The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception Study
Verena Distler
Abstract
In today’s digitized societies, phishing attacks are a security threat with damaging consequences. Organizations remain vulnerable to phishing attacks, and it is not clear how the work context influences people’s perceptions and behaviors related to phishing attempts. I investigate (1) how contextual factors influence reactions to a spear-phishing attempt, (2) why people report or do not report phishing attempts, (3) which opportunities for security-enhancing interventions people identify. I use an in-situ deception methodology to observe participants (N=14) in their realistic work environment. I triangulate observational and self-reported data to obtain rich qualitative insights into participants’ emotions, thoughts, and actions when receiving a targeted phishing email. I find that task, IT, internal and social context play an important role. The email’s request being aligned with expectations and perceived time pressure when responding to emails were associated with insecure behavior. The social context positively influenced phishing detection, but “phished” participants did not tell anyone.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5e5aa9da-9262-421e-8a25-9eb67ffb8954Cited by top-tier papers6
- The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentXiaowei Chen, Margault Sacré, Gabriele Lenzini, Samuel Greiff et al.CHI 2024 · 21 citations
- Employees' Attitudes towards Phishing Simulations: "It's like when a child reaches onto the hot hob"Katharina Schiller, Florian Adamsky, Christian Eichenmüller, Matthias Reimert et al.CCS 2024 · 5 citations
- Understanding Underground Incentivized Review ServicesRajvardhan Oak, Zubair ShafiqCHI 2024 · 5 citations
- From Harm to Healing: Understanding Individual Resilience after CybercrimesXiaowei Chen, Mindy Tran, Yue Deng, Bhupendra Acharya et al.CHI 2026 · 2 citations
- Experiencer, Helper, or Observer: Online Fraud Intervention for Older Adults Through a Role-based Simulation ApproachYue Deng, Xiaowei Chen, Junxiang Liao, Bo Li et al.CHI 2026 · 1 citation
Related papers
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen et al.CCS 2024 · 9 citations
- The Influence of Human Factors on the Intention to Report Phishing EmailsIoana Andreea Marin, Pavlo Burda, Nicola Zannone, Luca AllodiCHI 2023 · 30 citations
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 7 citations
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das et al.CSCW 2023 · 11 citations
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
