The Influence of Human Factors on the Intention to Report Phishing Emails

Ioana Andreea Marin, Pavlo Burda, Luca Allodi, Nicola Zannone

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

16 Citations (Scopus)
13 Downloads (Pure)

Abstract

Phishing attacks are a main threat to organizations and individuals. Current widespread defenses based on spam filters and domain blacklisting are unfortunately insufficient. Prior work identifies phishing reporting as a key, largely untapped resource to mitigate phishing threats. Yet, its practice suffers from very low reporting rates and generally too low an uptake from users. Whereas it is known that phishing reporting behavior is affected by a number of 'human factors', a comprehensive view of the different theories and their effects on (intent to) report is not yet developed. To address this gap, we evaluate theories and factors analyzed in the extant literature, build a cohesive theoretical view of their effects and constructs, and develop, model, and empirically evaluate (by means of an online questionnaire, n=284) the resulting hypothesis structure. We discuss both theoretical implications of our findings and research directions for practice at a research and organizational level.

Original languageEnglish
Title of host publicationCHI '23
Subtitle of host publicationProceedings of the 2023 CHI Conference on Human Factors in Computing Systems
EditorsAlbrecht Schmidt, Kaisa Väänänen, Tesh Goyal, Per Ola Kristensson, Anicia Peters, Stefanie Mueller, Julie R. Williamson, Max L. Wilson
Place of PublicationNew York
PublisherAssociation for Computing Machinery, Inc
Number of pages18
ISBN (Electronic)978-1-4503-9421-5
DOIs
Publication statusPublished - 19 Apr 2023
Event2023 Conference on Human Factors in Computing Systems, CHI 2023 - Hamburg, Germany
Duration: 23 Apr 202328 Apr 2023
https://chi2023.acm.org

Conference

Conference2023 Conference on Human Factors in Computing Systems, CHI 2023
Abbreviated titleCHI 2023
Country/TerritoryGermany
CityHamburg
Period23/04/2328/04/23
Internet address

Funding

This work is supported by the ITEA3 programme through the DEFRAUDIfy project funded by Rijksdienst voor Ondernemend Nederland (grant no. ITEA191010) and by the INTERSCT project, Grant No. NWA.1162.18.301, funded by Netherlands Organisation for Scientifc Research (NWO).

FundersFunder number
Rijksdienst voor Ondernemend NederlandITEA191010
Rijksdienst voor Ondernemend Nederland
Nederlandse Organisatie voor Wetenschappelijk Onderzoek

    Keywords

    • Cyber security behaviors
    • Information Security
    • Organizational citizenship behaviors
    • Personality traits

    Fingerprint

    Dive into the research topics of 'The Influence of Human Factors on the Intention to Report Phishing Emails'. Together they form a unique fingerprint.

    Cite this