Phishing in an academic community: A study of user susceptibility and behavior

dc.contributor.authorAlejandra Diaz
dc.contributor.authorAlan T. Sherman
dc.contributor.authorAnupam Joshi
dc.coverage.spatialBolivia
dc.date.accessioned2026-03-22T20:41:46Z
dc.date.available2026-03-22T20:41:46Z
dc.date.issued2019
dc.descriptionCitaciones: 9
dc.description.abstractWe present an observational study on the relationship between demographic factors and phishing susceptibility at the University of Maryland, Baltimore County (UMBC). In spring 2018, we delivered phishing attacks to 450 randomly selected students on three different days (1,350 students total) to examine user click rates and demographics among UMBC’s undergraduates. Participants were initially unaware of the study. We deployed the billing problem, contest winner, and expiration date phishing tactics. Experiment 1 impersonated banking authorities; Experiment 2 enticed users with monetary rewards; and Experiment 3 threatened users with account cancelation. We found correlations resulting in lowered susceptibility based on college affiliation, academic year progression, cyber training, involvement in cyber clubs or cyber scholarship programs, time spent on the computer, and age demographics. We found no significant correlation between gender and susceptibility. Contrary to our expectations, we observed a reverse correlation between phishing awareness and student resistance to clicking. Students who identified themselves as understanding the definition of phishing had a higher susceptibility rate than did their peers who were merely aware of phishing attacks, with both groups having a higher susceptibility rate than those with no knowledge whatsoever. Approximately 70% of survey respondents who opened a phishing email clicked on it, with 60% of student having clicked overall.
dc.identifier.doi10.1080/01611194.2019.1623343
dc.identifier.urihttps://doi.org/10.1080/01611194.2019.1623343
dc.identifier.urihttps://andeanlibrary.org/handle/123456789/83531
dc.language.isoen
dc.publisherTaylor & Francis
dc.relation.ispartofCryptologia
dc.sourceHigher University of San Andrés
dc.subjectPhishing
dc.subjectDemographics
dc.subjectObservational study
dc.subjectInternet privacy
dc.subjectPsychology
dc.subjectScholarship
dc.subjectWorld Wide Web
dc.titlePhishing in an academic community: A study of user susceptibility and behavior
dc.typepreprint

Files