Studies
20 studies · CSV
- Phishing reporting in organizations: What motivates employees to take action? Burda et al. (2025). Information & Computer Security The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
- Devising and Detecting Phishing Emails Using Large Language Models Heiding et al. (2024). IEEE Access, 12 Click-through was 19-28% for generic control phishing, 30-44% for GPT-4 generated emails, 69-79% for emails designed by hand using the V-Triad cognitive-bias rules, and 43-81% for GPT-4 combined with the V-Triad. Large language models were also fairly good at detecting phishing intent, sometimes beating humans, and cut attacker costs.
- Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects Heiding et al. (2024). arXiv:2412.00586 Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.
- "I didn't click": What users say when reporting phishing Pilavakis et al. (2023). Proceedings 2023 Symposium on Usable Security (USEC 2023) People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.
- Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study Jacobs et al. (2023). HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer Science Government security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.
- An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al. (2020). Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020) After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
- How Experts Detect Phishing Scam Emails Wash (2020). Proceedings of the ACM on Human-Computer Interaction (CSCW) Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.
- Moving from a ‘human-as-problem” to a ‘human-as-solution” cybersecurity mindset Zimmermann & Renaud (2019). International Journal of Human-Computer Studies, 131, 169-187 A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.
- Predicting susceptibility to social influence in phishing emails Parsons et al. (2019). International Journal of Human-Computer Studies In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.
- Exploring susceptibility to phishing in the workplace Williams et al. (2018). International Journal of Human-Computer Studies Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.
- Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility Vishwanath et al. (2018). Communication Research, 45(8), 1146-1166 Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.
- Tuning Out Security Warnings: A Longitudinal Examination of Habituation Through fMRI, Eye Tracking, and Field Experiments Vance et al. (2018). MIS Quarterly, 42(2), 355-380 Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.
- Who Provides Phishing Training? Facts, Stories, and People Like Me Wash & Cooper (2018). Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.
- Security Fatigue Stanton et al. (2016). IT Professional, 18(5) Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.
- Cyber Security Awareness Campaigns: Why do they fail to change behaviour? Bada et al. (2015). International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019) Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.
- Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security Kirlappos et al. (2014). Workshop on Usable Security (USEC 2014) Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.
- Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations Siponen & Vance (2010). MIS Quarterly, 34(3), 487-502 Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
- So long, and no thanks for the externalities: the rational rejection of security advice by users Herley (2009). Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09) Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
- The compliance budget: managing security behaviour in organisations Beautement et al. (2008). Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08) Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.
- Users are not the enemy Adams & Sasse (1999). Communications of the ACM, 42(12) Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.