Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital
Jan Tolsdorf, David Langer, Luigi Lo Iacono
摘要
Phishing attacks via email remain a major entry point for security and privacy breaches in hospitals. In the European Union, faced with both regulatory pressure to act and limited resources for cybersecurity, hospitals may resort to minimal-effort, off-the-shelf anti-phishing interventions such as warning banners in enterprise email systems. However, their effectiveness remains uncertain, particularly given the highly diverse workforce comprising medical, nursing, functional, administrative, IT, and other staff groups. We conducted a large-scale phishing simulation at a German university hospital, targeting 7,044 email accounts, to analyze how phishing susceptibility varies across staff groups, how email characteristics---such as timing, tone, context, and persuasive framing---influence susceptibility, and how 11 common in-situ anti-phishing interventions affect risky staff behavior. We found that susceptibility but also intervention effectiveness differed markedly across staff groups. Even a small number of phishing emails posed a substantial risk that persisted for about three days. The most effective interventions involved robust technical detection, including spam filtering and in-email phishing warnings. Friction-based measures, such as disabling links and active warning pages, showed mixed but promising effects. In contrast, display name suppression and the widely used method of generic [EXTERNAL] email tagging had no or inconsistent effects. Surveys revealed that some staff reacted with fear, shame, guilt, and hostility, highlighting the ethical challenges of such simulations. Our findings provide actionable guidance for phishing resilience in healthcare and similarly complex organizations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper8
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 被引用 100 次
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 被引用 94 次
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen 等CCS 2024 · 被引用 9 次
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 被引用 7 次
相关 Paper
- The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentXiaowei Chen, Margault Sacré, Gabriele Lenzini, Samuel Greiff 等CHI 2024 · 被引用 21 次
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong 等S&P 2025
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 等CSCW 2023 · 被引用 11 次
- Employees' Attitudes towards Phishing Simulations: "It's like when a child reaches onto the hot hob"Katharina Schiller, Florian Adamsky, Christian Eichenmüller, Matthias Reimert 等CCS 2024 · 被引用 5 次
- Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish ScaleAndrew T. Rozema, James C. DavisWWW 2026 · 被引用 1 次
