How Experts Detect Phishing Scam Emails
Rick Wash
Abstract
Phishing scam emails are emails that pretend to be something they are not in order to get the recipient of the email to undertake some action they normally would not. While technical protections against phishing reduce the number of phishing emails received, they are not perfect and phishing remains one of the largest sources of security risk in technology and communication systems. To better understand the cognitive process that end users can use to identify phishing messages, I interviewed 21 IT experts about instances where they successfully identified emails as phishing in their own inboxes. IT experts naturally follow a three-stage process for identifying phishing emails. In the first stage, the email recipient tries to make sense of the email, and understand how it relates to other things in their life. As they do this, they notice discrepancies: little things that are "off'' about the email. As the recipient notices more discrepancies, they feel a need for an alternative explanation for the email. At some point, some feature of the email --- usually, the presence of a link requesting an action --- triggers them to recognize that phishing is a possible alternative explanation. At this point, they become suspicious (stage two) and investigate the email by looking for technical details that can conclusively identify the email as phishing. Once they find such information, then they move to stage three and deal with the email by deleting it or reporting it. I discuss ways this process can fail, and implications for improving training of end users about phishing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 00cb67b0-3faf-43eb-97da-62b847717243Cited by top-tier papers7
- I Don't Need an Expert! Making URL Phishing Features Human ComprehensibleKholoud Althobaiti, Nicole Meng, Kami VanieaCHI 2021 · 32 citations
- "Auntie, Please Don't Fall for Those Smooth Talkers": How Chinese Younger Family Members Safeguard Seniors from Online FraudYue Deng, Changyang He, Yixin Zou, Bo LiCHI 2025 · 11 citations
- It's Trying Too Hard To Look Real: Deepfake Moderation Mistakes and Identity-Based BiasJaron Mink, Miranda Wei, Collins W. Munyendo, Kurt Hugenberg et al.CHI 2024 · 10 citations
- Assessing Suspicious Emails with Banner Warnings Among Blind and Low-Vision Users in Realistic SettingsFilipo Sharevski, Aziz ZeidiehUSENIX Security 2024 · 7 citations
- It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationLorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier et al.CHI 2025 · 5 citations
Related papers
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das et al.CSCW 2023 · 11 citations
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 100 citations
- Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current PracticesAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das et al.CHI 2023 · 12 citations
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 94 citations
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen et al.CCS 2024 · 9 citations
