2022 IEEE Symposium on Security and Privacy (SP) 2022
DOI: 10.1109/sp46214.2022.9833766
|View full text |Cite
|
Sign up to set email alerts
|

Phishing in Organizations: Findings from a Large-Scale and Long-Term Study

Abstract: In this paper, we present findings from a largescale and long-term phishing experiment that we conducted in collaboration with a partner company. Our experiment ran for 15 months during which time more than 14,000 study participants (employees of the company) received different simulated phishing emails in their normal working context. We also deployed a reporting button to the company's email client which allowed the participants to report suspicious emails they received. We measured click rates for phishing … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

1
20
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 31 publications
(21 citation statements)
references
References 43 publications
1
20
0
Order By: Relevance
“…Generally speaking, phishing awareness training continually exposes the participants to the risk of wasting their time [87]. However, as Lain et al [74] stated in their study, it does not expose the participants to a greater risk than what they would encounter during their daily lives because the partici-pants are regularly exposed to real phishing emails or spam. We acknowledge that conducting this study exposed our participants to minimal risks but similar to other researchers [74], we believe that the positive experience the participants gain merited these risks.…”
Section: B Ethics Statementmentioning
confidence: 95%
See 4 more Smart Citations
“…Generally speaking, phishing awareness training continually exposes the participants to the risk of wasting their time [87]. However, as Lain et al [74] stated in their study, it does not expose the participants to a greater risk than what they would encounter during their daily lives because the partici-pants are regularly exposed to real phishing emails or spam. We acknowledge that conducting this study exposed our participants to minimal risks but similar to other researchers [74], we believe that the positive experience the participants gain merited these risks.…”
Section: B Ethics Statementmentioning
confidence: 95%
“…However, as Lain et al [74] stated in their study, it does not expose the participants to a greater risk than what they would encounter during their daily lives because the partici-pants are regularly exposed to real phishing emails or spam. We acknowledge that conducting this study exposed our participants to minimal risks but similar to other researchers [74], we believe that the positive experience the participants gain merited these risks. In addition, the decision to conduct this study with all students and staff members was approved by the highest panel of our university (including the CISO) and we followed the ethical guidelines of our university to the best of our knowledge.…”
Section: B Ethics Statementmentioning
confidence: 97%
See 3 more Smart Citations