Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability

  • Unique Paper ID: 208435
  • PageNo: 118-125
  • Abstract:
  • Phishing attacks have become one of the most persistent forms of social engineering, exploiting human trust, emotions, habits, and decision-making rather than relying only on technical vulnerabilities. As digital communication continues to expand through email, social media, messaging applications, and online services, attackers are adopting increasingly sophisticated techniques such as impersonation, urgency-based manipulation, spear phishing, smishing, and AI-assisted phishing. This study examines the relationship between phishing attacks and human cybersecurity awareness, with particular emphasis on the factors that influence an individual's susceptibility to modern social engineering attacks. The research analyzes existing literature on phishing awareness, user behavior, psychological factors, phishing susceptibility, security awareness training, and social engineering techniques. It focuses on factors such as cybersecurity knowledge, attention, trust, urgency, familiarity, previous experience, demographic characteristics, and decision-making behavior. The study also examines the gap between users' perceived ability to identify phishing attacks and their actual ability to recognize deceptive messages. Furthermore, it evaluates whether conventional security awareness and phishing training are sufficient to produce long-term changes in user behavior. The findings from the reviewed literature indicate that cybersecurity awareness is important but does not necessarily guarantee resistance to phishing. Human decisions are influenced by contextual, psychological, and behavioral factors, while modern phishing messages are increasingly designed to appear legitimate and exploit users' expectations. Therefore, an effective defense strategy should combine user education, realistic phishing simulations, continuous awareness programs, behavioral analysis, technical security controls, and adaptive training approaches. The study highlights the importance of adopting a human-centered cybersecurity approach to reduce phishing susceptibility and improve individual and organizational resilience against evolving social engineering threats.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{208435,
        author = {Riddhi Shah and Tanvi Rakshe and Harshada Dhayagude and Guna Dhondwad},
        title = {Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {no},
        pages = {118-125},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=208435},
        abstract = {Phishing attacks have become one of the most persistent forms of social engineering, exploiting human trust, emotions, habits, and decision-making rather than relying only on technical vulnerabilities. As digital communication continues to expand through email, social media, messaging applications, and online services, attackers are adopting increasingly sophisticated techniques such as impersonation, urgency-based manipulation, spear phishing, smishing, and AI-assisted phishing. This study examines the relationship between phishing attacks and human cybersecurity awareness, with particular emphasis on the factors that influence an individual's susceptibility to modern social engineering attacks. 
The research analyzes existing literature on phishing awareness, user behavior, psychological factors, phishing susceptibility, security awareness training, and social engineering techniques. It focuses on factors such as cybersecurity knowledge, attention, trust, urgency, familiarity, previous experience, demographic characteristics, and decision-making behavior. The study also examines the gap between users' perceived ability to identify phishing attacks and their actual ability to recognize deceptive messages. Furthermore, it evaluates whether conventional security awareness and phishing training are sufficient to produce long-term changes in user behavior. The findings from the reviewed literature indicate that cybersecurity awareness is important but does not necessarily guarantee resistance to phishing. Human decisions are influenced by contextual, psychological, and behavioral factors, while modern phishing messages are increasingly designed to appear legitimate and exploit users' expectations. Therefore, an effective defense strategy should combine user education, realistic phishing simulations, continuous awareness programs, behavioral analysis, technical security controls, and adaptive training approaches. The study highlights the importance of adopting a human-centered cybersecurity approach to reduce phishing susceptibility and improve individual and organizational resilience against evolving social engineering threats.},
        keywords = {Phishing Attacks, Social Engineering, Human Awareness, Phishing Susceptibility, User Behavior, Cybersecurity Awareness, Security Awareness Training.},
        month = {September},
        }

Cite This Article

Shah, R., & Rakshe, T., & Dhayagude, H., & Dhondwad, G. (2026). Human Factors in Phishing Attacks: An Assessment of Awareness, Behavior, And Vulnerability. International Journal of Innovative Research in Technology (IJIRT), 118–125.

Related Articles