Pith. sign in

REVIEW 4 major objections 5 minor 51 references

A Survey on the Principles of Persuasion as a Social Engineering Strategy in Phishing

T0 review · 4 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read Phishing emails built on the six principles of persuasion are more effective than other phishing attacks, and spear phishing is the most effective variant, this survey argues.

desk verdict A useful narrative review of persuasion principles in phishing, with an unsupported comparative-effectiveness conclusion and a 'systematic' label the methods don't back. read the letter →

arxiv 2412.18488 v1 pith:EGIWSX5K submitted 2024-12-24 cs.CR cs.CYcs.HC

classification cs.CRcs.CYcs.HC
keywords phishingsocialengineeringpersuasionprinciplesCialdinispearcybersecurityinfluencetacticssystematicreview
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey paper seeks to establish that the six principles of persuasion -- reciprocation, commitment/consistency, social proof, authority, liking/similarity, and scarcity -- are a core mechanism of phishing, and that phishing attacks using them are more effective than attacks that do not. It concludes that spear phishing, which tailors messages to a specific target, is particularly successful when built on these principles. The paper also maps the current research landscape and identifies a significant gap in understanding how persuasion principles operate in phishing, calling for further study. A careful reader would care because this frames phishing as a psychological exploit rather than purely a technical one, implying that defences should be built around human susceptibility.

What carries the argument

The carrying mechanism is the taxonomy of six principles of persuasion -- reciprocation, commitment/consistency, social proof, authority, liking/similarity, and scarcity -- which the survey uses as a lens to organise the phishing literature. In the surveyed studies these principles function both as a coding scheme for analysing the content of phishing emails and as the independent variable in experiments measuring user susceptibility. The taxonomy connects psychological theory to attack strategy, and the paper also adopts an extended principle list that adds liking, similarity and deception, and distraction. This taxonomy is what lets the survey compare findings across studies and conclude that persuasion cues are what make phishing effective.

What would settle it

A controlled field experiment that sends matched phishing emails to random equivalent groups -- identical except for the presence of a persuasion cue -- would settle the effectiveness claim; if click or credential-entry rates do not differ between cue and no-cue variants, the survey's central conclusion fails. A second test is a protocol-driven systematic search with explicit inclusion criteria and date coverage to see whether the identified gap list and effectiveness conclusion survive a broader corpus.

Watch

Extended reading notes

Core claim

The paper's central claim is that phishing emails applying principles of persuasion are more effective social engineering tactics than other phishing attacks, and that spear phishing -- the targeted form -- is especially effective when these principles are used. This conclusion comes from a review of 50 full-text articles that the authors screened from database searches, covering content analyses of phishing emails, susceptibility experiments, personality-interaction studies, training and awareness interventions, and machine-learning detection work. The review also documents a significant gap in the literature: there is no consensus on which principles are most prevalent or most impactful, and most studies are short-term, university-based, and lack standardized coding of persuasion principles.

Load-bearing premise

The load-bearing premise is that the 50 full-text articles retrieved by a keyword search of Google Scholar, Scopus, and the UC library are a representative and unbiased sample of research on persuasion principles in phishing; if that corpus is skewed, the survey's effectiveness claim and gap list do not generalize.

Editorial extensions

If this is right

  • Phishing emails that apply principles of persuasion are more effective social engineering tactics than phishing attacks that do not use them.
  • Spear phishing is particularly effective when persuasion principles are used, because attackers can tailor messages to a target's characteristics and interests.
  • No consensus exists on which principles are most prevalent or most impactful in phishing emails, so further research is needed.
  • Key gaps include a lack of long-term studies, limited demographic diversity, little work on combinations of principles, and no standardized coding of persuasion principles.
  • Understanding persuasion principles is central to defence: training and awareness that address these cues are key to detecting and eventually eliminating spear phishing.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If persuasion-cue presence predicts phishing success, then detection systems could add a 'persuasion cue load' feature -- counting authority claims, urgent deadlines, and social-proof mentions -- to metadata-based classifiers; this is a testable extension the paper hints at but does not test.
  • The inconsistent rankings of which principle works best across studies may reflect unmeasured moderators (personality, life domain, organizational role) rather than genuine disagreement; reanalysing existing datasets with those moderators could resolve the apparent contradiction.
  • The survey's conclusion implies security awareness training should teach users to recognize influence patterns rather than generic warning signs; a randomised trial comparing cue-based training with conventional phishing training would test this implication.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. The paper is a survey of research on Cialdini's six principles of persuasion in phishing emails. It describes a search of Google Scholar, Scopus, and the UC library using the keyword phrase 'persuasion principles of Cialdini in Cybersecurity,' reports that 50 full-text articles were assessed, and organizes the reviewed work into content analysis, phishing susceptibility, training and awareness, and machine-learning themes. It then lists research gaps and concludes that phishing emails applying persuasion principles are more effective social engineering tactics than other phishing attacks, and that spear phishing is particularly effective when using these techniques.

Significance. A carefully scoped and reproducible review of this literature would be a useful contribution because the primary studies are scattered across venues, use inconsistent coding schemes, and report conflicting results. The paper usefully assembles many of the relevant studies, including those on content analysis (e.g., [2], [10], [35]), susceptibility (e.g., [19], [22], [38]), and machine-learning detection (e.g., [43], [49]), and its gap list is broadly consistent with the literature. However, in its current form the survey's central comparative claim is not supported by the reviewed evidence, and the methodology is not described to a standard that justifies the label 'systematic.' The paper's value is largely descriptive and hypothesis-generating; the conclusions need to be substantially revised before the claims can be accepted.

major comments (4)
  1. [Section VI and Abstract] The statement that phishing emails applying persuasion principles are 'more effective social engineering tactics than other phishing attacks' is not supported by the evidence reported in Section IV. The reviewed studies compare one persuasion principle against another (e.g., Taib et al. [30] vs. Ferreira and Teles [21]; De Bona and Paci [23] compare authority with urgency) or measure susceptibility to persuasion-based emails; the survey reports no comparison between matched phishing emails with and without persuasion principles. Section V itself notes the 'lack of control groups' in the literature. The conclusion should be removed or explicitly reframed as a hypothesis that future controlled studies should test.
  2. [Section III] The methodology does not meet the standards implied by the term 'systematic survey.' The query is given only as 'persuasion principles of Cialdini in Cybersecurity'; there is no date range, no database-specific search string, no screening or PRISMA-style flow diagram, no record of the number of records screened before the 50 full-text articles, and no inter-rater reliability. In addition, the inclusion criterion limiting the search to 'peer-reviewed journal articles and conference presentations' is contradicted by the inclusion of the Master's thesis [2] and the arXiv preprint [19]. Without a reproducible protocol, the corpus on which the gap list and conclusions rest cannot be independently verified, so the generalizability claims are unsupported.
  3. [Section IV, first paragraph] The survey reports directly contradictory findings across studies (Taib et al. [30] finding social proof most effective, while [21] and [31] find authority, consistency, and reciprocity most effective and social proof and scarcity least effective), but it does not attempt a meta-analysis, effect-size comparison, or quality appraisal. Without such synthesis, the later qualitative conclusion that persuasion-principled phishing is 'more effective' than other attacks cannot be derived from this body of work. At minimum, the conclusion should be limited to what the individual studies actually show, with the conflicts reported rather than resolved in favor of a single claim.
  4. [Section V vs. Section VI] The paper states in Section V that 'research has mostly focused on phishing emails while other types such as baiting, spear phishing emails, whaling, and impersonation are not well studied,' yet Section VI concludes that 'spear phishing, a targeted form of phishing, is particularly effective when using these persuasion techniques.' These two statements contradict each other: if the reviewed evidence base does not adequately cover spear phishing, the conclusion about its comparative effectiveness is not warranted. The conclusion should be revised to reflect the actual scope of the reviewed studies.
minor comments (5)
  1. [Introduction] The phrase 'caried out' should be corrected to 'carried out,' and the sentence 'Previous studies have shown that Cialdini’s six principles are effective in marketing and sales, additionally also in phishing' should be revised for clarity.
  2. [Section III] The Methodology refers to 'the researcher' rather than the authors; for a systematic review the authors should specify who performed screening and data extraction and how disagreements were resolved.
  3. [Section IV.E] The machine-learning subsection is only two sentences long and gives no detail on the persuasion cues used in [49] or the detection method in [43]; expanding it would increase the survey's descriptive utility.
  4. [References] Reference formatting is inconsistent: some URLs lack access dates, and news/report sources such as [11]–[16] should be clearly labeled as grey literature rather than peer-reviewed sources.
  5. [Section VI] The sentence 'This paper identified a gap in understanding the impact of principles of persuasion in phishing attacks' is vague; the gap should be specified precisely and linked to the limitations enumerated in Section V.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: this is a descriptive literature survey with no derivation chain, and its conclusions are syntheses of the surveyed literature rather than reductions of predictions to inputs.

full rationale

This paper is a narrative survey, not a derivation or modeling paper, so none of the circularity patterns apply. There are no equations, no fitted parameters, no predicted quantities, no uniqueness theorems, and no citations to the authors' own prior work; the reference list contains no self-citations by Khadka, Ullah, Ma, Marroquin, or Alem. The central claim that phishing emails using persuasion principles are 'more effective social engineering tactics than other phishing attacks' (Section VI) is a synthesis of the reviewed studies, and the paper itself lists gaps (lack of control groups, lack of standardization in coding and measurement, conflicting results across studies) that limit that synthesis. Those are internal-validity and generalizability problems, not circularity: a conclusion drawn from a corpus is not equivalent to an input of the corpus by construction unless the conclusion merely restates the inclusion criterion. Here the inclusion criterion was that papers apply Cialdini's principles in cybersecurity, while the conclusion asserts comparative effectiveness, which is not entailed by the criterion. The identified 'significant gap' is an interpretation of the selected literature, which is inherent to any systematic review and does not constitute a self-referential reduction. No evidence in the manuscript supports a finding that any load-bearing step reduces to its own inputs, so the circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The survey introduces no new parameters, entities, or derivations. Its central claims rest entirely on the Cialdini taxonomy and the reliability and representativeness of the cited primary studies, both of which are domain assumptions that the paper does not independently verify.

assumptions (3)
  • domain assumption Cialdini's six principles of persuasion are a valid and sufficient taxonomy for analyzing social engineering in phishing.
    The entire review is structured around Cialdini's taxonomy [1], but the paper does not justify why this taxonomy is complete or superior to alternative frameworks, such as the integrated list from Ferreira and Teles [21] which the paper itself mentions.
  • domain assumption The coding of persuasion principles in the reviewed primary studies is reliable and comparable across studies.
    The paper synthesizes results from studies with different coding schemes, while also noting that standardization is lacking. This tension is acknowledged in Section V but not resolved.
  • domain assumption The selected corpus of 50 full-text articles is representative of the phishing-persuasion literature.
    The search strategy, described in Section III, uses a single keyword phrase and no explicit date range, making representativeness an assumption rather than a demonstrated property.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Survey on the Principles of Persuasion as a Social Engineering Strategy in Phishing." pith.science (2026). https://pith.science/paper/EGIWSX5K

@misc{pith2026241218488,
  author       = {Pith},
  title        = {Pith review of: A Survey on the Principles of Persuasion as a Social Engineering Strategy in Phishing},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/EGIWSX5K}},
  note         = {Machine review of arXiv:2412.18488}
}
read the original abstract

Research shows that phishing emails often utilize persuasion techniques, such as social proof, liking, consistency, authority, scarcity, and reciprocity to gain trust to obtain sensitive information or maliciously infect devices. The link between principles of persuasion and social engineering attacks, particularly in phishing email attacks, is an important topic in cyber security as they are the common and effective method used by cybercriminals to obtain sensitive information or access computer systems. This survey paper concluded that spear phishing, a targeted form of phishing, has been found to be specifically effective as attackers can tailor their messages to the specific characteristics, interests, and vulnerabilities of their targets. Understanding the uses of the principles of persuasion in spear phishing is key to the effective defence against it and eventually its elimination. This survey paper systematically summarizes and presents the current state of the art in understanding the use of principles of persuasion in phishing. Through a systematic review of the existing literature, this survey paper identifies a significant gap in the understanding of the impact of principles of persuasion as a social engineering strategy in phishing attacks and highlights the need for further research in this area.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

51 extracted references · 47 canonical work pages

  1. [22]

    Interaction of personality and persuasion tactics in email phishing attacks,

    P. Lawson, O. Zielinska, C. Pearson, and C. B. Mayhorn, "Interaction of personality and persuasion tactics in email phishing attacks," in Proceedings of the Human Factors and Ergonomics Society , 2017, vol. 2017-October: Human Factors an Ergonomics Society Inc., pp. 1331 - 1333, doi: 10.1177/1541931213601815

  2. [2]

    Analysing persuasion principles in phishing emails,

    N. Akbar, "Analysing persuasion principles in phishing emails," University of Twente, 2014

  3. [10]

    How phishers exploit the coronavirus pandemic: A content analysis of COVID -19 themed phishing emails,

    N. Akdemir and S. Yenal, "How phishers exploit the coronavirus pandemic: A content analysis of COVID -19 themed phishing emails," SAGE Open, vol. 11, no. 3, p. 21582440211031879, 2021

  4. [35]

    A temporal analysis of persuasion principles in phishing emails,

    O. A. Zielinska, A. K. Welk, C. B. Mayhorn, and E. Murphy -Hill, "A temporal analysis of persuasion principles in phishing emails," in Proceedings of the Human Factors and Ergonomics Society , 2016: Human Factors an Ergonomics Society Inc., pp. 764 -768, doi: 10.1177/1541931213601175

  5. [19]

    Breaching the human firewall: Social engineering in phishing and spear -phishing emails,

    M. Butavicius, K. Parsons, M. Pattinson, and A. McCormac, "Breaching the human firewall: Social engineering in phishing and spear -phishing emails," arXiv preprint arXiv:1606.00887, 2016

  6. [38]

    Dissecting spear phishing emails for older vs young adults: On the interplay of weapons of influence and life domains in predicting susceptibility to phishing,

    D. Oliveira et al., "Dissecting spear phishing emails for older vs young adults: On the interplay of weapons of influence and life domains in predicting susceptibility to phishing," in Conference on Human Factors in Computing Systems - Proceedings, 2017, vol. 2017 -May: Association for Computing Machinery, pp. 6412 -6424, doi: 10.1145/3025453.3025831

  7. [43]

    Detection method of phishing email based on persuasion principle,

    X. Li, D. Zhang, and B. Wu, "Detection method of phishing email based on persuasion principle," in Proceedings of 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference, ITNEC 2020 , B. Xu and K. Mou, Eds., 2020: Institute of Electrical and Electronics Engineers Inc., pp. 571 -574, doi: 10.1109/ITNEC48623.2020.9084766

  8. [49]

    Phishing email detection using persuasion cues,

    R. Valecha, P. Mandaokar, and H. R. Rao, "Phishing email detection using persuasion cues," IEEE Transactions on Dependable and Secure Computing, vol. 19, no. 2, pp. 747-756, 2021

  9. [30]

    Social Engineering and Organisational Dependencies in Phishing Attacks,

    R. Taib, K. Yu, S. Berkovsky, M. Wiggins, and P. Bayl -Smith, "Social Engineering and Organisational Dependencies in Phishing Attacks," in Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), D. Lamas, F. Loizides, L. Nacke, H. Petrie, M. Winckler, and P. Zaphiris, Eds., 2019...

  10. [21]

    Persuasion: How phishing emails can influence users and bypass security measures,

    A. Ferreira and S. Teles, "Persuasion: How phishing emails can influence users and bypass security measures," (in English), Int J Hum Comput Stud, Article vol. 125, pp. 19-31, 2019, doi: 10.1016/j.ijhcs.2018.12.004

  11. [23]

    A real world study on employees' susceptibility to phishing attacks,

    M. De Bona and F. Paci, "A real world study on employees' susceptibility to phishing attacks," in ACM International Conference Proceeding Series, 2020: Association for Computing Machinery, doi: 10.1145/3407023.3409179

  12. [31]

    The design of phishing studies: Challenges for researchers,

    K. Parsons, A. McCormac, M. Pattinson, M. Butavicius, and C. Jerram, "The design of phishing studies: Challenges for researchers," Computers & Security, vol. 52, pp. 194-206, 2015

Show all 51 references
  1. [1]

    R. B. Cialdini, Influence: The psychology of persuasion . Collins New York, 2007

  2. [3]

    Research note —influence techniques in phishing attacks: an examination of vulnerability and resistance,

    R. T. Wright, M. L. Jensen, J. B. Thatcher, M. Dinger, and K. Marett, "Research note —influence techniques in phishing attacks: an examination of vulnerability and resistance," Information systems research, vol. 25, no. 2, pp. 385-400, 2014

  3. [4]

    Data Breach Investigations Report,

    Verizon, "Data Breach Investigations Report," 2022

  4. [5]

    Internet Crime Report,

    FBI, "Internet Crime Report," 2020. [Online]. Available: https://www.ic3.gov/Media/PDF/AnnualReport/2020_IC3Report.pdf

  5. [6]

    Business Email Compromise The $26 Billion Scam,

    FBI, "Business Email Compromise The $26 Billion Scam," 2019. [Online]. Available: https://www.ic3.gov/Media/Y2019/PSA190910

  6. [7]

    Phishing Activity Trends Report,

    APWG, "Phishing Activity Trends Report," 2021. [Online]. Available: https://docs.apwg.org/reports/apwg_trends_report_q1_2021.pdf

  7. [8]

    The psychology of social engineering —the “soft

    D. Kelley, "The psychology of social engineering —the “soft” side of cybercrime," vol. 2023, ed. Microsoft security Blog, 2020

  8. [9]

    Exploiting the human factor: Social engineering attacks on cryptocurrency users,

    K. Weber, A. E. Schütz, T. Fertig, and N. H. Müller, "Exploiting the human factor: Social engineering attacks on cryptocurrency users," in International Conference on Human -Computer Interaction , 2020: Springer, pp. 650-668

  9. [11]

    Scammers capitalise on pandemic as Australians lose record $851 million to scams,

    ACCC, "Scammers capitalise on pandemic as Australians lose record $851 million to scams," ed, 2021

  10. [12]

    Personal Fraud

    ABS. Personal Fraud . [Online]. Available: https://www.abs.gov.au/statistics/people/crime-and-justice/personal- fraud/latest-release

  11. [13]

    China link possible in cyber attack on Australian Parliament computer system, ABC understands,

    S. Borys, "China link possible in cyber attack on Australian Parliament computer system, ABC understands," ed, 2019

  12. [14]

    C. Tonkin. (2020) Service NSW suffers cyber attack. Informationage. Available: https://ia.acs.org.au/article/2020/service-nsw-suffers-cyber- attack.html#:~:text=Service%20NSW%20was%20the%20victim%20of %20a%20cyber,47%20staff%20accounts%20were%20accessed%20in% 20the%20attack

  13. [15]

    Channel Nine cyber -attack disrupts live broadcasts in Australia,

    B. News, "Channel Nine cyber -attack disrupts live broadcasts in Australia," in bbc.com, ed, 2021

  14. [16]

    Incident Report on the Breach of the Australian National University’s Administrative Systems,

    A. N. University, "Incident Report on the Breach of the Australian National University’s Administrative Systems," 2019. Accessed: 12 February 2023. [Online]. Available: https://imagedepot.anu.edu.au/scapa/Website/SCAPA190209_Public_re port_web_2.pdf

  15. [17]

    Phishing Detection: A Literature Survey,

    M. Khonji, Y. Iraqi, and A. Jones, "Phishing Detection: A Literature Survey," IEEE Communications Surveys & Tutorials, vol. 15, no. 4, pp. 2091-2121, 2013, doi: 10.1109/SURV.2013.032213.00009

  16. [18]

    Unifying the Global Response To Cybercrime,

    APWG, "Unifying the Global Response To Cybercrime," in "Phishing Activity Trends Report," Anti Phishing Working Group (APWG), 20 September 2022

  17. [20]

    An Analysis of Social Engineering Principles in Effective Phishing,

    A. Ferreira and G. Lenzini, "An Analysis of Social Engineering Principles in Effective Phishing," in Proceedings - 5th Workshop on Socio - Technical Aspects in Security and Trust, STAST 2015 , G. Lenzini and G. Bella, Eds., 2015: Institute of Electrical and Electronics Enginee...

  18. [24]

    Human factors in phishing attacks: a systematic literature review,

    G. Desolda, L. S. Ferro, A. Marrella, T. Catarci, and M. F. Costabile, "Human factors in phishing attacks: a systematic literature review," ACM Computing Surveys (CSUR), vol. 54, no. 8, pp. 1-35, 2021

  19. [25]

    Susceptibility to phishing on social network sites: A personality information processing model,

    E. D. Frauenstein and S. Flowerday, "Susceptibility to phishing on social network sites: A personality information processing model," Computers & Security, vol. 94, p. 101862, 2020/07/01/ 2020, doi: https://doi.org/10.1016/j.cose.2020.101862

  20. [26]

    A convicted hacker debunks some myths,

    K. Mitnick, "A convicted hacker debunks some myths," in Technology, CNN, Ed., ed. https://edition.cnn.com/2005/TECH/internet/10/07/kevin.mitnick.cnna/: CNN.com, 2005

  21. [27]

    Social engineering attack framework,

    F. Mouton, M. M. Malan, L. Leenen, and H. S. Venter, "Social engineering attack framework," in 2014 Information Security for South Africa, 2014: IEEE, pp. 1-9

  22. [28]

    How social engineers use persuasion principles during vishing attacks,

    K. S. Jones, M. E. Armstrong, M. K. Tornblad, and A. S. Namin, "How social engineers use persuasion principles during vishing attacks," Information & Computer Security, 2020

  23. [29]

    Why humans are the weakest link,

    M. Nohlberg, "Why humans are the weakest link," in Social and human elements of information security: Emerging trends and countermeasures: IGI Global, 2009, pp. 15-26

  24. [32]

    A taxonomy of attacks and a survey of defence mechanisms for semantic social engineering attacks,

    R. Heartfield and G. Loukas, "A taxonomy of attacks and a survey of defence mechanisms for semantic social engineering attacks," ACM Computing Surveys (CSUR), vol. 48, no. 3, pp. 1-39, 2015

  25. [33]

    The Social Engineering Personality Framework,

    S. Uebelacker and S. Quiel, "The Social Engineering Personality Framework," in 2014 Workshop on Socio -Technical Aspects in Security and Trust , 18 -18 July 2014 2014, pp. 24 -30, doi: 10.1109/STAST.2014.12

  26. [34]

    The persuasive phish: Examining the social psychological principles hidden in phishing emails,

    O. Zielinska, A. Welk, C. B. Mayhorn, and E. Murphy -Hill, "The persuasive phish: Examining the social psychological principles hidden in phishing emails," in Proceedings of the Symposium and Bootcamp on the Science of Security, 2016, pp. 126-126

  27. [36]

    Assessment of End-User Susceptibility to Cybersecurity Threats in Saudi Arabia by Simulating Phishing Attacks,

    D. Aljeaid, A. Alzhrani, M. Alrougi, and O. Almalki, "Assessment of End-User Susceptibility to Cybersecurity Threats in Saudi Arabia by Simulating Phishing Attacks," Information, vol. 11, no. 12, p. 547, 2020

  28. [37]

    Baiting the hook: Exploring the interaction of personality and persuasion tactics in email phishing attacks,

    P. A. Lawson, A. D. Crowson, and C. B. Mayhorn, "Baiting the hook: Exploring the interaction of personality and persuasion tactics in email phishing attacks," in Advances in Intelligent Systems and Computing , Y. Fujita, S. Bagnara, R. Tartaglia, S. Albolino, and T. Alexander,...

  29. [39]

    Predicting susceptibility to social influence in phishing emails,

    K. Parsons, M. Butavicius, P. Delfabbro, and M. Lillie, "Predicting susceptibility to social influence in phishing emails," (in English), Int J Hum Comput Stud, Article vol. 128, pp. 17 -26, 2019, doi: 10.1016/j.ijhcs.2019.02.007

  30. [40]

    Alexa in Phishingland: Empirical Assessment of Susceptibility to Phishing Pretexting in Voice Assistant Environments,

    F. Sharevski and P. Jachim, "Alexa in Phishingland: Empirical Assessment of Susceptibility to Phishing Pretexting in Voice Assistant Environments," in 2021 IEEE Security and Privacy Workshops (SPW) , 27-27 May 2021 2021, pp. 207 -213, doi: 10.1109/SPW53761.2021.00034

  31. [41]

    Research Article Phishing Susceptibility: An Investigation Into the Processing of a Targeted Spear Phishing Email,

    J. Wang, T. Herath, R. Chen, A. Vishwanath, and H. R. Rao, "Research Article Phishing Susceptibility: An Investigation Into the Processing of a Targeted Spear Phishing Email," IEEE Transactions on Professional Communication, vol. 55, no. 4, pp. 345 -362, 2012, doi: 10.1109/TPC...

  32. [42]

    Success and failure in expert reasoning,

    P. E. Johnson, S. Grazioli, K. Jamal, and I. A. Zualkernan, "Success and failure in expert reasoning," Organizational Behavior and Human Decision Processes, vol. 53, no. 2, pp. 173-203, 1992

  33. [44]

    Principles of persuasion in social engineering and their use in phishing,

    A. Ferreira, L. Coventry, and G. Lenzini, "Principles of persuasion in social engineering and their use in phishing," in Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) , T. Tryfonas and I. As...

  34. [45]

    “Alexa, What’s a Phishing Email?

    F. Sharevski and P. Jachim, "“Alexa, What’s a Phishing Email?”: Training users to spot phishing emails using a voice assistant," (in English), Eurasip J. Inf. Secur., Article vol. 2022, no. 1, 2022, Art no. 7, doi: 10.1186/s13635-022-00133-w

  35. [46]

    A Toolkit for Security Awareness Training Against Targeted Phishing,

    S. Pirocca, L. Allodi, and N. Zannone, "A Toolkit for Security Awareness Training Against Targeted Phishing," in International Conference on Information Systems Security, 2020: Springer, pp. 137-159

  36. [47]

    How persuasive is a phishing email? A phishing game for phishing awareness,

    R. Fatima, A. Yasin, L. Liu, and J. Wang, "How persuasive is a phishing email? A phishing game for phishing awareness," Journal of Computer Security, vol. 27, no. 6, pp. 581-612, 2019

  37. [48]

    Consolidated taxonomy and research roadmap for cybercrime and cyberterrorism,

    B. Akhgar et al. , "Consolidated taxonomy and research roadmap for cybercrime and cyberterrorism," Combatting Cybercrime and Cyberterrorism: Challenges, Trends and Priorities, pp. 295-321, 2016

  38. [50]

    Personalized persuasion: Quantifying susceptibility to information exploitation in spear -phishing attacks,

    T. Xu, K. Singh, and P. Rajivan, "Personalized persuasion: Quantifying susceptibility to information exploitation in spear -phishing attacks," (in English), Appl. Ergon., Article vol. 108, 2023, Art no. 103908, doi: 10.1016/j.apergo.2022.103908

  39. [51]

    Email phishing and signal detection: How persuasion principles and personality influence response patterns and accuracy,

    P. Lawson, C. J. Pearson, A. Crowson, and C. B. Mayhorn, "Email phishing and signal detection: How persuasion principles and personality influence response patterns and accuracy," (in English), Appl. Ergon., Article vol. 86, 2020, Art no. 103084, doi: 10.1016/j.apergo.2020.103084

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.