Phishing is one of the most prevalent social engineering attacks that targets both organizations and individuals. It is crucial to understand how email presentation impacts users' reactions to phishing attacks. We speculated that the device and email presentation may play a role, and, in particular, that how links are shown might influence susceptibility. Collaborating with the IT Services unit of a large organization doing a phishing training exercise, we conducted a study to explore the effects of the device and the presentation of links. Our findings indicate that mobile device and computer users were equally likely to click on unmasked links, however mobile device users were more likely to click on masked links compared to computer users. These findings suggest that link presentation plays a significant role in users' susceptibility to phishing attacks.
翻译:钓鱼攻击是针对组织和个人的最常见的社交工程攻击之一。理解邮件呈现方式如何影响用户对钓鱼攻击的反应至关重要。我们推测设备和邮件呈现方式可能会发挥作用,特别是链接的显示方式可能会影响易感性。与一家进行钓鱼训练的大型组织的IT服务单位合作,我们开展了一项研究,探讨了设备和链接呈现方式的影响。我们的发现表明,移动设备和计算机用户同样可能会点击未掩盖的链接,但与计算机用户相比,移动设备用户更有可能点击掩盖的链接。这些发现表明,链接呈现方式对用户易感性至关重要。