← Latest papers
💻 computer science

Profiling User Vulnerability to Phishing Through Psychological and Behavioral Factors

This study analyzes the Spamley dataset to identify five psychological and behavioral constructs of phishing susceptibility, revealing that a combination of operational maturity, decision-making speed, and cognitive approach—not just technical knowledge—distinguishes vulnerable users and necessitates a shift toward personalized, adaptive cybersecurity training.

Original authors: Valeria Formisano, Danilo Gentile, Gennaro Esposito Mocerino, Michela Ponticorvo, Luigi Gallo, Alessio Botta, Davide Marocco

Published 2026-05-21
📖 4 min read☕ Coffee break read

Original authors: Valeria Formisano, Danilo Gentile, Gennaro Esposito Mocerino, Michela Ponticorvo, Luigi Gallo, Alessio Botta, Davide Marocco

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine your email inbox as a bustling train station. Most of the time, the trains (emails) are legitimate passengers heading to the right destination. But occasionally, a "fake train" disguised as a real one pulls up, hoping to trick you into boarding it and handing over your valuables. This is phishing.

For a long time, cybersecurity experts thought the solution was just building better fences and locks (technology). But this paper argues that the real weak spot isn't the fence; it's the passenger (you). The researchers wanted to figure out: What kind of person is most likely to get on the fake train?

Here is the story of their investigation, broken down simply:

1. The Great Experiment

The researchers gathered a massive group of 1,086 people from all walks of life. They didn't just ask them questions; they put them in a realistic simulation. Imagine a test where you are handed 10 emails that look exactly like real ones you'd get at work or home. Some are safe; some are traps. Your job is to spot the traps.

While you did this, the researchers watched two things:

  • Did you get it right? (Did you spot the fake?)
  • How fast did you decide? (Did you click "safe" or "fake" instantly, or did you pause to think?)

2. The Five "Personality Ingredients"

The researchers realized that being good or bad at spotting fakes isn't about just one thing. They used a statistical "smoothie blender" (called Exploratory Factor Analysis) to mix all the data and found five main ingredients that make up a person's digital personality:

  1. Seniority: How old you are and how much work experience you have.
  2. Expertise: How much you know about computers and tech.
  3. Creativity: This is a tricky one. In this study, it didn't mean "good at art." It meant being open to new ideas, outgoing, and willing to take risks.
  4. Stability: How calm and emotionally steady you are.
  5. Vulnerability: How easily you get swayed by tricks like "Authority" (someone yelling at you) or "Scarcity" (a deal that expires in 5 minutes).

3. The Big Discovery: Speed is the Enemy

The most surprising finding was about time.
The researchers found a direct link between impulsivity and speed.

  • People who admitted they were impulsive (acted without thinking) were the ones who clicked the buttons the fastest.
  • The Rule: The faster you decide, the more likely you are to fall for the scam.
  • The Lesson: Being slow and deliberate is a superpower. Taking a moment to think acts like a shield.

4. The Two Types of Passengers

Using the data, the researchers split everyone into two distinct groups, like sorting passengers into two different waiting rooms:

Group A: The "Aware User" (The Careful Traveler)

  • Who they are: Usually older, with more work experience, and a bit more cautious.
  • How they act: They take their time. They don't rush. They look at the email, think about it, and check the details.
  • Result: They are much better at spotting the fake trains. They only fell for the scam about 22% of the time.

Group B: The "High-Risk User" (The Hasty Traveler)

  • Who they are: This group makes up the majority of people (about 71%). They tend to be younger, have less work experience, and are more "creative" (open, outgoing, and impulsive).
  • How they act: They are fast. They see an email that looks urgent or comes from a boss, and they react immediately without thinking.
  • Result: They are the easiest targets. They fell for the scam about 31% of the time.

5. What This Means for You

The paper concludes that you can't just teach people "tech facts" (like how to spot a bad link) and expect them to be safe. Knowing how to use a computer isn't enough.

The real problem is how we think.

  • If you are the "Hasty Traveler," your brain is wired to act fast and be open to new things, which is great for creativity but dangerous for security.
  • The scammers know this. They use tricks like "Your account will be closed in 1 hour!" to make you panic and stop thinking.

The Bottom Line:
To stay safe, you don't need to be a computer genius. You just need to slow down. If you feel that urge to click immediately because of urgency or fear, that is your brain's "danger signal." The best defense is to pause, take a breath, and think before you act. The paper suggests that future security training shouldn't just be a generic lecture for everyone; it should be tailored to help the "Hasty Travelers" learn how to hit the brakes.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →