{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T02:25:23Z","timestamp":1783995923638,"version":"3.55.0"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2016,6,10]],"date-time":"2016-06-10T00:00:00Z","timestamp":1465516800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2016,6,10]],"date-time":"2016-06-10T00:00:00Z","timestamp":1465516800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Hum. Cent. Comput. Inf. Sci."],"published-print":{"date-parts":[[2016,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Over the last decade, substantial progress has been made in understanding and mitigating phishing attacks. Nonetheless, the percentage of successful attacks is still on the rise. In this article, we critically investigate why that is the case, and seek to contribute to the field by highlighting key factors that influence individuals\u2019 susceptibility to phishing attacks. For our investigation, we conducted a web-based study with 382 participants which focused specifically on identifying factors that help or hinder Internet users in distinguishing phishing pages from legitimate pages. We considered relationships between demographic characteristics of individuals and their ability to correctly detect a phishing attack, as well as time-related factors. Moreover, participants\u2019 cursor movement data was gathered and used to provide additional insight. In summary, our results suggest that: gender and the years of PC usage have a statistically significant impact on the detection rate of phishing; pop-up based attacks have a higher rate of success than the other tested strategies; and, the psychological <jats:italic>anchoring effect<\/jats:italic> can be observed in phishing as well. Given that only 25\u00a0% of our participants attained a detection score of over 75\u00a0%, we conclude that many people are still at a high risk of falling victim to phishing attacks but, that a careful combination of automated tools, training and more effective awareness campaigns, could significantly help towards preventing such attacks.<\/jats:p>","DOI":"10.1186\/s13673-016-0065-2","type":"journal-article","created":{"date-parts":[[2016,5,9]],"date-time":"2016-05-09T13:05:38Z","timestamp":1462799138000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":87,"title":["Baiting the hook: factors impacting susceptibility to phishing attacks"],"prefix":"10.1186","volume":"6","author":[{"given":"Cristian","family":"Iuga","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jason R. C.","family":"Nurse","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Arnau","family":"Erola","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2016,6,10]]},"reference":[{"issue":"1","key":"65_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/2193-7680-3-1","volume":"3","author":"EE Lastdrager","year":"2014","unstructured":"Lastdrager EE (2014) Achieving a consensual definition of phishing based on a systematic review of the literature. Crim Sci 3(1):1\u201310. doi:10.1186\/s40163-014-0009-y","journal-title":"Crim Sci"},{"key":"65_CR2","doi-asserted-by":"publisher","unstructured":"Sheng S, Magnien B, Kumaraguru P, Acquisti A, Cranor LF, Hong J, Nunge E (2007) Anti-phishing phil: the design and evaluation of a game that teaches people not to fall for phish. In: Proceedings of the 3rd symposium on usable privacy and security. ACM, New York, pp 88\u201399. doi:10.1145\/1280680.1280692","DOI":"10.1145\/1280680.1280692"},{"key":"65_CR3","doi-asserted-by":"publisher","unstructured":"Zeydan HZ, Selamat A, Salleh M (2014) Survey of anti-phishing tools with detection capabilities. In: International symposium on biometrics and security technologies (ISBAST), 2014. IEEE, New York, pp 214\u2013219. doi:10.1109\/ISBAST.2014.7013124","DOI":"10.1109\/ISBAST.2014.7013124"},{"issue":"1","key":"65_CR4","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.cose.2006.10.009","volume":"26","author":"RC Dodge","year":"2007","unstructured":"Dodge RC, Carver C, Ferguson AJ (2007) Phishing for user security awareness. Comput Secur 26(1):73\u201380. doi:10.1016\/j.cose.2006.10.009","journal-title":"Comput Secur"},{"key":"65_CR5","doi-asserted-by":"publisher","unstructured":"Furnell S. Still on the hook: the persistent problem of phishing. Comput Fraud Secur (10). doi:10.1016\/S1361-3723(13)70092-7","DOI":"10.1016\/S1361-3723(13)70092-7"},{"key":"65_CR6","doi-asserted-by":"publisher","first-page":"576","DOI":"10.1016\/j.dss.2011.03.002","volume":"3","author":"A Vishwanath","year":"2011","unstructured":"Vishwanath A, Herath T, Chen R, Wang J, Rao HR (2011) Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model. Decis Support Syst 3:576\u2013586. doi:10.1016\/j.dss.2011.03.002","journal-title":"Decis Support Syst"},{"key":"65_CR7","unstructured":"Raywood D (2016) Phishing costs UK \u00a3174 Million in 2015. http:\/\/www.infosecurity-magazine.com\/news\/phishing-costs-uk-174-million-in\/. Accessed 4 Jan 2016"},{"key":"65_CR8","unstructured":"FBI (2014) 2014 Internet crime report. https:\/\/www.fbi.gov\/news\/news_blog\/2014-ic3-annual-report. Accessed 4 Jan 2016"},{"key":"65_CR9","unstructured":"Ponemon Institute (2015) The cost of phishing and value of employee training. http:\/\/www.rsaconference.com\/blogs\/how-much-will-that-phishing-trip-cost-you. Accessed 4 Jan 2016"},{"key":"65_CR10","doi-asserted-by":"publisher","unstructured":"Dhamija R, Tygar JD, Hearst M (2006) Why phishing works. In: Proceedings of the SIGCHI conference on human factors in computing systems. ACM, New York, pp 581\u2013590. doi:10.1145\/1124772.1124861","DOI":"10.1145\/1124772.1124861"},{"key":"65_CR11","doi-asserted-by":"publisher","unstructured":"Downs JS, Holbrook MB, Cranor LF (2006) Decision strategies and susceptibility to phishing. In: Proceedings of the second symposium on usable privacy and security. ACM, New York, pp 79\u201390. doi:10.1145\/1143120.1143131","DOI":"10.1145\/1143120.1143131"},{"key":"65_CR12","unstructured":"Symantec Corporation: A brief history of phishing (2007). http:\/\/www.symantec.com\/connect\/blogs\/brief-history-phishing-part-i. Accessed 4 Jan 2016"},{"issue":"3","key":"65_CR13","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1145\/2730912","volume":"21","author":"JRC Nurse","year":"2015","unstructured":"Nurse JRC (2015) Exploring the risks to identity security and privacy in cyberspace. XRDS Crossroads 21(3):42\u201347. doi:10.1145\/2730912","journal-title":"XRDS Crossroads"},{"key":"65_CR14","unstructured":"BBC (2007) Phishing catches victims 'in minutes'. http:\/\/www.bbc.co.uk\/news\/technology-32285433. Accessed 4 Jan 2016"},{"key":"65_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2015.04.001","volume":"17","author":"RM Mohammad","year":"2015","unstructured":"Mohammad RM, Thabtah F, McCluskey L (2015) Tutorial and critical analysis of phishing websites methods. Comput Sci Rev 17:1\u201324. doi:10.1016\/j.cosrev.2015.04.001","journal-title":"Comput Sci Rev"},{"issue":"6","key":"65_CR16","doi-asserted-by":"publisher","first-page":"584","DOI":"10.1080\/0144929X.2011.632650","volume":"32","author":"K Jansson","year":"2013","unstructured":"Jansson K, von Solms R (2013) Phishing for phishing awareness. Behav Inform Technol 32(6):584\u2013593. doi:10.1080\/0144929X.2011.632650","journal-title":"Behav Inform Technol"},{"key":"65_CR17","doi-asserted-by":"crossref","unstructured":"Canova G, Volkamer M, Bergmann C, Reinheimer B (2015) Nophish app evaluation: lab and retention study. In: NDSS workshop on usable security","DOI":"10.14722\/usec.2015.23009"},{"key":"65_CR18","doi-asserted-by":"publisher","unstructured":"Hale ML, Gamble RF, Gamble P (2015) CyberPhishing: a game-based platform for phishing awareness testing. In: Proceedings of the 48th Hawaii international conference on system sciences (HICSS). IEEE, New York, pp. 5260\u20135269. doi:10.1109\/HICSS.2015.670","DOI":"10.1109\/HICSS.2015.670"},{"key":"65_CR19","unstructured":"Wombat Security Technologies (2016) Anti-Phishing training suite. https:\/\/www.wombatsecurity.com\/suggested-programs\/anti-phishing. Accessed 4 Jan 2016"},{"issue":"2","key":"65_CR20","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1145\/2019599.2019606","volume":"14","author":"G Xiang","year":"2011","unstructured":"Xiang G, Hong J, Rose CP, Cranor L (2011) Cantina+: a feature-rich machine learning framework for detecting phishing web sites. ACM Trans Inform Syst Secur 14(2):21","journal-title":"ACM Trans Inform Syst Secur"},{"key":"65_CR21","doi-asserted-by":"publisher","unstructured":"Miyamoto D, Hazeyama H, Kadobayashi Y (2009) An evaluation of machine learning-based methods for detection of phishing sites. In: Advances in neuro-information processing. Springer, Berlin, pp 539\u2013546. doi:10.1007\/978-3-642-02490-0_66","DOI":"10.1007\/978-3-642-02490-0_66"},{"key":"65_CR22","doi-asserted-by":"publisher","unstructured":"Dhamija R, Tygar JD (2005) The battle against phishing: Dynamic security skins. In: Proceedings of the 2005 symposium on usable privacy and security, ACM, New York, pp 77\u201388. doi:10.1145\/1073001.1073009","DOI":"10.1145\/1073001.1073009"},{"key":"65_CR23","unstructured":"Yahoo! Inc (2016) Yahoo personalized Sign-In seal. https:\/\/protect.login.yahoo.com\/. Accessed 4 Jan 2016"},{"key":"65_CR24","doi-asserted-by":"publisher","unstructured":"Bursztein E, Benko B, Margolis D, Pietraszek T, Archer A, Aquino A, Pitsillidis A, Savage S (2014) Handcrafted fraud and extortion: manual account hijacking in the wild. In: Proceedings of the 2014 conference on internet measurement conference. ACM, New York, pp 347\u2013358. doi:10.1145\/2663716.2663749","DOI":"10.1145\/2663716.2663749"},{"key":"65_CR25","unstructured":"PhishTank (2006) PhishTank | Join the fight against phishing. https:\/\/www.phishtank.com\/. Accessed 4 Jan 2016"},{"issue":"15","key":"65_CR26","doi-asserted-by":"publisher","first-page":"11861","DOI":"10.1016\/j.eswa.2012.02.020","volume":"39","author":"W Han","year":"2012","unstructured":"Han W, Cao Y, Bertino E, Yong J (2012) Using automated individual white-list to protect web digital identities. Expert Syst Appl 39(15):11861\u201311869. doi:10.1016\/j.eswa.2012.02.020","journal-title":"Expert Syst Appl"},{"key":"65_CR27","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1016\/j.ijhcs.2015.05.005","volume":"82","author":"M Alsharnouby","year":"2015","unstructured":"Alsharnouby M, Alaca F, Chiasson S (2015) Why phishing still works: user strategies for combating phishing attacks. Int J Hum Comput Stud 82:69\u201382. doi:10.1016\/j.ijhcs.2015.05.005","journal-title":"Int J Hum Comput Stud"},{"key":"65_CR28","doi-asserted-by":"publisher","unstructured":"Sheng S, Holbrook M, Kumaraguru P, Cranor LF, Downs J (2010) Who falls for phish? A demographic analysis of phishing susceptibility and effectiveness of interventions. In: Proceedings of the SIGCHI conference on human factors in computing systems. ACM, New York, pp 373\u2013382. doi:10.1145\/1753326.1753383","DOI":"10.1145\/1753326.1753383"},{"key":"65_CR29","doi-asserted-by":"publisher","unstructured":"Alseadoon I, Othman M, Chan T (2015) What is the influence of users\u2019 characteristics on their ability to detect phishing emails? Advanced computer and communication engineering technology. Springer International Publishing, Berlin, pp 949\u2013962. doi:10.1007\/978-3-319-07674-4_89","DOI":"10.1007\/978-3-319-07674-4_89"},{"key":"65_CR30","unstructured":"Trustworthy Internet Movement (2015) SSL pulse. https:\/\/www.trustworthyinternet.org\/ssl-pulse\/. Accessed 4 Jan 2016"},{"key":"65_CR31","doi-asserted-by":"publisher","unstructured":"Chen MC, Anderson JR, Sohn MH (2001) What can a mouse cursor tell us more? Correlation of eye\/mouse movements on web browsing. In: Extended abstracts on human factors in computing systems (CHI). ACM, New York, pp 281\u2013282. doi:10.1145\/634067.634234","DOI":"10.1145\/634067.634234"},{"key":"65_CR32","unstructured":"Felt A, Wagner D (2011) Phishing on mobile devices. In: Web 2.0 security and privacy workshop (W2SP)"},{"key":"65_CR33","doi-asserted-by":"publisher","unstructured":"Nurse JRC, Creese S, Goldsmith M, Lamberts K (2011) Trustworthy and effective communication of cybersecurity risks: a review. In: Proceedings of international workshop on socio-technical aspects in security and trust (STAST). IEEE, New York, pp 60\u201368. doi:10.1109\/STAST.2011.6059257","DOI":"10.1109\/STAST.2011.6059257"},{"key":"65_CR34","doi-asserted-by":"publisher","unstructured":"Yang W, Chen J, Xiong A, Proctor RW, Li N (2015) Effectiveness of a phishing warning in field settings. In: Proceedings of the symposium and bootcamp on the science of security. ACM, New York, pp 14\u20131142. doi:10.1145\/2746194.2746208","DOI":"10.1145\/2746194.2746208"},{"key":"65_CR35","doi-asserted-by":"publisher","unstructured":"Zielinska OA, Tembe R, Hong KW, Ge X, Murphy-Hill E, Mayhorn CB (2014) One phish, two phish, how to avoid the internet phish analysis of training strategies to detect phishing emails. In: Proceedings of the human factors and ergonomics society annual meeting, vol 58. SAGE Publications, Thousand Oaks, pp 1466\u20131470. doi:10.1177\/1541931214581306","DOI":"10.1177\/1541931214581306"},{"key":"65_CR36","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1016\/j.chb.2016.02.065","volume":"60","author":"NAG Arachchilage","year":"2016","unstructured":"Arachchilage NAG, Love S, Beznosov K (2016) Phishing threat avoidance behaviour: an empirical investigation. Comput Hum Behav 60:185\u2013197. doi:10.1016\/j.chb.2016.02.065","journal-title":"Comput Hum Behav"},{"key":"65_CR37","doi-asserted-by":"publisher","unstructured":"Nurse JRC, Creese S, Goldsmith M, Lamberts K (2011) Guidelines for usable cybersecurity: past and present. In: Proceedings of the third international workshop on cyberspace safety and security (CSS), IEEE, New York, pp 21\u201326. doi:10.1109\/CSS.2011.6058566","DOI":"10.1109\/CSS.2011.6058566"},{"key":"65_CR38","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1109\/MSP.2010.198","volume":"2","author":"C Bravo-Lillo","year":"2010","unstructured":"Bravo-Lillo C, Cranor LF, Downs J, Komanduri S (2010) Bridging the gap in computer security warnings: a mental model approach. IEEE Secur Priv 2:18\u201326. doi:10.1109\/MSP.2010.198","journal-title":"IEEE Secur Priv"}],"container-title":["Human-centric Computing and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-016-0065-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13673-016-0065-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-016-0065-2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-016-0065-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,30]],"date-time":"2021-07-30T07:46:58Z","timestamp":1627631218000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13673-016-0065-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,6,10]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2016,12]]}},"alternative-id":["65"],"URL":"https:\/\/doi.org\/10.1186\/s13673-016-0065-2","relation":{},"ISSN":["2192-1962"],"issn-type":[{"value":"2192-1962","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,6,10]]},"assertion":[{"value":"27 January 2016","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 May 2016","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 June 2016","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"8"}}