A Routine Activities Approach to Evidence-Based Risk Assessment: Findings From Two Simulated Phishing Attacks

Howell, CJ (通讯作者),Univ Texas El Paso, 500 W Univ Ave, El Paso, TX 79968 USA.
2023-2
To assess the efficacy of routine activity theory (RAT) for explaining phishing victimization and guide evidence-based policy, we launched two phishing attacks via a university Listserv (N = 25,875). The first email offered access to a pdf file; the second offered free concert tickets. Several interesting findings emerged demonstrating phishing victimization results from network users' routine behaviors. Students were significantly less likely to open the phishing email sharing a pdf but more likely to open the email offering free concert tickets. Moreover, students were more likely to click the malicious link embedded within the phishing email in both studies, often using mobile devices. Conversely, employees were more likely to click the link while connected to the university network, thus exposing the network to greater levels of risk. Finally, the email offering concert tickets was opened at a frequency more than double the email containing the pdf. Theoretical and policy implications are discussed.
SOCIAL SCIENCE COMPUTER REVIEW
卷号:41|期号:1|页码:286-304
ISSN:0894-4393|收录类别:SCIE
语种
英语
来源机构
University System of Georgia; Georgia State University; University of Texas System; University of Texas El Paso; University System of Georgia; Georgia State University; University System of Georgia; Georgia State University; Hebrew University of Jerusalem
资助信息
The authors disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: This research was conducted with support from the Israeli Ministry of Science, Technology and Space (grant no. 3-10888) and the National Science Foundation (grant no. 1343430).
被引频次(WOS)
0
被引频次(其他)
0
180天使用计数
2
2013以来使用计数
9
EISSN
1552-8286
出版年
2023-2
DOI
10.1177/08944393211046339
学科领域
循证社会科学-综合
关键词
information security phishing risk assessment routine activity theory victimization
资助机构
Israeli Ministry of Science, Technology and Space(Ministry of Science, Technology and Space (MOST), Israel) National Science Foundation(National Science Foundation (NSF))
WOS学科分类
Computer Science, Interdisciplinary Applications Information Science & Library Science Social Sciences, Interdisciplinary