Phishing susceptibility across industries: The differential impact of influence techniques

被引:3
|
作者
Tian, Chuan [1 ]
Jensen, Matthew L. [2 ]
Durcikova, Alexandra [2 ]
机构
[1] Univ Alabama, Culverhouse Coll, Business Sch, Tuscaloosa, AL 35487 USA
[2] Univ Oklahoma, Price Coll Business, Norman, OK 73019 USA
基金
美国国家科学基金会;
关键词
Phishing; Deception; Self-determination theory; Persuasion; Influence techniques; Finance; Organizational characteristics; Organizational Culture; DECISION-MAKING; ORGANIZATIONAL CULTURE; SELF-DETERMINATION; INFLUENCE TACTICS; SOCIAL-INFLUENCE; PERSONALITY; SYSTEMS; RATIONALITY; QUALITY; ATTACKS;
D O I
10.1016/j.cose.2023.103487
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Organizations face an increasing risk of phishing attacks, leading to potential financial losses, privacy breaches, and damage to reputation. While past research has focused on individual and organizational factors in phishing susceptibility, there is a lack of understanding related to industry differences and their impact on the phenomenon. Drawing on existing literature on persuasion and phishing, we propose that shared industry practices, values, and assumptions influence the effectiveness of phishing techniques. To test our hypotheses, we conducted two studies: a lab experiment (n = 259) and a field quasi-experiment (n = 10,967) using a secondary dataset comprising mock phishing attacks on 30 finance and 15 non-finance organizations. The results revealed varying susceptibility to phishing techniques based on industry. Consistent with our expectations, liking-based techniques were more effective among non-finance organizations, while social proof, reciprocity, and authority techniques were more effective in finance organizations. These findings contribute to resolving past inconsistencies in empirical phishing research and provide insights into the role of industry characteristics in shaping phishing susceptibility.
引用
收藏
页数:16
相关论文
共 50 条