To read this content please select one of the options below:

Individual processing of phishing emails: How attention and elaboration protect against phishing

Brynne Harrison (Department of Communication, University of Buffalo, Buffalo, New York, USA)
Elena Svetieva (Catolica-Lisbon School of Business and Economics, Universidade Catolica Portuguesa, Lisbon, Portugal)
Arun Vishwanath (Department of Communication, University at Buffalo - SUNY, Buffalo, New York, USA)

Online Information Review

ISSN: 1468-4527

Article publication date: 11 April 2016

3641

Abstract

Purpose

The purpose of this paper is to explore user susceptibility to phishing by unpacking the mechanisms that may influence individual victimization. The focus is on the characteristics of the e-mail message, users’ knowledge and experience with phishing, and the manner in which these interact and influence how users cognitively process phishing e-mails.

Design/methodology/approach

A field experiment was conducted where 194 subjects were exposed to a real phishing attack. The experimenters manipulated the contents of the message and measures of user traits and user processing were obtained after the phishing attack.

Findings

Of the original list of targets, 47 percent divulged their private information to a bogus form page. Phishing susceptibility was predicted by a particular combination of both low attention to the e-mail elements and high elaboration of the phishing message. The presence of a threat or reward-based phishing message did not affect these processes, nor did it affect subsequent phishing susceptibility. Finally, individual factors such as knowledge and experience with e-mail increased resilience to the phishing attack.

Research limitations/implications

The findings are generalizable to students who are a particularly vulnerable target of phishing attacks.

Practical implications

The results presented in this study provide pragmatic recommendations for developing user-centered interventions to thwart phishing attacks. Lastly the authors suggest more effective educational efforts to protect individuals from such online fraud.

Originality/value

This study provides novel insight into why phishing is successful, the human factor in susceptibility to online deception as well the role of information processing in effective decision making in this context. Based on the findings, the authors dispel common misconceptions about phishing and discuss more effective educational efforts to protect individuals from such online fraud.

Keywords

Citation

Harrison, B., Svetieva, E. and Vishwanath, A. (2016), "Individual processing of phishing emails: How attention and elaboration protect against phishing", Online Information Review, Vol. 40 No. 2, pp. 265-281. https://doi.org/10.1108/OIR-04-2015-0106

Publisher

:

Emerald Group Publishing Limited

Copyright © 2016, Emerald Group Publishing Limited

Related articles