Abstract
Social-psychological research on phishing has implicated ineffective cognitive processing as the key reason for individual victimization. Interventions have consequently focused on training individuals to better detect deceptive emails. Evidence, however, points to individuals sinking into patterns of email usage that within a short period of time results in an attenuation of the training effects. Thus, individual email habits appear to be another predictor of their phishing susceptibility. To comprehensively account for all these influences, we built a model that accounts for the cognitive, preconscious, and automatic processes that potentially leads to phishing-based deception. The resultant suspicion, cognition, and automaticity model (SCAM) was tested using two experimental studies in which participants were subjected to different types of email-based phishing attacks.
Phishing—a social engineering attack deployed via email to deceive individuals—is one of the biggest threats to cyber security. There has been a 782% rise in cyber crimes since 2007, and phishing accounts for more than a third of these attacks (Government Accountability Office Report, 2013). These statistics are particularly troubling when one considers that the Pentagon alone receives 10 million cyber attacks each day, and most major banks, financial institutions, and media organizations report close to 50,000 cyber intrusions each day (Fung, 2013). Phishing attacks have been implicated in crimes ranging from identity and intellectual property theft to financial fraud, cyber espionage, and hacktivism, with estimated losses at over 1,000 billion dollars (Passeri, 2014). There is, thus, an urgent need to address the phishing problem from a law enforcement, public policy, and cyber security perspective.
A typical phishing attack tends to be rather simple and utilizes a short email that acts as bait with either an embedded hyperlink or an attached file. The goal of such link attacks and attachment attacks is to direct individuals to phony sites or launch spyware on the host computer (“FireEye,” 2013; Wilshusen & Powner, 2009). In simulated studies, a single phishing email campaign has been shown to victimize 50% of the email’s recipients; when repeated twice, the same campaign tends to net 80% of its intended victims (Team, 2013; ThreatSim, n.d.). According to scholars who study phishing, such high victimization rates occur because individuals fail to recognize the cues in the emails that reveal the deception (Vishwanath, Herath, Chen, Wang, & Rao, 2011; Workman, 2008). This has led to the development of educational interventions aimed at improving individuals’ ability to cognitively process and spot deceptive cues within phishing emails (Kumaraguru, Sheng, Acquisti, Cranor, & Hong, 2008). Emerging research, however, suggests that information processing may not be the sole determinant of phishing susceptibility. In a series of studies called the Carronade Experiments conducted at West Point, army cadets were trained on various ways to effectively detect phishing emails before subjecting them to real phishing attacks (Ferguson, 2005). The research found that education and training were only effective in the short-term, with any effects wearing off within a few hours after the cadets reverted back to their regular patterns of email use. Consequently, most of them were successfully phished within four hours after the educational intervention was administered. This suggests that habitual patterns of media use—a factor that has yet to be considered in deception research—may be another factor contributing to the high success of phishing attacks.
Thus, there appears to be two prospective reasons why individuals succumb to phishing: consciously defined individual actions premised on some degree of cognitive processing, on one hand, and autonomous behavioral reactions based on email-use habits, on the other. The effects of these processes have yet to be considered together, especially within the phishing-based deception context. Understanding their relative effects is important because interventions such as education and training may be ineffective among individuals whose online habits determine their likelihood of being deceived. Given this, the current study builds a theory-based research model of phishing susceptibility that incorporates the cognitive and habitual influences with the goal of comprehensively answering the following research questions:
Our study builds on existing research that has studied how individuals cognitively process information. We extend the heuristic systematic model (HSM; Eagly & Chaiken, 1993) from social psychology, a framework that is widely used to explain individual information processing and attitude formation in a variety of persuasive contexts. Emerging research on the operation of attitudes suggests that besides influencing how individuals process information, some beliefs have an immediate, preconscious influence on judgment (Ajzen, 2001). To capture this, our study proposes a new construct, cyber-risk beliefs, and explores its influence on deception-detection. Our study also builds on mass-communication theory that explains how repeated patterns of media consumption can lead to media habits and the enactment of automatic, nonconscious actions (LaRose, 2010). Finally, from the interpersonal deception literature, we borrow the construct of suspicion and extend it as an operational indicator of phishing-deception likelihood. Together, cognitively mediated and habitually enacted behaviors, along with their antecedents, are seen as predictors of whether a phishing email arouses suspicion. The resultant suspicion, cognition, and automaticity model (SCAM) is built to comprehensively explain deception through phishing using a handful of higher order theoretical constructs. The model is tested on matched samples of individuals subjected to real-world link and attachment attacks. The outcome of the study includes a cognitive-behavioral model that is empirically validated along with the measures for the model constituents. We begin the next section with an explication of the model.
The SCAM
The SCAM encompasses the key factors that lead to individual suspicion about phishing emails and their resultant actions. Figure 1 shows the proposed model. Each of the constructs and the rationale for their interrelationships are discussed below.

The Suspicion, Cognition, and Automaticity Model.
Suspicion
In their quest to find a reliable indicator of interpersonal lie-detection, scholars have often utilized the construct of trust to predict individuals’ likelihood of detecting deception (Buller, 1988; McCornack & Levine, 1990). Trust, defined as an individual’s intention to accept vulnerabilities with the expectation of positive outcomes (Kee & Knox, 1970; Lyons, Stokes, Eschleman, Alarcon, & Barelka, 2011), has, however, posed a number of problems. First, there are quite a few dimensions of trust, each with its own potential relationship with deception. For instance, the information technology (IT) automation literature has found trust dimensions ranging from reliability, robustness, familiarity, understandability, explication of intent, usefulness, and dependence (Sheridan, 1988), to predictability, dependability, faith, competence, trustworthiness, and responsibility (Muir & Moray, 1996). It is, however, unclear which dimension best explains individual susceptibility to email-based phishing. Second, the different types of trust are further complicated by their conflicting interrelationships. For instance, some research utilizes trustworthiness as a contextual determinant of deception likelihood (Lyons et al., 2011), while others focus on trust and distrust cues (Sinaceur, 2010). Trust, however, is distinct from trustworthiness (Jian, Bisantz, & Drury, 2000), and trust is also orthogonal to distrust (Lewicki, McAllister, & Bies, 1998; McKnight, Kacmar, & Choudhury, 2004). This makes it difficult to explain these results (e.g., What does it mean when someone scores low on trust?) and develop focused interventions (e.g., Should the intervention focus on improving trust or reducing distrust?). Finally, trust is a rather poor predictor of deception-detection because the presence of trust desensitizes individuals to deception cues. For instance, research on interpersonal deception has found that when individuals trust a relational partner, they tend to become blind toward their partner’s lies (McCornack & Parks, 1986).
Given these issues, some scholars advocate the use of trust’s “darker cousin” (McCornack & Levine, 1990, p. 219), suspicion, as a predictor of deception-detection (Levine & McCornack, 1991). Suspicion, defined as the degree of uncertainty one has when interacting with a particular stimulus (Lyons et al., 2011), is a unidimensional construct that is both necessary for detecting deception, as well as a better predictor of deception-detection accuracy. In relational deception studies, even moderate amounts of suspicion, when aroused, resulted in a better-than-chance improvement in deception-detection accuracy (McCornack & Levine, 1990). Thus, suspicion is both fundamental to the process of detecting deception (Toris & DePaulo, 1984) and a particularly sensitive measure of deception-detection. Furthermore, the suspicion construct is well understood, and its nomological position and antecedents are relatively clear. Suspicion is distinct from the various facets of trust and distrust (Lyons et al., 2011), and is aroused by specific contextual cues in the decision-context (McCornack & Levine, 1990). Thus, the SCAM uses suspicion as the major endogenous predictor of individual susceptibility to email-based phishing.
Cognition
Suspicion is aroused when contextual cues trigger a dissonance between one’s expected reality and one’s perceived reality (Lyons et al., 2011). 1 Perceptions of reality are shaped by how individuals cognitively evaluate and process information within a context. Expectations of reality are reflected in individuals’ beliefs about what is acceptable in a context. Thus, the SCAM focuses on both aspects of cognition that lead to suspicion about phishing emails: the different modes of cognitive processing and the individuals’ cyber-risks beliefs that shape their expected reality.
Cognitive processing
Among the models that explain cognitive-information processing, the HSM (Chaiken, 1980; Eagly & Chaiken, 1993) is the most influential. It has been used to predict communication involving risk (Griffin, Neuwirth, Giese, & Dunwoody, 2002; Trumbo, 2002), as well as online behavior (Bucy & Tao, 2007; Kalyanaraman & Sundar, 2006), making it particularly well suited for the study of email-based deception.
The HSM distinguishes between two modes of information processing that individuals employ. At the upper end of the information-processing continuum is systematic processing, where individuals make judgments by carefully examining the quality of arguments within the persuasive context. At the other end is heuristic processing, which involves the use of simple decision rules or cognitive heuristics triggered by adjunct cues in the context to reach judgments. From a cognitive resource standpoint, systematic processing is effortful and requires the allocation of substantial information-processing resources, while heuristic processing is more economical and efficient.
The overwhelming research evidence points to individuals acting as cognitive misers, preferring economical over effortful information evaluation (Sundar, 2008; Sundar, Knobloch-Westerwick, & Hastall, 2007). Consequently, heuristic processing tends to dominate information processing. Research that has examined the outcomes of the two processing modes has suggested that the use of heuristic shortcuts, although efficient, is frequently undercut by irrationality and increased errors in judgment (Tversky & Kahneman, 1974). For instance, research has found heuristic processing to result in lower risk evaluations (Trumbo, 2002), and emerging research has also connected such processing to the increased likelihood of deception on social media (Vishwanath, 2014a). In contrast, systematic processing, due to its high scrutiny toward the content and need for comprehension, results in more reasoned and optimal decisions.
Within the email-based phishing context, the snap judgments that individuals make based on a cursory examination of emails during heuristic processing is expected to result in individuals overlooking some of the cues that may arouse suspicion. In contrast, the scrutiny inherent to the depth of systematic processing is expected to increase the likelihood that individuals notice the discrepancies that trigger suspicion and ultimately reveal the deception. Consequently, the SCAM posits the following:
Cyber-risk beliefs
Risk-related beliefs have been shown to be the most commonly accessed cognitions considered by individuals when they examine risk-related actions (Griffin et al., 2002). Hence, a core exogenous construct in the SCAM is individuals’ cyber-risk beliefs. Cyber-risk beliefs are individuals’ perceptions about the risks associated with online behaviors. 2 Social-psychological theories explain how beliefs generally form based on individuals’ prior experience, exposure to media, and internal factors such as personality and efficacy (Bandura, 1989). Since cyber-risk beliefs are the outcome of similar processes, in the SCAM, they serve as the bridge between the individuals’ subjective knowledge about online risks and their experience and efficacy in dealing with such risks.
In the HSM, motivation to commit cognitive resources is premised on the individuals’ perceived expectations from their actions (Chaiken, 1987). Systematic processing occurs when individuals expect their actions to have severe consequences. This raises their level of uncertainty and leads individuals to seek a higher degree of confidence during decision making. This, in turn, motivates the allocation of more cognitive resources to the task (Zuckerman & Chaiken, 1998). Thus, the SCAM posits that individuals are more likely to systematically process emails when they perceive their cyber actions to be risky. In contrast, heuristic processing is motivated when individuals perceive a lower need for confidence in their decisions because the outcomes of their actions are seen as less risky. In the phishing email context, when individuals perceive their online actions as being relatively safe, their desired need for confidence in judgments about emails they receive is expected to be low. Therefore, it is likely for them to heuristically process phishing emails instead. Thus, the SCAM posits the following:
A growing body of evidence also points to attitude-based evaluations being immediate, fast, and utilized with minimal to no awareness (Ajzen, 2001). Early evidence of this direct effect of preconscious perceptions on behavior comes from research on product-warning labels, where results suggested that individuals disregarded warnings and used products in ways that were consonant with their beliefs about the safety of the product (DeTurck & Goldhaber, 1989). For instance, individuals intuitively believe that powdered products such as dehydrated milk and infant formula are sterile and safer than their liquid versions, which has resulted in the deaths of many infants due to bacterial infections (Centers for Disease Control and Prevention [CDC], 2014). Subsequent research has found that the direct effects of beliefs are much stronger when individuals have high familiarity with the attitude object or behavior (Ajzen, 2001; Bargh & Chartrand, 1999), presumably because individuals’ beliefs serve as rules of thumb that are directly applied without much need for interaction with the contextual cues. Thus, although there are warning labels on “Q-tips” expressively cautioning against their use inside the ear, individuals routinely use the product in their ear potentially using thumb rules such as “Q-tips are shaped for safe use in the ear,” or “The cotton ends of Q-tips make them better for the ear.” Due to the routinized and familiarized nature of email usage, email-based phishing contexts are potentially susceptible to the direct application of belief-based expectations on behavior. Thus, a risk-belief such as “Opening any email on a mobile device is safe” or “Opening any email attachment is risky” may directly decrease or increase suspicion without the need for examining the email. Thus, the SCAM posits that when individuals believe their cyber actions to be relatively risky, it could also have the direct effect of increasing their level of suspicion toward the emails they receive.
Automaticity in behavior
The information-processing view contends that individual actions are premised on some degree of cognitive mediation. Social-psychological research on habits, however, presents an alternative perspective. In this view, habits and conscious decision making are considered as independent and opposing processes (Aarts, Verplanken, & Knippenberg, 1998; Landis, Triandis, & Adamopoulos, 1978). Some behaviors, which begin as goal-directed, conscious activities, get routinized as individuals continually enact the behavior under stable conditions (LaRose, 2010). Overtime, these routines become habitual action-scripts that are automatically applied without conscious reflection about the behavior’s antecedents, consequences, or even its enactment (LaRose & Eastin, 2004).
Emerging mass-communication research suggests that similar to other compulsive behaviors, many media behaviors such as repeated instant messaging use (Lee & Perry, 2004), social media use (Vishwanath, 2014b), pornography viewing (Sirianni & Vishwanath, 2012), and online shopping (LaRose & Eastin, 2002) tend to become habitual over time. Email use presents a particularly strong case for habituation for the following reasons (LaRose, 2010). First, people frequently interact with emails throughout the day, making it a behavior that is continually enacted. Second, checking email is part of the routine of web surfing and often the primary reason for repeatedly going online. Many individuals ritualistically check their emails first thing in the morning, at night before they end the day, or whenever they are able to use their smartphone or tablet, such as while driving or immediately after an airplane lands. Finally, most email exchanges tend to be fairly benign, making it easy to relax cognitive involvement and form formulaic patterns of usage over time. While research has yet to connect such habitual email use to deception, the SCAM contends that the lack of cognitive mediation during habitual email use is perhaps another reason for individuals to ignore cues within a phishing email and fall for the deception. The impulsive nature of habitual enactment means that individuals’ cyber-risk beliefs may not be activated, and they might fail to consider the risks in opening or responding to the email. As a result, neither the deceptive cues are recognized, nor do they trigger suspicion. Consequently, individuals under the influence of email habits are less likely to be suspicious of phishing emails and more likely to be deceived.
While frequent repetition under stable conditions could lead to the ritualization of media behaviors, not all frequently enacted behaviors become habits. For instance, many individuals receive emails on their smartphone, but not all of them habitually check messages while they drive. Media scholars contend that the root of habit formation lies in individuals’ self-regulatory mechanism (LaRose, 2010). The self-regulatory mechanism involves self-control by being observant about one’s media-related actions and contrasting it against what is acceptable. A failure of this control mechanism leads to deficient self-regulation (Bandura, 1989; LaRose, 2010). Even among individuals who receive the same volume of emails, an individual with high self-control may avoid checking email messages on their smartphones when driving, while another individual, whose self-control is relatively ineffective, may check their smartphones while driving, without a concern for its consequences. Thus, a deficiency in the ability to control email use leads to individuals’ formation of email habits. Together, these lead to the hypotheses linking deficient self-regulation to email habits and email habits to suspicion:
Overall, the SCAM captures the conscious, cognitive factors, the preconscious influence of cyber-risk beliefs, and the automatic, nonconscious actions that lead to phishing-based deception. Cyber-risk beliefs and deficiency in self-regulation, because of their governance over conscious and nonconscious processes, are expected to co-vary. Finally, lower order factors, such as the number of emails received, frequency of email use, and other directly observable behaviors; descriptive differences such as sex, age, and income; and ultimate factors such as personality and culture, are external factors that are thought to indirectly influence deception by influencing the core constructs. The next section presents the methodology used to empirically validate the model.
Method and Measures
The SCAM was tested using two experimental studies conducted in the spring and fall of 2013. Undergraduate students enrolled in large introductory communication classes at the University at Buffalo were recruited as subjects for the studies. Study 1 was conducted in the spring semester and involved a link attack; Study 2 was conducted in the fall semester and involved an attachment attack.
Students were used to validate the SCAM for the following reasons. First, phishers increasingly pursue soft targets such as college students and senior citizens who usually do not have the support of organizational firewalls and security officers (Maskaleris, 2007; RSA, 2010). Besides, students are also consumers of many products and services, making them an important group warranting study. Second, the focus of the present study was on validating the theoretical structure of the model. The emphasis is therefore on internal validity, which is more easily achieved by minimizing exogenous influences. Students within the same university and cohort tend to be relatively similar in technology experience, exposure, technical efficacy, and socioeconomics, making it easier to control for these influences across studies. Finally, using sections of the same required course in consecutive semesters resulted in naturally matched samples and also ensured that the same student was not exposed or even aware of the previous attack.
In order to conduct the attack, a free email account was created and utilized each semester. Recent phishing attacks that targeted students at the university included the name of the university in the reply-to address and sender’s name. To appear similar to these attacks, the two email accounts used the name of the university in the sender’s name:
Study 1: Link Attack
In order to appear similar to a real phishing attack, all subjects in the study were sent the email with a hyperlink. Clicking on the hyperlink redirected subjects to a web survey. Subjects were considered phished if they clicked on the hyperlink. The attack was deployed using email-marketing software that along with the web survey allowed the research team to track individuals who opened the email and/or clicked on the survey link. A week after deployment of the initial attack, a follow-up email reminder was sent to all subjects who had not yet opened their emails. A week later, students who had yet to respond to the two phishing attempts were sent an email by the research team soliciting their participation in a web survey. Here, subjects were asked to verify whether they recalled seeing a phishing email; they were then presented a few exemplars, one of which included the phishing email that was sent to them, and asked to identify the phish they received. Only subjects who recalled seeing a phishing email and identified it correctly were retained in the study. A total of 125 students were sent the original phishing email. From these, 85 subjects were successfully phished (49 were phished in the first phase, another 36 were phished in the second). A total of 19 subjects, who were not phished, and who completed the follow-up survey, correctly identified the phishing email and were used in the analysis.
Study 2: Attachment Attack
All subjects in the attachment attack received an email with an Adobe PDF attachment. This document format was used because it is commonly used in emails as well as by phishers. Subjects were considered phished if they opened the attachment. As with the link attack, subjects were tracked using email-marketing software, and those who had yet to respond a week after the initial attack were sent another reminder. Subjects who did not respond after the two phishing attempts were contacted by the research team and, after verifying receipt of the phish, were requested to complete the follow-up web survey. A total of 220 students were sent the original phishing email. From these, 168 subjects were successfully phished (103 were phished in the first phase, another 65 were phished in the second). A total of 52 subjects completed the follow-up survey. A total of 34 subjects, who were not phished and who completed the follow-up survey, correctly identified the phishing email and were used in the analysis. The net victimization rate in the link and attachment attacks were consistent with those reported in prior simulations using samples of working adults (Team, 2013).
Measures
Most of the measures were derived from prior research and individual items, where necessary, were modified to fit the email-based phishing context. Table 1 presents sample items from each measure, the source of the adapted measure, and the Cronbach’s alpha achieved in Studies 1 and 2. For most items, subjects indicated their agreement using a response scale that varied from 1 (strongly disagree) to 5 (strongly agree).
Measures Used in the Study.
Analysis
The SCAM model was tested using path analysis on AMOS. For each model, goodness of fit was estimated using a combination of four fit indices: χ2, relative chi-square (χ2/df; Bentler, 1990; Bentler & Bonett, 1980), comparative fit index (CFI), goodness of fit index (GFI), and root mean square error of approximation (RMSEA; Browne, Cudeck, Bollen, & Long, 1993). In general, high CFI and GFI (greater than 0.95) and low RMSEA (lesser than 0.05) suggest a good fit, with numbers in the extremes indicating superior fit.
Results
Study 1: Link Attack
The structural model resulted in a χ2 value of 7.48, df = 7, p = .38, indicating that the imposed-model’s fit was superior to the unconstrained model. The model also netted a χ2/df of 1.06, CFI of 0.99, GFI of 0.98, and an RMSEA of 0.02, further suggesting that the hypothesized model achieved a superior fit.
Study 2: Attachment Attack
The structural model for the attachment attack data resulted in a χ2 value of 7.95, df = 7, p = .34, indicating that the imposed-model’s fit was superior to the unconstrained model. The model also netted a χ2/df of 1.15, CFI of 0.98, GFI of 0.99, and an RMSEA of 0.03, again suggesting that the hypothesized model achieved a superior fit.
Hypotheses Tests
Appendix B presents the correlations among the link attack measures and attachment attack measures, respectively. Table 2 presents the means and standard deviations of all measures tested in the model. Table 3 summarizes the results of the path analysis. Most of the hypotheses were supported across the two studies. H1 positing that increased heuristic processing was less likely to lead to suspicion was supported in both studies and achieved significance in the attachment attack data. H2 positing that increased systematic processing was more likely to lead to suspicion was supported in both studies. H3 positing that cyber-risk beliefs would decrease heuristic processing was supported in both studies. H4 positing that cyber-risk beliefs would increase systematic processing was supported in only the link attack. H5 positing that cyber-risk beliefs would directly influence suspicion was supported in both studies. H6 positing that deficient self-regulation would influence email habits was supported across both studies. H7 positing that email habits would negatively influence suspicion was supported in both studies, although it achieved significance in the attachment attack.
Means and Standard Deviations of Measures.
Results of the Path Analysis.
Note. Link attack R2 = 17% for suspicion, 21% for email habits, 5% for systematic processing, and 10% for heuristic processing; attachment attack R2 = 20% for suspicion, 7% for email habits, 3% for systematic processing, and 2% for heuristic processing.
p = .66. #2p = .87. #3p = .24. *p < .05. **p < .001.
Finally, independent samples t tests were used to ascertain whether individuals who were suspicious were indeed less likely to be phished. This was confirmed among subjects in both attacks: In the link attack, those who were more suspicious (M = 2.47, SD = 1.02) were significantly less likely (t = 2.62, p < .05) to be phished than those who were less suspicious (M = 3.07, SD = 0.86); likewise, among subjects in the attachment attack, those who were suspicious (M = 2.53, SD = 0.89) were significantly less likely (t = 3.16, p < .001) to be phished than those whose who were not suspicious (M = 3.06, SD = 0.90).
Discussion
The current research built and tested a research model that expands the scope of our understanding of individual victimization by accounting for cognitive processing as well as habitual email use. Based on cognitive processing theories, the model accounts for different modes of information processing and locates the motivation for the choice of processing mode in individuals’ cyber-risk beliefs. Building from the literature on media automaticity, the model also focuses on the individuals’ ability to self-regulate behaviors as the antecedent to habitual email use. The model tests were motivated by two goals, the first of which was to understand the underlying processes that led to individual victimization through phishing attacks.
The SCAM’s theoretical linkages were robust in explaining individual susceptibility to different types of email-based phishing attacks. Overall, the model tests revealed that individuals were likely to fall victim to phishing emails when aspects of the email aroused suspicion about the request. Suspicion was contextually determined and more likely when individuals systematically processed the email and less likely when they heuristically processed emails. As hypothesized, the choice of information-processing mode that led to suspicion was, in turn, contingent on the individuals’ cyber-risk beliefs. When individuals believed their cyber actions were relatively risky, they tended to systematically process emails, and when individuals believed their cyber actions were relatively safe, they tended to heuristically process emails. In addition to influencing cognitive processing, cyber-risk beliefs also directly influenced suspicion. Besides cognition, suspicion was also influenced by the individuals’ habitual patterns of email use, wherein habitual email use significantly reduced the likelihood of deception-detection.
The second goal of the study was to understand the relative influence of cognitive mediation and habitual actions in explaining individual susceptibility to phishing attacks. The test of the SCAM suggests that habitual email actions that are unconsciously enacted are separate from conscious actions that involve some level of thought (Aarts et al., 1998). Email habits are rooted in individuals’ ability to control behaviors, while the mode of cognitive processing is predicated on the individuals’ cyber-risk beliefs. Due to this, individuals fail to notice cues that could have potentially led to suspicion and reveal the deception. This results in individuals automatically enacting email-related behaviors, such as opening the email and subsequently falling for a phisher’s deception.
Interestingly, the test of the SCAM also found strong evidence for the direct effects of cyber-risk beliefs on suspicion. While research in social psychology has demonstrated the direct application of attitudes, no research, to date, has examined its effects on online deception-detection. For subjects in both attacks in the current study, cyber-risk beliefs had a significant direct effect on suspicion, which adds credence to its role as a direct trigger of suspicion. The results suggest that cyber-risk beliefs perhaps work more on a preconscious level and function as thumb rules that are directly applied without any cognitive mediation. The use of such broad decision rules is perhaps indicative of the familiar and routine nature of emails use that allows for the development and reinforcement of cognitive rules and the speed with which individuals make decisions about emails that necessitates the use of decision rules. Thus, the SCAM accounts for the conscious, unconscious, and preconscious factors that lead to individual victimization through a variety of email-based phishing attacks.
The SCAM also introduced suspicion as the key dependent measure. The use of suspicion theoretically positions SCAM within the deception-detection literature, where research has already demonstrated the validity of the construct as a robust and sensitive predictor of deception-detection accuracy. While it is widely accepted that being minimally suspicious is a necessary precursor of truth-lie judgments, most interpersonal research tends to focus less on how suspicion is aroused and more on how it influences relational judgments. Consequently, suspicion is often poorly measured and most interpersonal research tends to measure it dichotomously or use it as an independent, manipulated measure of deception-detection accuracy (e.g., Sinaceur, 2010). This “all-or-nothing” approach (Levine & McCornack, 1991, pp. 221) has been criticized for obscuring our extant understanding of the true effects of suspicion. The SCAM may be among the first to develop and test a Likert-type scale of phishing email suspicion, examine its antecedents in cognitive processing, and empirically evaluate its importance. It is also among the first to connect suspicion about an email to cognitive processing and preconscious beliefs.
Like any research that breaks new ground, the SCAM comes with some limitations while also presenting a number of new opportunities for theoretical advancement. For one, the SCAM only focused on the higher order proximate predictors of individual victimization in phishing attacks. This is both a limitation of the study and a potential area for future exploration. Future research can explore how individual differences in sex, age, and income influence processing, email habits, and phishing susceptibility. In addition, the relationship among these predictors was modeled using structural equation modeling (SEM), which tests for the correlations among variables. Thus, while the causal influences in the research model were theoretically justified, the proposed linkages between the model variables could be reversed without affecting the overall fit of the model. Here again, future empirical research needs to be conducted, perhaps using eye-tracking and incorporating behavioral or other observational measures of cognitive processing and deception-detection in order to triangulate the modeled relationships.
Two, in focusing on suspicion, the research also opens the door for other related influences. For instance, the research on interpersonal deception has identified a personality trait that makes some individuals more suspicious than others (Levine & McCornack, 1991). This trait called generalized state suspicion (GSS), when it works in conjunction with contextually aroused suspicion, has been shown to improve detection accuracy. The influence of GSS on cyber-risk perceptions and online phishing susceptibility remains unexplored and is yet another future research topic. Third, given cyber-risk beliefs’ role in motivating processing and influencing suspicion, future research needs to validate the measure. In the present model, cyber-risk beliefs subsume individual efficacy, experience, knowledge, and expertise, but the extent to which each of these factors shape these beliefs remain unknown and another important topic for future research.
Fourth, the study utilized suspicion as the dependent measure instead of utilizing the behavioral measure. This is partly keeping up with the best practices in online deception research, where there is a need for scaled measures that could capture the variance in individual deception likelihood, and partly because the dichotomous behavioral measure and the limited number of individuals who were not phished limited the ability to test for the differences among the modeled paths using SEM. While the t-test results provide an indirect test of the validity of using suspicion as the dependent measure, it is still plausible that some subjects’ responses on that measure were influenced by them knowing they were phished. Finally, the SCAM was tested using a simple, targeted link and attachment attack. Phishing attacks, however, vary in context and the types of appeals they utilize. Some are timed to take advantage of global events such as the Olympics; others are seasonal, such as the Internal Revenue System (IRS) tax-filing scams; still others craft appeals using catastrophes and natural disasters in an attempt to hook individuals who are interested in the incident. Although the SCAM is built to accommodate different types of attacks, the extent to which different appeals triggers different cognitive or preconscious considerations remains topics for future research.
Overall, the SCAM utilizes a handful of constructs to describe the underlying process of deception through different phishing attacks. In doing so, it provides a parsimonious explanation of prior research results. In earlier work, Wright and Marett (2010) examined a variety of behavioral predictors of phishing-deception success and found that computer self-efficacy, web experience, security knowledge, and trait-level suspicion (termed suspicion of humanity) reduced individual phishing susceptibility. Their research, however, did not explain the underlying cognitive processes that led to these factors reducing deception success. In other research, Vishwanath et al. (2011) 3 and Wang, Herath, Chen, Vishwanath, and Rao (2012) presented predictive models of phishing-deception likelihood that included cognitive factors but mostly ignored media habits and its antecedents. Through cyber-risk beliefs, deficient self-regulation, email habits, and the heuristic and systematic processing constructs, SCAM accounts for the experiential, dispositional, behavioral, and cognitive factors along with their theoretical linkages—thereby providing a more comprehensive explanation of the process of victimization through phishing.
The overall model is, thus, encompassing and rich enough to be used to explain other forms of online deception. Email-based attacks, where individuals are asked to fill-out credentials or respond with information; spoof attacks, where individuals are directed to fake online websites; social media scams involving fake profiles and requests; and text-message attacks on mobile devices that goad people to reactively click on a hyperlink, reply to a text, or download a mobile app, can potentially be explained using the SCAM.
In light of the inability of policy interventions to effectively curtail the rising tide of phishing attacks, the Secretary of Homeland Security Janet Napolitano had called for individuals to develop better “cyber-hygiene” by becoming more aware of their cyber risks and forming effective online habits (Spiering, 2013). The SCAM provides measures and explains the mechanism for forming and tracking individuals’ cyber-hygiene levels. IT managers could use the model framework to evaluate the cyber-risk perceptions and email habits of individuals in an organization on a priori basis and create targeted interventions based on individual cognitive and behavioral patterns. Finally, law enforcement and cyber-forensic specialists, two groups that are interested in understanding the reasons individuals fall victim to phishing attacks, could use the model to map the process of victimization. Thus, the SCAM’s constructs are rich in explanatory potential, and the model provides policy makers with a theoretical scaffold to develop and test interventions that effectively reduce individual susceptibility to email-based phishing.
Footnotes
Appendix A
Appendix B
Declaration of Conflicting Interests
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The authors received no financial support for the research, authorship, and/or publication of this article.
