The unpredictability of phishing susceptibility: results from a repeated measures experiment
Teodor Sommestad, Henrik Karlzén · Journal of Cybersecurity · 2024
Abstract Phishing attacks via email remain a popular and cost-effective alternative for attackers looking to penetrate computer networks. A number of experiments suggest that a person’s susceptibility to this type of deception depends on the phishing email. In field experiments, three variables found to be important are: the scam represented in the email, to what extent the email has been adapted to recipient, and to what extent influence techniques are used. These variables have intricate interdependencies, and the overall scam of the message often constrains how the message can be adapted using influence techniques. In this study, a multilevel model is used. Scam is added cluster variable, and the other two are added as predictor variables. Thus, variations in the overall scam are controlled for before the effect impact of adaptations and use of influence techniques is estimated. In total, 2294 emails were sent to 102 participants and it is measured if they click links provided in emails (N = 1953) or run executables referenced in emails (N = 2199). The results show that the difference in scam in the message results in 6% variance in susceptibility to phishing links, and 3% variance in susceptibility to executing code. When controlling for the scam, no robust relationships were found between the remaining variables and phishing susceptibility. It is discussed if previous research has overestimated the impact of adaptation and influence techniques, e.g. because of the interdependency between the variables and the scam.