reach 95% of peak automaticity ranged from 18 to 254 days, and missing a single day did not materially derail habit formation.
FoundationalField experiment · 2008
Workman — Journal of the American Society for Information Science and Technology, 59(4), 662-674
Drawing on marketing-persuasion theory, a field study tested whether the factors that make marketing campaigns work also explain who falls for phishing and pretext phone attacks, and found that they do: dispositional factors tied to persuasion predicted victimization.
FoundationalConceptual · 2007
Wood & Neal — Psychological Review, 114(4), 843-863
Habits are learned links between context cues and responses that form through repetition and can then be triggered directly by those cues without the goal that originally drove them. Goals shape habits mainly by motivating the early repetition and by steering people toward cues, rather than by directly activating the habit.
FoundationalLab experiment · 1997
Bechara et al. — Science, 275(5304), 1293-1295
Healthy participants began choosing advantageously and showed anticipatory skin-conductance responses to risky options before they could explain which strategy was best. Patients with prefrontal damage never developed these signals and kept choosing badly even after knowing the right strategy.