Pablo López-Aguilar , Carlota Urruela , Edgar Batista , Juvenal Machin , Agusti Solanas
{"title":"Phishing vulnerability and personality traits: Insights from a systematic review","authors":"Pablo López-Aguilar , Carlota Urruela , Edgar Batista , Juvenal Machin , Agusti Solanas","doi":"10.1016/j.chbr.2025.100784","DOIUrl":null,"url":null,"abstract":"<div><div>Phishing attacks have gained prominence and effectiveness over the years. Although many efforts are devoted to combat them, generic anti-phishing awareness and training campaigns have shown limited success. In this context, considering individuals’ personality traits in relation to phishing behaviour could significantly enhance cybersecurity defence strategies. In this article, we concentrate on personality traits and their effects on vulnerability to phishing attacks. We implement a rigorous systematic review following the methodology proposed by vom Brocke et al. (2009) along with the PRISMA statement. We searched five major databases (<em>i.e.,</em> Web of Science, Scopus, IEEE Xplore, ACM Digital Library, and PubMed), with an all-years’ time span from 1900 to January 2025. From the 1919 articles yielded in the initial search, 26 satisfied all criteria. Results reveal that extraversion, agreeableness, and neuroticism generally show a positive association with phishing vulnerability, whereas conscientiousness emerges as a protective factor. The review also highlights significant gaps in the current methodologies used to measure phishing vulnerability, noting a lack of standardised measurement tools to perform phishing experiments. Finally, this study underscores the need to develop secondary prevention strategies targeting at-risk groups to combat the increasingly sophisticated phishing threats. To enhance consistency in future research, the Appendix includes guidelines for measuring phishing vulnerability under experimental conditions.</div></div>","PeriodicalId":72681,"journal":{"name":"Computers in human behavior reports","volume":"20 ","pages":"Article 100784"},"PeriodicalIF":5.8000,"publicationDate":"2025-08-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers in human behavior reports","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S245195882500199X","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"PSYCHOLOGY, EXPERIMENTAL","Score":null,"Total":0}
引用次数: 0
Abstract
Phishing attacks have gained prominence and effectiveness over the years. Although many efforts are devoted to combat them, generic anti-phishing awareness and training campaigns have shown limited success. In this context, considering individuals’ personality traits in relation to phishing behaviour could significantly enhance cybersecurity defence strategies. In this article, we concentrate on personality traits and their effects on vulnerability to phishing attacks. We implement a rigorous systematic review following the methodology proposed by vom Brocke et al. (2009) along with the PRISMA statement. We searched five major databases (i.e., Web of Science, Scopus, IEEE Xplore, ACM Digital Library, and PubMed), with an all-years’ time span from 1900 to January 2025. From the 1919 articles yielded in the initial search, 26 satisfied all criteria. Results reveal that extraversion, agreeableness, and neuroticism generally show a positive association with phishing vulnerability, whereas conscientiousness emerges as a protective factor. The review also highlights significant gaps in the current methodologies used to measure phishing vulnerability, noting a lack of standardised measurement tools to perform phishing experiments. Finally, this study underscores the need to develop secondary prevention strategies targeting at-risk groups to combat the increasingly sophisticated phishing threats. To enhance consistency in future research, the Appendix includes guidelines for measuring phishing vulnerability under experimental conditions.
多年来,网络钓鱼攻击变得越来越突出和有效。尽管许多努力致力于打击它们,但普遍的反网络钓鱼意识和培训活动显示出有限的成功。在这种情况下,考虑个人的人格特征与网络钓鱼行为的关系可以显著提高网络安全防御策略。在本文中,我们将集中讨论人格特征及其对网络钓鱼攻击脆弱性的影响。我们按照vom Brocke等人(2009)提出的方法以及PRISMA声明进行了严格的系统审查。我们检索了五个主要数据库(即Web of Science, Scopus, IEEE Xplore, ACM Digital Library和PubMed),时间跨度从1900年到2025年1月。在最初检索的1919篇文章中,有26篇符合所有标准。结果表明,外倾性、亲和性和神经质与网络钓鱼脆弱性普遍呈正相关,而尽责性则是保护因素。该审查还强调了目前用于测量网络钓鱼漏洞的方法的重大差距,指出缺乏执行网络钓鱼实验的标准化测量工具。最后,本研究强调需要针对高危人群制定二级预防策略,以对抗日益复杂的网络钓鱼威胁。为了增强未来研究的一致性,附录中包含了在实验条件下测量网络钓鱼脆弱性的指南。