Unrealistic Promises and Urgent Wording Differently Affect Suspicion of Phishing and Legitimate Emails

McKenna K. Tornblad, Miriam E. Armstrong, Keith S. Jones, Akbar Siami Namin · Proceedings of the Human Factors and Ergonomics Society Annual Meeting · 2021

Phishing emails have certain characteristics, including wording related to urgency and unrealistic promises (i.e., “too good to be true”), that attempt to lure victims. To test whether these characteristics affected users’ suspiciousness of emails, users participated in a phishing judgment task in which we manipulated 1) email type (legitimate, phishing), 2) consequence amount (small, medium, large), 3) consequence type (gain, loss), and 4) urgency (present, absent). We predicted users would be most suspicious of phishing emails that were urgent and offered large gains. Results supporting the hypotheses indicate that users were more suspicious of phishing emails with a gain consequence type or large consequence amount. However, urgency was not a significant predictor of suspiciousness for phishing emails, but was for legitimate emails. These results have important cybersecurity-related implications for penetration testing and user training.

Read the paper · More papers on PaperTik