Spear phishing in a barrel: Insights from a targeted phishing campaign

A. J. Burns,M. Eric Johnson,Deanna D. Caputo
DOI: https://doi.org/10.1080/10919392.2019.1552745
IF: 2.2368
2019-01-02
Journal of Organizational Computing and Electronic Commerce
Abstract:Executives in many industries have fallen prey to socially engineered attacks known as spear phishing. Using highly targeted emails, social engineers trick victims into performing unintended actions by masquerading as legitimate actors. To shed light on effective spear phishing training, we conducted a multi-round experiment. Our results indicate that training users with individual loss messaging might increase the effectiveness of the training. Additionally, we found potential evidence that organizational training can lead to increased overall spear phishing awareness, even for those not directly trained. Despite these promising results, however, individuals’ susceptibility to highly targeted spear phishing attacks remains troubling for practitioners and researchers.
computer science, information systems, interdisciplinary applications
What problem does this paper attempt to address?