USENIX Security2026Top-tier venue
Selling the Dream: How Intimate Insiders and Identity-Based Attackers Disrupt Micro-businesses
Nazanin Sabri, Arkaprabha Bhattacharya, Sterling Williams-Ceci, Daniel V. Bailey, Rosanna Bellini
Abstract
Micro-businesses represent the majority of all businesses, and act as vehicles to economic freedom for many at-risk population groups. At the risk of falling behind, many microbusiness owners (MBOs) increasingly adopt platforms as their primary infrastructure, and rely heavily on recruiting friends, families, and even romantic partners for running essential operations. Despite these facts, most prior work has focused on larger corporations and enterprise cybersecurity hygiene, ignoring the cybersecurity risks that such social relationships and changes in visibility introduce.
In this work, we conduct a deep dive into the experiences of MBOs through two complementary analyses: an evaluation of case records of 38 at-risk MBOs subject to insider threats, and semi-structured interviews with 16 MBOs. Our analysis show a combination of restricted access to financial resources and disruption to relationships drove them to take greater risks in recruiting and access control, leaving them more vulnerable to malicious insider attacks. They also shared that their pursuit of market reach frequently led to an unwanted, hypervisible presence, inadvertently providing intimate insiders among other adversaries with further leverage or information needed to cause harm. We conclude by proposing avenues for eCommerce governance that address these risks, focusing on preventing insider harm within these highly visible environments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 32503bd8-cbc9-4ebb-88f8-d5eea0815fe7Builds on26
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh et al.S&P 2021 · 175 citations
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul et al.S&P 2022 · 101 citations
- "At the End of the Day Facebook Does What ItWants": How Users Experience Contesting Algorithmic Content ModerationKristen Vaccaro, Christian Sandvig, Karrie KarahaliosCSCW 2020 · 79 citations
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi et al.CHI 2022 · 77 citations
- "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices OnlineAllison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub et al.USENIX Security 2021 · 75 citations
Related papers
- Security Obstacles and Motivations for Small Businesses from a CISO's PerspectiveFlynn Wolf, Adam J. Aviv, Ravi KuberUSENIX Security 2021 · 18 citations
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 6 citations
- The Mundane Art of Cybersecurity: Living with Insecure IT in Danish Small- and Medium-Sized EnterprisesLaura Kocksch, Torben Elgaard JensenCSCW 2024 · 5 citations
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 10 citations
- Security and Privacy Perspectives of People Living in Shared Home EnvironmentsNandita Pattnaik, Shujun Li, Jason R. C. NurseCSCW 2024 · 9 citations
