UTFacultiesBMSDept HIBPCRSInformation for studentsNew students assignmentsNew Master Thesis AssignmentsLet’s go phishing! - Real world investigation of the effectiveness of phishing attacks (GERMAN SPEAKERS ONLY

Let’s go phishing! - Real world investigation of the effectiveness of phishing attacks (GERMAN SPEAKERS ONLY

Description

Phishing remains one of the most persistent and effective attack vectors in the contemporary threat landscape, serving as the initial entry point for a substantial proportion of data breaches, ransomware incidents, and corporate espionage cases. Despite decades of technical countermeasures—spam filters, email authentication protocols, and browser-based warning systems—phishing continues to succeed because it exploits something arguably harder to patch than software: humans. Attackers craft messages that leverage psychological principles such as urgency, authority, trust, and social proof to bypass rational scrutiny, often achieving success rates that purely technical defenses fail to prevent. This makes phishing not merely a technical problem but a socio-technical one.

In this project there will be two waves of phishing attacks: one several weeks before half of the people receives a cyber security training (and the other half not), and the second wave of attacks several weeks after this intervention. The empirical backbone of this investigation will be a survey study, designed to measure participants' baseline and post-intervention knowledge of phishing tactics, alongside their real susceptibility to simulated phishing attempts. This dual measurement—what people know versus what they actually do when confronted with a realistic attack—is central to the study. A person who can correctly define phishing in a questionnaire may still click a malicious link under the right conditions. Quantitative data alone, however, can only tell part of the story. To understand not just whether individuals fell for an attack but why, follow-up interviews will be conducted with a subset of participants who were successfully phished. These conversations are intended to surface the specific vulnerabilities, assumptions, or momentary lapses in judgment that the survey data alone cannot capture. In doing so, the qualitative component of this thesis complements the experimental design, grounding the statistical findings in the lived, human experience of being deceived, and offering richer insight into where prevention efforts might be most meaningfully directed.

Thus – in short - in this thesis project you will conduct a study with a 2 (cyber security training intervention: yes or no) x 2 (time point: before or after intervention) design. You are expected to conduct a survey study to measure knowledge about phishing attacks and to evaluate the effectiveness of the intervention as well as the phishing attacks. Follow-up interviews with some of the victims are also desired in order to uncover what security vulnerabilities still exist.

This project will be carried out in close collaboration with several companies from Germany. Thus, German language skills are a necessity. Depending on the study outcome and setup, there is an opportunity to potentially visit a conference.

Research Questions

- Are preventative and informational anti-phishing workshops effective at reducing the vulnerabilities?

- What is the rationale of victims and what vulnerabilities can be exploited?


Type of Research

Experimental research; mixed methods

Key words

Phishing, Social Engineering, Cyber security, mixed methods, social cognitive theory, protection motivation theory, risk perception, principles of persuasion

Information

If you are interested in this topic, please contact Iris van Sintemaartensdijk via i.vansintemaartensdijk@utwente.nl.  

Start

Flexible. The internship with the same name is a prerequisite to the thesis. 

Literature

- Khonji, M., Iraqi, Y., & Jones, A. (2013). Phishing detection: a literature survey. IEEE Communications Surveys & Tutorials, 15(4), 2091-2121.

- Varshney, G., Kumawat, R., Varadharajan, V., Tupakula, U., & Gupta, C. (2024). Anti-phishing: A comprehensive perspective. Expert Systems with Applications, 238, 122199.

- Kavvadias, A., & Kotsilieris, T. (2025). Understanding the role of demographic and psychological factors in users’ susceptibility to phishing emails: A review. Applied Sciences, 15(4), 2236.

- Arévalo, D., Valarezo, D., Fuertes, W., Cazares, M. F., Andrade, R. O., & Macas, M. (2023, July). Human and cognitive factors involved in phishing detection. A literature review. In 2023 Congress in Computer Science, Computer Engineering, & Applied Computing (CSCE) (pp. 608-614). IEEE.

- Chaiken, S., Wood, W., & Eagly, A. H. (1996). Principles of persuasion.

- Crano, W. D., & Prislin, R. (2006). Attitudes and persuasion. Annu. Rev. Psychol., 57(1), 345-374.

- Ferreira, A., Coventry, L., & Lenzini, G. (2015, July). Principles of persuasion in social engineering and their use in phishing. In International Conference on Human Aspects of Information Security, Privacy, and Trust (pp. 36-47). Cham: Springer International Publishing.

- Black, J., & Sarno, D. M. (2023, September). The influence of time pressure and persuasion principles on phishing detection. In Proceedings of the Human Factors and Ergonomics Society Annual Meeting (Vol. 67, No. 1, pp. 1977-1982). Sage CA: Los Angeles, CA: SAGE Publications.

- Ferreira, A., & Teles, S. (2019). Persuasion: How phishing emails can influence users and bypass security measures. International Journal of Human-Computer Studies, 125, 19-31.

- Jones, K. S., Armstrong, M. E., Tornblad, M. K., & Siami Namin, A. (2021). How social engineers use persuasion principles during vishing attacks. Information & Computer Security, 29(2), 314-331.