Publisher DOI: 10.1145/3733155.3736796
Title: Emotional manipulation in phishing emails : experimental study of affective responses and human classification errors in a simulated email environment
Authors: Wiemken, Mika 
Hildebrandt, Kilian 
Jeworutzki, André  
Putzar, Larissa 
Other : Association for Computing Machinery 
Keywords: Affective Computing; Electrodermal Activity; Email Security; Facial Expression Recognition; Phishing; User Behavior
Issue Date: 17-Jul-2025
Publisher: Association for Computing Machinery
Part of Series: Proceedings of The 18th ACM International Conference on PErvasive Technologies Related to Assistive Environments (PETRA 2025) : June 25– June 27, Corfu, Greece 
Startpage: 583
Endpage: 589
Conference: ACM International Conference on PErvasive Technologies Related to Assistive Environments 2025 
Abstract: 
Phishing emails are a type of social engineering designed to extract sensitive information from individuals and organizations. Phishing attacks can exploit psychological mechanisms - such as fear and urgency - to trigger impulsive decision-making and security errors. Given the growing threat of phishing in recent years, this paper investigates emotional manipulation through phishing emails by examining affective and behavioral responses in a simulated email environment. To investigate how emotional triggers affect user susceptibility, a laboratory-based study was conducted using simulated email scenarios that closely resembled typical workplace communication patterns, enabling detailed tracking of multimodal responses. Participants interacted with legitimate and phishing emails while their facial expressions, electrodermal activity, and decision behaviors were recorded.Statistical analysis revealed significant correlations between physiological stress indicators and increased susceptibility to various decision-making errors - such as replying to, archiving, or failing to flag phishing emails - particularly when participants were exposed to emotionally charged messages. The findings underscore the need for cybersecurity training approaches that incorporate psychological and emotional dimensions. By identifying key affective states associated with security lapses, this research contributes to the design of more effective awareness strategies and affect-sensitive defense mechanisms.
URI: https://hdl.handle.net/20.500.12738/18195
ISBN: 979-8-4007-1402-3
Review status: This version was peer reviewed (peer review)
Institute: Department Informatik 
Fakultät Technik und Informatik 
Department Medientechnik 
Fakultät Design, Medien und Information 
Type: Chapter/Article (Proceedings)
Appears in Collections:Publications without full text

Show full item record

Google ScholarTM

Check

HAW Katalog

Check

Add Files to Item

Note about this record


This item is licensed under a Creative Commons License Creative Commons