"To click or not to click is the question": Fraudulent URL identification accuracy in a community sample
Ed Pearson, Cindy L. Bethel, Andrew F. Jarosz, Mitchell E. Berman · 2017
Technology is in a constant state of evolution, which allows for new and cunning cyber-attacks and tactics. Out of all these tactics, the exploitation of human cognitive biases in response to phishing attacks is challenging to defend against. The purpose of this study was to determine if humans could discriminate fraudulent Uniform Resource Locators (URLs) or links from legitimate URLs without the aid of specific hardware or software. We also explored whether simple textual manipulations were easier to detect compared to complex manipulations. Participants (N = 1044) completed the following: (1) A demographic questionnaire including their internet and email usage, (2) a role-playing exercise where participants were shown a series of emails from an inbox and had to select the action(s) that they would take, and (3) a series of questions related to technology and security to assess their prior knowledge and awareness of phishing. Results indicated that it was difficult for participants to correctly identify URLs when checking email. Results also revealed that difficulty in detecting simple textual manipulations versus complex manipulations was category dependent.