Loretta J. Stalans, Eric Chan-Tin, Anna Hart, M. Moran, S. Kennison
{"title":"预测网络钓鱼受害:比较先前受害,认知和情感风格,以及脆弱或保护性电子邮件策略","authors":"Loretta J. Stalans, Eric Chan-Tin, Anna Hart, M. Moran, S. Kennison","doi":"10.1080/15564886.2023.2218369","DOIUrl":null,"url":null,"abstract":"ABSTRACT Phishing victimization is prevalent and results in theft of personal identifiable information (PII) or installing malware to steal PII. Drawing upon social psychological and criminological theories, we conducted a prospective study to assess three groups of predictors to being phished or not: a) prior victimization; b) protective or vulnerable habitual strategies, and c) emotional and cognitive decision-making styles. Students (N = 236) completed a survey assessing these predictors and then about 4 weeks later received a phishing e-mail using the university’s phishing testing system. The e-mail requested that they click on a link and enter their student ID to avoid having their account blocked. About half (50.8%) clicked on the link, and 81.6% of those phished entered their PII. Individuals who had low avoidant style and high generalized anxiety were four times more likely to be phished, after controlling for the significant effects of vulnerable habitual strategies and using dating apps. Machine learning analyses also found cognitive styles and generalized anxiety are the better predictors of getting phished compared to vulnerable and protective strategies and prior victimization. These findings suggest that cybersecurity training needs to be expanded to address the emotional and cognitive processing of deceptive appeals in e-mails.","PeriodicalId":47085,"journal":{"name":"Victims & Offenders","volume":"25 1","pages":"1216 - 1235"},"PeriodicalIF":1.4000,"publicationDate":"2023-06-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Predicting Phishing Victimization: Comparing Prior Victimization, Cognitive, and Emotional Styles, and Vulnerable or Protective E-mail Strategies\",\"authors\":\"Loretta J. Stalans, Eric Chan-Tin, Anna Hart, M. Moran, S. Kennison\",\"doi\":\"10.1080/15564886.2023.2218369\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"ABSTRACT Phishing victimization is prevalent and results in theft of personal identifiable information (PII) or installing malware to steal PII. Drawing upon social psychological and criminological theories, we conducted a prospective study to assess three groups of predictors to being phished or not: a) prior victimization; b) protective or vulnerable habitual strategies, and c) emotional and cognitive decision-making styles. Students (N = 236) completed a survey assessing these predictors and then about 4 weeks later received a phishing e-mail using the university’s phishing testing system. The e-mail requested that they click on a link and enter their student ID to avoid having their account blocked. About half (50.8%) clicked on the link, and 81.6% of those phished entered their PII. Individuals who had low avoidant style and high generalized anxiety were four times more likely to be phished, after controlling for the significant effects of vulnerable habitual strategies and using dating apps. Machine learning analyses also found cognitive styles and generalized anxiety are the better predictors of getting phished compared to vulnerable and protective strategies and prior victimization. These findings suggest that cybersecurity training needs to be expanded to address the emotional and cognitive processing of deceptive appeals in e-mails.\",\"PeriodicalId\":47085,\"journal\":{\"name\":\"Victims & Offenders\",\"volume\":\"25 1\",\"pages\":\"1216 - 1235\"},\"PeriodicalIF\":1.4000,\"publicationDate\":\"2023-06-02\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Victims & Offenders\",\"FirstCategoryId\":\"90\",\"ListUrlMain\":\"https://doi.org/10.1080/15564886.2023.2218369\",\"RegionNum\":3,\"RegionCategory\":\"社会学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"CRIMINOLOGY & PENOLOGY\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Victims & Offenders","FirstCategoryId":"90","ListUrlMain":"https://doi.org/10.1080/15564886.2023.2218369","RegionNum":3,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"CRIMINOLOGY & PENOLOGY","Score":null,"Total":0}
Predicting Phishing Victimization: Comparing Prior Victimization, Cognitive, and Emotional Styles, and Vulnerable or Protective E-mail Strategies
ABSTRACT Phishing victimization is prevalent and results in theft of personal identifiable information (PII) or installing malware to steal PII. Drawing upon social psychological and criminological theories, we conducted a prospective study to assess three groups of predictors to being phished or not: a) prior victimization; b) protective or vulnerable habitual strategies, and c) emotional and cognitive decision-making styles. Students (N = 236) completed a survey assessing these predictors and then about 4 weeks later received a phishing e-mail using the university’s phishing testing system. The e-mail requested that they click on a link and enter their student ID to avoid having their account blocked. About half (50.8%) clicked on the link, and 81.6% of those phished entered their PII. Individuals who had low avoidant style and high generalized anxiety were four times more likely to be phished, after controlling for the significant effects of vulnerable habitual strategies and using dating apps. Machine learning analyses also found cognitive styles and generalized anxiety are the better predictors of getting phished compared to vulnerable and protective strategies and prior victimization. These findings suggest that cybersecurity training needs to be expanded to address the emotional and cognitive processing of deceptive appeals in e-mails.
期刊介绍:
Victims & Offenders is a peer-reviewed journal that provides an interdisciplinary and international forum for the dissemination of new research, policies, and practices related to both victimization and offending throughout the life course. Our aim is to provide an opportunity for researchers -- both in the United States and internationally -- from a wide range of disciplines (criminal justice, psychology, sociology, political science, economics, public health, and social work) to publish articles that examine issues from a variety of perspectives in a unique, interdisciplinary forum. We are interested in both quantitative and qualitative research, systematic, evidence-based reviews, and articles that focus on theory development related to offenders and victims.