Int J Performability Eng ›› 2026, Vol. 22 ›› Issue (9): 495-503.doi: 10.23940/ijpe.26.09.p1.495503

    Next Articles

Fool Me Once, Shame on You: A Comparison of Generic and Inoculation-Based Warnings for Phishing Email Identification

Imani Bellamya, Chih-Wei Hsub,*, and Zizhao Chenb   

  1. aCoppin State University, Baltimore, Maryland, USA;
    bDepartment of Computer Science, The University of Texas at Dallas, Texas, USA
  • Submitted on ; Revised on ; Accepted on
  • Contact: *E-mail address: cxh210019@utdallas.edu

Abstract: Cybercriminals increasingly exploit psychological vulnerabilities and software design weaknesses to deceive users across trusted digital platforms. This study explores patterns among self-reported stress, impulsivity, online behaviors, and phishing-identification performance. Young adults frequently experience emotionally demanding circumstances, including job searches, financial deadlines, and academic stress, that may increase susceptibility to deceptive communications. The study also compares phishing-identification accuracy and confidence among participants who received no warning, a generic warning, or an inoculation-style warning. Grounded in the Heuristic-Systematic Model (HSM) and Cyber-Routine Activity Theory (Cyber-RAT), the study examines how emotional states and routine online behaviors may relate to decision-making during simulated phishing encounters. Participants completed a pre-survey assessing emotional state and online behavior prior to phishing exposure. They were then randomly assigned to receive either no warning, a generic security tip, or a targeted inoculation message designed to reduce susceptibility to phishing. Participants then completed a simulated phishing task using emotionally salient emails (e.g., fake job offers or tuition warnings) to assess trust judgments and response patterns. Participants in the inoculation-warning group showed the highest average accuracy and confidence, while findings involving stress, impulsivity, and online behaviors remained exploratory. By integrating emotional psychology, digital behavior, and preventive intervention strategies, this study provides insight into the psychological factors underlying susceptibility to cyber-enabled fraud. The findings may inform the development of targeted prevention strategies and real-time awareness tools to reduce vulnerability to online deception among young adults.

Key words: cyber-enabled fraud, phishing susceptibility, psychological vulnerability, heuristic-systematic model (HSM), cyber-routine activity theory (Cyber-RAT), inoculation theory