[Paper Review] Why People Still Fall for Phishing Emails: An Empirical Investigation into How Users Make Email Response Decisions
This study investigates why users still fall for phishing emails by analyzing their email response decision-making through a think-aloud experiment and grounded theory. It proposes a theoretical model identifying emotional, habitual, and cognitive factors that drive unsafe responses—such as replying or clicking links—and offers actionable insights for improving anti-phishing training and tools to prioritize secure response behaviors over mere legitimacy judgment.
Despite technical and non-technical countermeasures, humans continue to be tricked by phishing emails. How users make email response decisions is a missing piece in the puzzle to identifying why people still fall for phishing emails. We conducted an empirical study using a think-aloud method to investigate how people make 'response decisions' while reading emails. The grounded theory analysis of the in-depth qualitative data has enabled us to identify different elements of email users' decision-making that influence their email response decisions. Furthermore, we developed a theoretical model that explains how people could be driven to respond to emails based on the identified elements of users' email decision-making processes and the relationships uncovered from the data. The findings provide deeper insights into phishing email susceptibility due to people's email response decision-making behavior. We also discuss the implications of our findings for designers and researchers working in anti-phishing training, education, and awareness interventions
Motivation & Objective
- To understand the underlying decision-making processes users employ when responding to emails, especially in the context of phishing.
- To identify specific psychological and behavioral factors—such as emotions, habits, and validation techniques—that influence users’ susceptibility to phishing attacks.
- To address the gap in existing research by moving beyond personality and demographics to examine the actual cognitive and emotional processes behind email response decisions.
- To develop a theoretically grounded model explaining how these decision-making elements interact and drive unsafe responses.
- To inform the design of more effective anti-phishing education, training, and awareness interventions based on empirical insights into user behavior.
Proposed method
- Conducted a think-aloud role-play experiment with participants reading and responding to simulated phishing and legitimate emails.
- Collected qualitative data through in-depth interviews and real-time verbalizations during email evaluation tasks.
- Applied grounded theory analysis to identify recurring themes, patterns, and relationships in users’ decision-making processes.
- Developed a theoretical model based on emergent categories and their interrelationships, such as emotions, habits, and validation behaviors.
- Validated findings through iterative analysis and triangulation with prior literature on phishing detection and user behavior.
- Proposed design implications and enhancements for anti-phishing tools and training based on identified decision-making flaws.

Experimental results
Research questions
- RQ1What psychological and behavioral factors influence users’ decisions to respond to phishing emails?
- RQ2How do emotions such as anxiety or excitement affect users’ intentions to reply, click, or download from suspicious emails?
- RQ3What role do personal habits and self-learned detection strategies play in increasing or decreasing phishing susceptibility?
- RQ4How do users validate sender legitimacy, and what are the flaws in their validation techniques?
- RQ5What are the key decision-making elements that attackers can exploit to manipulate user responses?
Key findings
- Users are significantly influenced by emotions such as anxiety about work relationships or excitement, which can override rational judgment and increase the likelihood of responding to phishing emails.
- Many users rely on flawed or self-learned detection strategies—such as trusting outdated logos or misinterpreting reply-to addresses—that lead to unsafe responses despite awareness.
- Personal habits, including habitual checking of emails or automatic reply behaviors, increase the risk of responding to malicious content without critical evaluation.
- Users often fail to distinguish between sender address and reply-to address, leading to trust in fraudulent communication channels.
- Theoretical modeling revealed that emotional states and cognitive shortcuts can positively reinforce unsafe response behaviors, even when users believe they are being cautious.
- Many users lack effective validation techniques for organizational logos and URLs, often relying on superficial cues or internet searches that can be manipulated by attackers.

Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.