Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability

Phishing attacks have become one of the most persistent forms of social engineering, exploiting human trust, emotions, habits, and decision-making rather than relying only on technical vulnerabilities.As digital communication continues to expand through email, social media, messaging applications, and online services, attackers are adopting increasingly sophisticated techniques such as impersonation, urgency-based manipulation, spear phishing, smishing, and AI-assisted phishing.This study examines the relationship between phishing attacks and human cybersecurity awareness, with particular emphasis on the factors that influence an individual's susceptibility to modern social engineering attacks.The research analyzes existing literature on phishing awareness, user behavior, psychological factors, phishing susceptibility, security awareness training, and social engineering techniques.It focuses on factors such as cybersecurity knowledge, attention, trust, urgency, familiarity, previous experience, demographic characteristics, and decision-making behavior.The study also examines the gap between users' perceived ability to identify phishing attacks and their actual ability to recognize deceptive messages.Furthermore, it evaluates whether conventional security awareness and phishing training are sufficient to produce long-term changes in user behavior.The findings from the reviewed literature indicate that cybersecurity awareness is important but does not necessarily guarantee resistance to phishing.Human decisions are influenced by contextual, psychological, and behavioral factors, while modern phishing messages are increasingly designed to appear legitimate and exploit users' expectations.Therefore, an effective defense strategy should combine user education, realistic phishing simulations, continuous awareness programs, behavioral analysis, technical security controls, and adaptive training approaches.The study highlights the importance of adopting a human-centered cybersecurity approach to reduce phishing susceptibility and improve individual and organizational resilience against evolving social engineering threats.

Authors

Publication Details

Journal
International Journal of Innovative Research in Technology
Published
2026-09-14
DOI
https://doi.org/10.64643/ijirt.208435-459
Primary Topic
Spam and Phishing Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability

Guna Dhondwad, Riddhi Shah, Tanvi Rakshe, Harshada Dhayagude
International Journal of Innovative Research in Technology
Spam and Phishing Detection
article

Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability

Guna Dhondwad, Riddhi Shah, Tanvi Rakshe, Harshada Dhayagude
article en

Abstract

Phishing attacks have become one of the most persistent forms of social engineering, exploiting human trust, emotions, habits, and decision-making rather than relying only on technical vulnerabilities.As digital communication continues to expand through email, social media, messaging applications, and online services, attackers are adopting increasingly sophisticated techniques such as impersonation, urgency-based manipulation, spear phishing, smishing, and AI-assisted phishing.This study examines the relationship between phishing attacks and human cybersecurity awareness, with particular emphasis on the factors that influence an individual's susceptibility to modern social engineering attacks.The research analyzes existing literature on phishing awareness, user behavior, psychological factors, phishing susceptibility, security awareness training, and social engineering techniques.It focuses on factors such as cybersecurity knowledge, attention, trust, urgency, familiarity, previous experience, demographic characteristics, and decision-making behavior.The study also examines the gap between users' perceived ability to identify phishing attacks and their actual ability to recognize deceptive messages.Furthermore, it evaluates whether conventional security awareness and phishing training are sufficient to produce long-term changes in user behavior.The findings from the reviewed literature indicate that cybersecurity awareness is important but does not necessarily guarantee resistance to phishing.Human decisions are influenced by contextual, psychological, and behavioral factors, while modern phishing messages are increasingly designed to appear legitimate and exploit users' expectations.Therefore, an effective defense strategy should combine user education, realistic phishing simulations, continuous awareness programs, behavioral analysis, technical security controls, and adaptive training approaches.The study highlights the importance of adopting a human-centered cybersecurity approach to reduce phishing susceptibility and improve individual and organizational resilience against evolving social engineering threats.

International Journal of Innovative Research in TechnologyVol. 13(5)
Peace, Justice and strong institutions
Openalex Percentile: Top 3%
Spam and Phishing Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability — Guna Dhondwad, Riddhi Shah, et al. · International Journal of Innovative Research in Technology (2026) | TGRS Research Map | TGRS