Individual processing of phishing emails: how attention and elaboration protect against phishing

Brynne Harrison, Elena Svetieva, Arun Vishwanath*

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

78 Citations (Scopus)

Abstract

Purpose - The purpose of this paper is to explore user susceptibility to phishing by unpacking the mechanisms that may influence individual victimization. The focus is on the characteristics of the e-mail message, users' knowledge and experience with phishing, and the manner in which these interact and influence how users cognitively process phishing e-mails. Design/methodology/approach - A field experiment was conducted where 194 subjects were exposed to a real phishing attack. The experimenters manipulated the contents of the message and measures of user traits and user processing were obtained after the phishing attack. Findings - Of the original list of targets, 47 percent divulged their private information to a bogus form page. Phishing susceptibility was predicted by a particular combination of both low attention to the e-mail elements and high elaboration of the phishing message. The presence of a threat or reward-based phishing message did not affect these processes, nor did it affect subsequent phishing susceptibility. Finally, individual factors such as knowledge and experience with e-mail increased resilience to the phishing attack. Research limitations/implications - The findings are generalizable to students who are a particularly vulnerable target of phishing attacks. Practical implications - The results presented in this study provide pragmatic recommendations for developing user-centered interventions to thwart phishing attacks. Lastly the authors suggest more effective educational efforts to protect individuals from such online fraud. Originality/value - This study provides novel insight into why phishing is successful, the human factor in susceptibility to online deception as well the role of information processing in effective decision making in this context. Based on the findings, the authors dispel common misconceptions about phishing and discuss more effective educational efforts to protect individuals from such online fraud.
Original languageEnglish
Pages (from-to)265-281
Number of pages17
JournalOnline Information Review
Volume40
Issue number2
DOIs
Publication statusPublished - 11 Apr 2016

Keywords

  • Experimental study
  • Online cognitive processing
  • Online deception
  • Phishing

Fingerprint

Dive into the research topics of 'Individual processing of phishing emails: how attention and elaboration protect against phishing'. Together they form a unique fingerprint.

Cite this