Research / Studies

Studies

Peer-reviewed research and foundational works, each summarized in plain English and tagged to PsySec principles, tactics, and the belief chain.

Filters (2 active)
Clear filters

5 studies match your filters

Download these as CSV

SupportsField experiment · 2024

Devising and Detecting Phishing Emails Using Large Language Models

Click-through was 19-28% for generic control phishing, 30-44% for GPT-4 generated emails, 69-79% for emails designed by hand using the V-Triad cognitive-bias rules, and 43-81% for GPT-4 combined with the V-Triad. Large language models were also fairly good at detecting phishing intent, sometimes beating humans, and cut attacker costs.

SupportsField experiment · 2024

Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects

Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.

SupportsQualitative · 2023

"I didn't click": What users say when reporting phishing

People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.

SupportsQualitative · 2020

How Experts Detect Phishing Scam Emails

Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.

SupportsLab experiment · 2018

Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility

Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.