Predicting susceptibility to social influence in phishing emails

Kathryn Parsons,Marcus Butavicius,Paul Delfabbro,Meredith Lillie
DOI: https://doi.org/10.1016/j.ijhcs.2019.02.007
2019-08-01
Abstract:To reduce the threat caused by phishing attacks, it is vital to investigate why some phishing attacks are successful, and why some people are more susceptible to them than others. To examine this, we used a social influence framework, and applied the Susceptibility to Persuasion Strategies scale within a dual-process model of persuasion framework. A total of 985 participants took part in a role-play scenario-based phishing study. Results indicated that phishing emails utilising scarcity and social proof principles were least successful, whereas those applying consistency and reciprocity principles were most successful. The same principles were also considered least and most persuasive according to the Susceptibility to Persuasion Strategies scale. For the majority of principles, participants who were susceptible to a specific principle were significantly more susceptible to emails containing that principle. Further results revealed that age; the percentage of time spent using a computer; susceptibility to the social proof principle; and, both dispositional and situational impulsivity, were significant predictors in people's ability to detect phishing emails. Practical implications of these findings as well as future directions are discussed.
computer science, cybernetics,ergonomics,psychology, multidisciplinary
What problem does this paper attempt to address?