Skip to main content
QUICK REVIEW

[Paper Review] Why People Still Fall for Phishing Emails: An Empirical Investigation into How Users Make Email Response Decisions

Asangi Jayatilaka, Nalin Asanka Gamagedara Arachchilage|arXiv (Cornell University)|Jan 24, 2024
Personal Information Management and User BehaviorDecision Sciences3 citations
TL;DR

This study investigates why users still fall for phishing emails by analyzing their email response decision-making through a think-aloud experiment and grounded theory. It proposes a theoretical model identifying emotional, habitual, and cognitive factors that drive unsafe responses—such as replying or clicking links—and offers actionable insights for improving anti-phishing training and tools to prioritize secure response behaviors over mere legitimacy judgment.

ABSTRACT

Despite technical and non-technical countermeasures, humans continue to be tricked by phishing emails. How users make email response decisions is a missing piece in the puzzle to identifying why people still fall for phishing emails. We conducted an empirical study using a think-aloud method to investigate how people make 'response decisions' while reading emails. The grounded theory analysis of the in-depth qualitative data has enabled us to identify different elements of email users' decision-making that influence their email response decisions. Furthermore, we developed a theoretical model that explains how people could be driven to respond to emails based on the identified elements of users' email decision-making processes and the relationships uncovered from the data. The findings provide deeper insights into phishing email susceptibility due to people's email response decision-making behavior. We also discuss the implications of our findings for designers and researchers working in anti-phishing training, education, and awareness interventions

Motivation & Objective

  • To understand the underlying decision-making processes users employ when responding to emails, especially in the context of phishing.
  • To identify specific psychological and behavioral factors—such as emotions, habits, and validation techniques—that influence users’ susceptibility to phishing attacks.
  • To address the gap in existing research by moving beyond personality and demographics to examine the actual cognitive and emotional processes behind email response decisions.
  • To develop a theoretically grounded model explaining how these decision-making elements interact and drive unsafe responses.
  • To inform the design of more effective anti-phishing education, training, and awareness interventions based on empirical insights into user behavior.

Proposed method

  • Conducted a think-aloud role-play experiment with participants reading and responding to simulated phishing and legitimate emails.
  • Collected qualitative data through in-depth interviews and real-time verbalizations during email evaluation tasks.
  • Applied grounded theory analysis to identify recurring themes, patterns, and relationships in users’ decision-making processes.
  • Developed a theoretical model based on emergent categories and their interrelationships, such as emotions, habits, and validation behaviors.
  • Validated findings through iterative analysis and triangulation with prior literature on phishing detection and user behavior.
  • Proposed design implications and enhancements for anti-phishing tools and training based on identified decision-making flaws.
Figure 1: Simulated web email client
Figure 1: Simulated web email client

Experimental results

Research questions

  • RQ1What psychological and behavioral factors influence users’ decisions to respond to phishing emails?
  • RQ2How do emotions such as anxiety or excitement affect users’ intentions to reply, click, or download from suspicious emails?
  • RQ3What role do personal habits and self-learned detection strategies play in increasing or decreasing phishing susceptibility?
  • RQ4How do users validate sender legitimacy, and what are the flaws in their validation techniques?
  • RQ5What are the key decision-making elements that attackers can exploit to manipulate user responses?

Key findings

  • Users are significantly influenced by emotions such as anxiety about work relationships or excitement, which can override rational judgment and increase the likelihood of responding to phishing emails.
  • Many users rely on flawed or self-learned detection strategies—such as trusting outdated logos or misinterpreting reply-to addresses—that lead to unsafe responses despite awareness.
  • Personal habits, including habitual checking of emails or automatic reply behaviors, increase the risk of responding to malicious content without critical evaluation.
  • Users often fail to distinguish between sender address and reply-to address, leading to trust in fraudulent communication channels.
  • Theoretical modeling revealed that emotional states and cognitive shortcuts can positively reinforce unsafe response behaviors, even when users believe they are being cautious.
  • Many users lack effective validation techniques for organizational logos and URLs, often relying on superficial cues or internet searches that can be manipulated by attackers.
Figure 2: The number of unique concepts for each participant
Figure 2: The number of unique concepts for each participant

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.