Skip to article sections
Purpose

This study aims to identify and analyse the persuasive principles employed in phishing emails through a detailed content analysis of both email subject lines and entire email contents. It investigates how these persuasion principles differ between subject lines and full email content, examines trends in their use over time and identifies common combinations of persuasion strategies used by attackers.

Design/methodology/approach

A qualitative content analysis was conducted on 200 phishing email samples selected systematically over a ten-year period from the phishing database. The analysis employed NVivo software, guided by the Principles of Human Persuasion in Social Engineering framework proposed by Ferreira and Teles (2019). This framework facilitated systematic coding based on five main principles (Authority, Social Proof, Deception, Distraction and Integrity) and their sub-principles.

Findings

The analysis revealed distinct differences in the application of persuasion principles between email subject lines and entire email contents. Subject lines predominantly employed Authority and Distraction to elicit immediate responses, while full email content relied more heavily on Deception, Distraction, Integrity and Reciprocation to construct convincing narratives. Trends indicated an evolving strategic shift among attackers, highlighting increased usage of Deception and decreased reliance on Authority over time. Additionally, the most frequent combinations identified were Authority with Distraction for subject lines, and Deception with Distraction and Integrity for entire email contents.

Practical implications

Findings from this study suggest that phishing detection systems and training programs must be designed with sensitivity to nuanced persuasion techniques. Training should emphasize recognizing subtle persuasive cues in full email narratives in addition to immediate triggers present in subject lines, adapting to evolving phishing methodologies over time.

Originality/value

Unlike previous studies primarily focused on user vulnerabilities, this research uniquely examines how attackers strategically apply persuasion principles within phishing emails themselves, considering both immediate (subject lines) and extended (email content) engagement. This dual-level, temporally comparative analysis provides deeper insight into the evolution and complexity of phishing tactics, particularly relevant in the era of generative artificial intelligence that minimizes detectable technical errors in phishing communications.

Phishing, as defined by the Anti-Phishing Working Group (APWG, 2024), is a crime that employs social engineering and technical subterfuge to steal personal identity data and financial account credentials. This definition highlights the dual nature of phishing attacks, which exploit both human psychology and technological vulnerabilities to achieve their malicious objectives (Kheruddin et al., 2024). Social engineering tactics are particularly effective because they manipulate unsuspecting individuals into believing they are interacting with a trustworthy source. This often involves using misleading subject lines or crafting emails that appear legitimate, thereby increasing the likelihood that victims will disclose sensitive information (Ferreira et al., 2015).

Research indicates that despite ongoing efforts to educate users about phishing, many individuals still fall victim to these attacks. For instance, a report from the Australian Competition and Consumer Commission (ACCC, 2024) revealed that 66,286 phishing emails were reported in Australia by October 2024, resulting in significant financial losses totalling over $32m this year. Furthermore, the APWG recorded 877,536 phishing attacks in the second quarter of 2024, indicating a stable yet alarming prevalence of these incidents. This persistence suggests that while users may receive training to recognize phishing attempts, the sophistication of the tactics employed by phishers continues to evolve, necessitating a shift in research focus from user vulnerabilities to the characteristics of phishing emails themselves (Ojugo and Nwankwo, 2021; Zielinska et al., 2016).

The aim of this study is to analyse the phishing email samples based on Principles of Human Persuasion in Social Engineering, as they are applied to the content and subject lines of phishing emails. Ferreira and Teles (2019) provided a framework for understanding how social engineering exploits psychological and persuasive principles to manipulate individuals into complying with requests for sensitive information. By examining both the content and subject lines of phishing emails, this study seeks to identify the specific or combination of persuasion principles as social engineering tactics that phishers employ to effectively convince victims to disclose their personal information. This approach is crucial, as understanding the methods used by attackers can inform the development of more effective countermeasures and training programs (Alsharif et al., 2022).

Butavicius et al. (2016) found that individuals exhibiting lower impulsivity in decision-making were generally less likely to perceive fraudulent email links as safe and lower cognitive impulsivity can protect against spear phishing. This underscores the importance of considering individual personality differences and characteristics when developing tailored phishing awareness training programs. Valuable insights for personalizing such training can also be obtained by analysing the crafting techniques employed in phishing emails. Moreover, research highlights that while phishing awareness training significantly enhances users’ initial ability to identify phishing emails, the retention of this knowledge diminishes over time, particularly when encountering novel or sophisticated phishing techniques (Kalio, 2022), underscoring the necessity for continuous education and regular reinforcement aligned with evolving phishing trends to maintain user vigilance (Shi et al., 2021).

Furthermore, phishing attacks leverage psychological manipulation through social engineering, using deceptive tactics to exploit human emotions, obedience and vulnerabilities for accessing sensitive information such as usernames and passwords (Naz et al., 2024); attackers often employ emotionally charged language, creating urgency or fear to compromise rational decision-making (Sharma and Bashir, 2020), making the understanding of these psychological triggers critical to developing effective phishing countermeasures (Abroshan et al., 2021).

The complex nature of phishing attacks requires an extensive approach that addresses both user susceptibilities and the strategies used by attackers. This study focuses on the Principles of Human Persuasion in Social Engineering to explore how these tactics are leveraged by phishers to manipulate victims. Additionally, it aims to identify trends and conduct comparative analyses over different time periods, highlighting the latest developments.

Understanding combinations of persuasion principles is critical because real-world phishing emails rarely rely on a single tactic in isolation. Combinations create layered, more convincing messages that are harder for users – and automated systems – to detect. This complexity represents a significant challenge for cybersecurity awareness training programs, phishing simulation designers and anti-phishing software developers. By identifying the most common patterns of these combinations, our findings can inform training that exposes users to realistic, multi-cue attack scenarios, improving their ability to recognize sophisticated phishing attempts. Although teaching users to detect such intricate combinations may seem challenging, explicitly highlighting these patterns can increase awareness of subtle manipulation tactics and strengthen overall defensive strategies.

Research Questions:

RQ1.

How do the use and frequency of individual principles of persuasion differ between email subject lines and the full email content?

RQ2.

What broad shifts in the use of persuasion principles are observable over time in phishing emails?

RQ3.

What combinations of persuasion principles are used in phishing emails?

Recent studies have increasingly focused on understanding the principles of persuasion used in social engineering attacks across different cybersecurity fields (Khadka et al., 2023). Cialdini’s six principles of persuasion authority, social proof, liking/similarity, commitment/consistency, scarcity and reciprocation are among the most studied principles in phishing. Among these, authority and distraction have been identified as particularly effective in phishing emails (Ferreira et al., 2015). Meanwhile, the use of commitment/consistency and scarcity has increased over time, while reciprocation and social proof have seen a decline (Zielinska et al., 2016).

Research has consistently demonstrated that use of these principles as manipulation tactics significantly enhances the effectiveness of phishing attacks. Cialdini’s six principles authority, social proof, scarcity, liking, commitment and reciprocity have been adapted by attackers to exploit human vulnerabilities and induce compliance (Bayl-Smith et al., 2021; Lawson et al., 2017). Phishers often utilize heuristic cues including authority, urgency and familiarity to persuade users into acting swiftly without fully analysing the content of the message (Frauenstein and Flowerday, 2020). Individuals with personality traits like neuroticism or openness may be particularly vulnerable to these tactics due to heightened emotional reactivity or curiosity. Persuasive strategies are often customized to elicit emotional responses or appeal to a user’s desire for novelty or exclusivity. According to Frauenstein and Flowerday (2020), personality traits, such as agreeableness, also play a significant role in determining an individual’s susceptibility to phishing attacks. Individuals with specific characteristics may be more easily swayed by persuasive tactics and cognitive biases, for example, attackers often impersonate familiar individuals or brands to foster trust (social proof) or simulate a crisis to instil fear (Frauenstein and Flowerday, 2020), suggesting the need for tailored interventions based on individual needs.

Content analysis has been instrumental in revealing the range of strategies used to elicit emotional responses in phishing attacks. Kim and Hyun Kim (2013) conducted an in-depth analysis of phishing messages, categorizing them into rational and emotional appeals. They found that emotional appeals, such as the fear of loss or the promise of rewards, were particularly effective in persuading recipients to engage with phishing content. These findings align with Taib et al. (2019), who emphasized that phishing emails often leverage established psychological principles to enhance perceived credibility while reducing recipients’ critical evaluation.

The role of subject lines in phishing emails is crucial as well, as they serve as the first point of engagement. Studies have found that subject lines invoking urgency or fear, such as “Immediate Action Required: Verify Your Account,” are more likely to elicit responses than neutral or vague alternatives (Atkins and Huang, 2013; Williams and Polage, 2019). This effectiveness is further corroborated by Harrison et al. (2016) and Ferreira and Teles (2019), who highlighted how persuasive elements in subject lines affect users’ cognitive processing of phishing emails and effectiveness of it.

The impact of phishing emails is further amplified when messages are tailored to fit the recipient’s context or interests, a tactic referred to as contextualization and personalization or spear phishing (Khadka et al., 2023). Tambe Ebot (2019) argued that personalized messages, especially those referencing recent interactions or transactions, significantly increase perceived legitimacy and reduce scepticism. By making phishing email attempts appear relevant to the recipient’s recent activities, attackers can effectively lower their guard and prompt action.

The application of persuasion principles extends beyond email phishing to other types of social engineering attacks. Research shows that social engineering attacks exploit these principles to manipulate targets, significantly influencing risk-taking behaviours across different cultural contexts (Goodman-Delahunty and Howes, 2016).

The development of detection systems based on three principles (i.e. Authority, Reciprocation and Scarcity) out of Cialdini’s six principles of persuasion has shown promising results in identifying phishing emails through the presence of manipulative tactics (Li et al., 2020). Such insights have applications in user training, improvement of security software and the design of effective defences against phishing (Ferreira and Lenzini, 2015; Zielinska et al., 2016).

While Cialdini’s principles provide a strong foundation for understanding phishing, they were originally developed for marketing and general communication, which may not fully capture the nuances of phishing in electronic contexts. To address this gap, Ferreira and Teles (2019) proposed a specialized framework called Principles of Human Persuasion in Social Engineering that draws upon foundational research by Cialdini (2007), Gragg (2003) and Stajano and Wilson (2011), offering a more targeted approach for social engineering.

Gragg (2003) identified key psychological triggers that enhance the effectiveness of social engineering, such as strong affect, overloading, reciprocation, deceptive relationships, diffusion of responsibility, moral duty, authority and integrity. Stajano and Wilson (2011) added a broader perspective, analysing how victims fall prey to fraudsters. Ferreira and Teles (2019) adapted these insights into a framework specific to phishing, recognizing the limitations of broad principles of persuasion and focusing on those directly relevant to manipulating email recipients.

Although significant research has explored the psychological underpinnings of phishing, gaps remain in understanding how these principles adapt to evolving communication technologies and sophisticated attack. Consequently, education and awareness become crucial for enabling users to recognize the subtle discrepancies present in phishing attempts. Our earlier literature review shows that much of the current research has focused on users’ profile like demographic factors that influence susceptibility to phishing rather than the evolving strategies and the complex mechanics of phishing attacks as well as sources of the phishing attacks itself which is designed using the persuasive tactics (Lawson et al., 2019). Moreover, the adaptability of phishing methods is evident in the shift from generic attacks to more targeted campaigns such as spear phishing, advanced persistent threats (APTs) and whaling (Do et al., 2022).

The literature review highlights that previous studies have primarily focused on Cialdini’s principles of persuasion. However, there is a significant gap in research exploring how combinations of these principles are applied in phishing attacks. Most studies examine individual principles in isolation, overlooking their potential synergistic or antagonistic interactions. Additionally, earlier research has largely centred on how users are affected by these principles; this study shifts the focus to understanding the phishers’ approach. This perspective is crucial as traditional automated detection systems often depend on identifying technical errors, such as spelling and grammatical mistakes. However, with the advent of generative artificial intelligence (AI), such errors are likely to diminish, necessitating a deeper investigation into the use of persuasion tactics throughout the entirety of phishing emails.

This study seeks to extend the framework of Principles of Human Persuasion in Social Engineering, as integrated by Ferreira and Teles (2019), by conducting a comprehensive analysis of both the subject lines and full content of phishing emails. This dual-level analysis provides a holistic perspective on how attackers craft their messages to exploit principles of persuasion effectively. The study enhances our understanding on how specific tactics, including combinations of different principles, are employed to manipulate recipients effectively. By comparing and analysing trends over time between subject lines and full email content, this research intends to reveal temporal differences in the application of persuasive strategies, thereby providing insights that may contribute to the development of improved phishing detection and defence mechanisms.

This study examines and analyses data collected from both the full email content and email subject lines to address the research questions. A qualitative research approach was employed, utilizing content analysis as the primary method. NVivo software was used to conduct this content analysis, allowing for systematic coding, categorization and examination of persuasive elements in phishing emails based on the principles of persuasion. NVivo is a qualitative data analysis software developed by QSR International, designed to facilitate the organization, management and analysis of qualitative data. It provides researchers with a comprehensive set of tools that support various analytical approaches, including thematic analysis and coding, which are essential for extracting meaningful insights from qualitative data (Limna, 2023). The data were analysed using deductive content analysis, guided by the Principles of Human Persuasion in Social Engineering as defined by Ferreira and Teles (2019). Deductive analysis, or deductive reasoning, in qualitative research involves applying pre-existing theories or frameworks to analyse data systematically. In this study the email content and subjects were studied qualitatively, based on defined Principles of Human Persuasion in Social Engineering. Specifically, five major principles were used to analyse the phishing emails and their subjects. Two study was conducted: first, the email subject lines was examined just like Ferreira and Teles (2019) has conducted the study. In a subsequent study, the entire email content, along with the subject, was analysed once. For the coding process, to guide the deductive reasoning, the following main principles and sub-principles integrated by Ferreira and Teles (2019) were used:

  1. Authority (P1)

  2. Social Proof (P2)

    • Herd (P2.1)

    • Diffusion of Responsibility (P2.2)

    • Moral Duty (P2.3)

  3. Deception (P3)

    • General Deception (P3.1)

    • Deceptive Relationship (P3.2)

    • Liking and Similarity (P3.3)

  4. Distraction (P4)

    • Scarcity (P4.1)

      • Scarcity of Time (P4.1.1)

      • Scarcity by Other Factors (P4.1.2) (excluding scarcity of time)

    • Overloading (P4.2)

      • Overloading by Time (P4.2.1

      • Overloading by Other Factors (P4.2.2) (excluding the time)

    • Strong Affect (P4.3)

    • Need and Greed (P4.4)

  5. Integrity (P5)

    • Integrity (P5.1)

    • Consistency (P5.2)

    • Commitment (P5.3)

      • Commitment by Dishonesty (P5.3.1) (excluding commitment by other factors)

      • Commitment by Other Factors (P5.3.2) (excluding commitment by dishonesty)

    • Reciprocation (P5.4)

This coding process allowed for a structured analysis of the phishing emails based on established principles of persuasion in social engineering. These principles are particularly suitable in a social engineering context because they bridge gaps between different aspects of human vulnerabilities and weaknesses making them a comprehensive tool for analysis. Notably, other researchers, namely, Ahmad et al. (2023), Akdemir and Yenal (2021), Ferreira and Teles (2019) and Jones et al. (2020), have validated these principles across various social engineering attacks, including vishing (voice phishing), email subjects, coronavirus themed phishing emails and mobile instant message phishing, further validating their applicability and relevance in broader cybersecurity studies.

This study analysed 200 phishing email samples, systematically selected to ensure representative coverage over a ten-year period (2014–2023). This sample size is consistent with standard practices established by Ferreira and Teles (2019) and Akbar (2014) in phishing email research, where the typical range analysed in literature is between 200 and 250 samples. Furthermore, variability analysis demonstrated that stable patterns were observed after 180 samples, supporting the selection of a 200-sample data set. Specifically, 20 phishing emails were randomly sampled from each year using a random sampling tool available at Link to calculatorsoupLink to the Website. The decision to sample 20 emails per year was guided by the need to balance manageable qualitative coding with the goal of identifying temporal trends over a ten-year period. This consistent yearly sampling ensures the ability to detect variations in persuasive strategies over time while maintaining depth of analysis. Additionally, preliminary variability analysis demonstrated stable patterns after approximately 180 samples, supporting the adequacy of our 200-sample data set for capturing representative trends. We acknowledge, however, that larger yearly samples might further refine detection of subtle temporal shifts, which future research could explore. These emails were obtained from the Millersmiles.co.uk archive, a comprehensive database consisting of approximately 285,641 phishing emails collected from 2003 to 2024. From the various categories of emails in the Millersmiles.co.uk database, the phishing email category spanning March 2005 to November 2024 was used, containing a total of 33,363 phishing email samples. Then, last ten-year frame from January 2014 to December 2023 was selected. The selection process was conducted twice: once for analysing the full email content and another for analysing only the email subjects.

The next step involved case classification based on the entities of the ontological model of social engineering by Mouton et al. (2014). The entities used are target and goal of the phishing attacks. The entity “target” attribute values were either individuals or organizations, while the goals of the phishing attacks were categorized as financial gain, unauthorized access or service disruption. Following these classifications, each email sample was individually coded.

From the 200 phishing emails, while looking at the entities of the phishing email attacks based on the ontological model in accordance with Mouton et al. (2014), three primary goals were identified: service disruption, with very minimal cases; financial gain, observed in 78 cases; and unauthorized access, accounting for 121 instances. Notably, all phishing emails in this sample specifically targeted individuals not the organization.

The study by Ferreira and Teles (2019) identified common social engineering principles used in phishing email subject lines. In the following section, their findings will be compared with the results from this study’s analysis of email subject lines data as shown in Table 1, to highlight changes.

Ferreira and Teles (2019) identified Authority in 119 sources and 139 references, suggesting that phishing subject lines effectively leveraged the credibility of authoritative figures or entities to gain users’ trust. In this analysis (2024), there was a slight decline (104 files, 105 references).

In Ferreira and Teles’ study, the Deception principle was minimally used in subject lines (seven sources, seven references). Conversely, this study found Deception in 21 files, reflecting a significant increase.

Distraction was used frequently in Ferreira and Teles’s study with 139 sources and 146 references. In this analysis, the occurrence decreased (109 files, 120 references), suggesting attackers are now complementing distraction with other principles. The use of Integrity increased slightly from 88 sources to 94 sources in the current study, indicating an increased effort by attackers to appear credible.

A comparison between 2019 and 2024 data reveals evolving phishing tactics see Figure 1: while the use of Authority has declined, Deception has increased significantly in subject lines and the Integrity principle’s growth suggests a strategic shift towards creating a false sense of honesty. The General Deception sub-principle was rarely present in Ferreira and Teles’s (2019) study but showed a substantial increase in this study. The sub-principles like Scarcity and Overloading by Time were notably present in this study data but not in Ferreira and Teles’s study.

The comparison between the subject line and the entire email content analysis highlights few key insights. The Authority, Distraction and Deception principles are commonly used across both subject lines and entire email content, but their application differs significantly (see Table 1 and Table 2). Authority is often employed in subject lines; whereas, in the full email content, the Deception, Distraction and Reciprocation were used equally.

Subject lines primarily employ tactics that can achieve instant results, such as creating urgency or exploiting authority, to prompt the reader to open the email. Entire email content, however, is more strategically designed to establish a narrative that influences the recipient’s decision-making process, encouraging deeper engagement with the content.

As shown in Table 3 and Figure 2, Authority is used moderately across all years, beginning with 11 in 2014, then showing a decline to 5 in 2016. A peak appears in 2020 at 14, indicating a resurgence in the usage of authority-based tactics to influence recipients to engage with phishing emails. The high value in 2020 might indicate a preference for leveraging authority during a period of global uncertainty, possibly to exploit the environment of crisis, such as the COVID-19 pandemic. According to Parsons et al. (2019), the presence of authority in the subject line is particularly compelling because the first impression is crucial, which directly supports the consistency of Authority in our data set.

Deception remains relatively low throughout all years, with values peaking at 6 in 2015 and then declining significantly thereafter, becoming absent in 2022 and 2023. This indicates that overt deception in subject lines might not be an effective tactic for phishing campaigns in recent years, possibly because such direct deception is more easily recognized by both recipients and automated filters. Williams et al. (2017) highlighted that deception tactics may be more effective when subtle in the subject line, as an overtly deceptive subject can increase the risk of being flagged by automated spam detection systems. The observed low frequency may also be due to the effectiveness of subtle emotional triggers in phishing emails, rather than explicit deception, as noted by Bakhshi et al. (2009).

Distraction shows a consistent presence throughout the years, with its highest usage at 14 in 2017 and 2021. This principle remains a steady tool, varying between 10 and 14 in most years. The findings by Vishwanath et al. (2011) suggested that distraction as a tactic works particularly well when attackers attempt to overwhelm recipients with an ambiguous or vague message. In the subject line, such distraction could serve as a means to stimulate curiosity (e.g., “Regarding your recent purchase”), which is reflected in moderate use across multiple years.

Integrity starts high in 2014 at 17 and continues with some fluctuations, peaking again in 2018 at 16. However, its usage decreases to a lower value of 4 by 2021 before slightly recovering to 8 in 2023.

Social proof is entirely absent across all years in email subject lines. This outcome suggests that this tactic, which relies on demonstrating group behaviour or consensus, is not suitable or effective for phishing email subject lines. Attackers might find it difficult to convincingly convey a sense of social endorsement within the short and direct format of a subject line. Cialdini (2007) describes social proof as contextually powerful, particularly in environments with visible peer actions.

Figure 3 depicts the trends in the use of five different principles of persuasion Authority (P1), Deception (P3), Distraction (P4), Integrity (P5) and Social Proof (P2) in phishing emails from the years 2014–2023. Each line represents the frequency of usage for a particular principle in phishing email subject lines over these years.

As shown in Table 4, the use of authority as a persuasive principle has shown a steady increase over the years, particularly peaking in 2021. From a relatively low usage in 2014 and 2015, its frequency rose significantly by 2021, indicating that phishers might have begun increasingly relying on authoritative messages to gain users’ trust. In a study by Parsons et al. (2019), authority was highlighted as one of the most influential principles used in phishing attacks.

The Deception (P3) principle has had notable peaks, particularly in 2019 and 2021, suggesting that during these years, there was an increased focus on misleading recipients as part of the phishing strategy. The sudden spike in 2019 followed by a drop in 2020 and a subsequent rise again in 2021 indicates fluctuations that may be related to varying strategies based on user response to previous phishing campaigns or global context of that period. Bakhshi et al. (2009) noted that deception is a core element in social engineering attacks, often involving misleading or impersonating trusted sources. The consistent high frequency observed here aligns with research findings that deception is a foundational strategy in phishing. According to Jakobsson and Myers (2007), phishing is inherently deceptive, involving false promises and forged identities.

Distraction (P4) has generally remained at a moderate frequency throughout the observed years, but it saw a notable increase in 2019 and 2021. This could imply that attackers used distraction alongside deception during these years. Research by Vishwanath et al. (2011) highlighted the use of cognitive overload and distraction as a means of influencing target behaviour in phishing. While our study shows moderate use, Vishwanath’s work suggested that attackers use distraction to exploit divided attention, which can be context specific. The variability in distraction could be influenced by factors such as the target’s environment or broader social factors, as suggested by Vishwanath et al. (2011), where people with heavy workloads or multitasking tendencies are more vulnerable to distraction tactics.

The principle of Integrity (P5) also follows a consistent pattern with a moderate level of use across the years, but it saw a peak in 2021. Aleroud and Zhou (2017) described how attackers often try to appear trustworthy or sincere in phishing emails to foster credibility. The frequency in this study data set may represent attempts to balance apparent integrity with other manipulative techniques. The moderate and fluctuating use of integrity also aligns with Workman (2008), who argued that maintaining a facade of trustworthiness is important for some types of attacks, but it may not be as necessary in all phishing contexts, leading to the observed variability.

Social Proof (P2) appears to be almost non-existent, with only a few instances recorded across all years, specifically in 2016, 2018 and 2022. This suggests that phishers rarely rely on social proof in while creating phishing email, possibly because it is less effective or harder to leverage in email compared to other principles. The lack of social proof usage could also be linked to the nature of the email context. Research by Williams et al. (2017) showed that social proof, such as testimonials or herd behaviour, may be more effective in social media scams rather than emails, which may be the reason of minimal use in phishing emails.

As shown in the Table 5 and Figure 4; the most frequently used combination in email subjects is Authority (P1) + Distraction (P4), which appear 52 times. Authority (P1) + Integrity (P5) is the second most common combination, with 46 occurrences. The combination Distraction (P4) + Integrity (P5) occurs 24 times, indicating a strategy where phishers aim to create confusion while presenting a trustworthy facade in the email subject.

Authority (P1) + Deception (P3) appears 12 times. Authority (P1) + Distraction (P4) + Integrity (P5), with 9 instances, implies a subtle approach where the subject line uses authority and credibility to gain trust while also introducing an element of distraction to limit critical thinking.

Deception (P3) + Integrity (P5), appearing 7 times, shows that deception in subject lines is often paired with an attempt to create trust.

Combinations involving three principles, such as Authority (P1) + Deception (P3) + Integrity (P5) and Deception (P3) + Distraction (P4), occur relatively infrequently, with 5 and 4 occurrences, respectively.

Combinations such as Authority (P1) + Deception (P3) + Distraction (P4) and Deception (P3) + Distraction (P4) + Integrity (P5) occur only once, likely because combining multiple principles in a concise subject line is difficult without making the subject overly complex or suspicious.

Table 6 and Figure 5 illustrate the top ten combinations of principles of persuasion used in the entire content of phishing emails, providing insights into how multiple persuasive tactics are deployed in combination to manipulate recipients. Deception (P3) + Distraction (P4) appears 151 times, making it the most frequently used combination. Deception (P3) + Integrity (P5) follows closely with 147 occurrences and Distraction (P4) + Integrity (P5) also appears frequently (145 times). Deception (P3) + Distraction (P4) + Integrity (P5) is the most frequently used three-principles combination, appearing 128 times. Similarly, Authority (P1) + Deception (P3) (105 times), Authority (P1) + Integrity (P5) (102 times) and Authority (P1) + Distraction (P4) (100 times) are also prominent combinations. Authority (P1) + Deception (P3) + Distraction (P4) and Authority (P1) + Deception (P3) + Integrity (P5) each occur 92 times, indicating more complex strategies where attackers use authority combined with deception to either overwhelming or trust-building elements. The dominance of Deception (3) and Distraction (P4) in combinations shows that these two principles are fundamental to phishing emails. Authority (P1) is consistently present in several combinations, often alongside other principles such as Deception, Distraction or Integrity. To sum up, the analysis of the top combinations of principles of persuasion in phishing email content reveals a sophisticated mix of deception, credibility and authority tactics. The most frequent combinations are those that leverage Deception and Distraction, often with Integrity to build credibility. The presence of Authority in various combinations underlines its effectiveness in compelling compliance, while Distraction and Integrity work as supporting elements to mislead or reassure the recipient.

Our analysis of phishing email subject lines and full content over a ten-year period highlights important trends in how attackers use persuasion principles and, crucially, how they combine them. Compared to earlier research that often looked at these principles individually (e.g., Ferreira and Teles, 2019), our findings show that phishers increasingly layer multiple tactics together to make their messages more convincing. For instance, combinations like Deception with Distraction and Integrity are especially common in full email content, suggesting attackers carefully construct narratives that both mislead and build trust.

This move toward more complex, multi-principle strategies aligns with work by Vishwanath et al. (2011), who emphasized that attackers exploit cognitive overload and divided attention to reduce critical thinking. Our study quantifies these combinations over time, showing how attackers adapt their approaches as users become more aware of simple, single-cue phishing tactics. For example, the decline in overt use of Authority in subject lines alongside rising use of Deception and Integrity in full content suggests phishers are responding to increased user vigilance by crafting subtler, more credible attacks.

These findings have direct practical implications. Cybersecurity training and phishing simulations need to move beyond teaching users to spot obvious cues like urgent language or fake authority. Instead, training should incorporate realistic scenarios that reflect the layered nature of real attacks, helping users recognize patterns where multiple persuasive techniques are used together. This is consistent with calls from Frauenstein and Flowerday (2020) to design interventions that account for the ways personality traits and cognitive biases can increase vulnerability to such nuanced manipulation.

For detection systems, our results also suggest that rules and algorithms should be sensitive to combinations of persuasion principles rather than single features. By identifying common patterns such as Authority paired with Distraction in subject lines or Deception with Integrity in full content security solutions can better flag sophisticated phishing attempts that might otherwise bypass traditional filters focused on technical errors.

Overall, this study contributes to the field by shifting the focus from individual persuasion principles to understanding how attackers combine them strategically over time. By mapping these evolving patterns, we provide actionable insights that can help improve both training programs and technical defences against phishing, making them better equipped to handle the complex, adaptive nature of modern attacks.

In terms of limitations, this study focuses on a specific data set of phishing emails from millersmiles.com.uk [Link to millersmiles.com.uk], providing a detailed analysis based on key persuasion principles. While the sample size is suitable for qualitative insights, future work could expand on this by including more diverse data sets to capture additional variations in phishing tactics. Furthermore, future research could explore real-time phishing detection systems that incorporate the identified principles of persuasion, thereby enhancing practical applications of this study’s findings.

This study advances our understanding of phishing by examining how principles of persuasion are deployed as social engineering tactics across both the full email content and subject lines of phishing emails. The findings confirm that principles such as Distraction, Deception, Integrity and Authority are commonly used to manipulate users. Specifically, subject lines tend to rely on principles like Authority and Distraction to quickly capture attention, while full email content utilizes more elaborate narratives involving Deception and Integrity to establish credibility and maintain manipulation. These insights highlight the necessity for a focused, psychologically informed approach to phishing defence strategies that can adapt to evolving phishing methodologies.

Abroshan
,
H.
,
Devos
,
J.
,
Poels
,
G.
and
Laermans
,
E.
(
2021
), “
A phishing mitigation solution using human behaviour and emotions that influence the success of phishing attacks
”, pp.
345
-
350
, doi: .
ACCC
(
2024
), “
Scam statistics
”.
Ahmad
,
R.
,
Terzis
,
S.
, and
Renaud
,
K.
(
2023
), “
Content analysis of persuasion principles in mobile instant message phishing
”,
International Symposium on Human Aspects of Information Security and Assurance
.
Akbar
,
N.
(
2014
),
Analysing Persuasion Principles in Phishing Emails
,
University of Twente
.
Akdemir
,
N.
and
Yenal
,
S.
(
2021
), “
How phishers exploit the coronavirus pandemic: a content analysis of covid-19 themed phishing emails
”,
Sage Open
, Vol.
11
No.
3
, p.
21582440211031879
.
Aleroud
,
A.
and
Zhou
,
L.
(
2017
), “
Phishing environments, techniques, and countermeasures: a survey
”,
Computers and Security
, Vol.
68
, pp.
160
-
196
.
Alsharif
,
M.
,
Mishra
,
S.
and
AlShehri
,
M.
(
2022
), “
Impact of human vulnerabilities on cybersecurity
”,
Computer Systems Science and Engineering
, Vol.
40
No.
3
, pp.
1153
-
1166
,
available at:
Link to Impact of human vulnerabilities on cybersecurityLink to the cited article
APWG
(
2024
), “
Unifying the global response to cybercrime (phishing activity trends report 2nd quarter 2024
”,
Issue
.
Atkins
,
B.
and
Huang
,
W.
(
2013
), “
A study of social engineering in online frauds
”,
Open Journal of Social Sciences
, Vol.
1
No.
3
, pp.
23
-
32
.
Bakhshi
,
T.
,
Papadaki
,
M.
and
Furnell
,
S.
(
2009
), “
Social engineering: assessing vulnerabilities in practice
”,
Information Management and Computer Security
, Vol.
17
No.
1
, pp.
53
-
63
.
Bayl-Smith
,
P.
,
Taib
,
R.
,
Yu
,
K.
and
Wiggins
,
M.
(
2021
), “
Response to a phishing attack: persuasion and protection motivation in an organizational context
”,
Information and Computer Security
, Vol.
30
No.
1
.
Butavicius
,
M.
,
Parsons
,
K.
,
Pattinson
,
M.
and
McCormac
,
A.
(
2016
), “
Breaching the human firewall: social engineering in phishing and spear-phishing emails
”,
arXiv preprint
.
Cialdini
,
R.B.
(
2007
),
Influence: The Psychology of Persuasion
,
Collins New York, NY
, Vol.
55
.
Do
,
N.Q.
,
Selamat
,
A.
,
Krejcar
,
O.
and
Fujita
,
H.
(
2022
), “
Deep learning for phishing detection: taxonomy, current challenges and future directions
”,
IEEE Access
, Vol.
10
, pp.
36429
-
36463
, doi: .
Ferreira
,
A.
, and
Lenzini
,
G.
(
2015
), “
An analysis of social engineering principles in effective phishing
”,
Proceedings - 5th Workshop on Socio-Technical Aspects in Security and Trust, STAST 2015
.
Ferreira
,
A.
and
Teles
,
S.
(
2019
), “
Persuasion: how phishing emails can influence users and bypass security measures [article]
”,
International Journal of Human Computer Studies
, Vol.
125
, pp.
19
-
31
, doi: .
Ferreira
,
A.
,
Coventry
,
L.
, and
Lenzini
,
G.
(
2015
),
Principles of Persuasion in Social Engineering and Their Use in Phishing
.
Springer International Publishing
, pp.
36
-
47
, doi: .
Frauenstein
,
E.D.
and
Flowerday
,
S.
(
2020
), “
Susceptibility to phishing on social network sites: a personality information processing model
”,
Computers and Security
, Vol.
94
, p.
101862
, doi: .
Goodman-Delahunty
,
J.
and
Howes
,
L.M.
(
2016
), “
Social persuasion to develop rapport in high-stakes interviews: qualitative analyses of Asian-Pacific practices
”,
Policing and Society
, Vol.
26
No.
3
, pp.
270
-
290
.
Gragg
,
D.
(
2003
), “
A multi-level defense against social engineering
”,
SANS Reading Room
, Vol.
13
, pp.
1
-
21
.
Harrison
,
B.
,
Svetieva
,
E.
and
Vishwanath
,
A.
(
2016
), “
Individual processing of phishing emails
”,
Online Information Review
, Vol.
40
No.
2
, pp.
265
-
281
, doi: .
Jakobsson
,
M.
, and
Myers
,
S.
(
2007
),
Phishing and Countermeasures: understanding the Increasing Problem of Electronic Identity Theft
,
John Wiley and Sons
.
Jones
,
K.S.
,
Armstrong
,
M.E.
,
Tornblad
,
M.K.
and
Namin
,
A.S.
(
2020
), “
How social engineers use persuasion principles during vishing attacks
”,
Information and Computer Security.
Kalio
,
S.
(
2022
), “
Phishing attack: raising awareness and protection techniques
”, doi: .
Khadka
,
K.
,
Ullah
,
A.B.
,
Ma
,
W.
,
Marroquin
,
E.M.
and
Alem
,
Y.
(
2023
), “
A survey on the principles of persuasion as a social engineering strategy in phishing
”,
2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom).
Kheruddin
,
M.S.
,
Zuber
,
M.A.E.M.
and
Radzai
,
M.M.M.
(
2024
), “
Phishing attacks: unraveling tactics, threats, and defenses in the cybersecurity landscape
”, doi: .
Kim
,
D.
and
Hyun Kim
,
J.
(
2013
), “
Understanding persuasive elements in phishing e-mails
”,
Online Information Review
, Vol.
37
No.
6
, pp.
835
-
850
, doi: .
Lawson
,
P.A.
,
Crowson
,
A.D.
and
Mayhorn
,
C.B.
(
2019
), “
Baiting the hook: exploring the interaction of personality and persuasion tactics in email phishing attacks
”,
Advances in Intelligent Systems and Computing.
Lawson
,
P.
,
Zielinska
,
O.
,
Pearson
,
C.
, and
Mayhorn
,
C.B.
(
2017
), “
Interaction of personality and persuasion tactics in email phishing attacks
”,
Proceedings of the Human Factors and Ergonomics Society Annual Meeting
, Vol.
61
No.
1
, pp.
1331
-
1333
, doi:
Li
,
X.
,
Zhang
,
D.
and
Wu
,
B.
(
2020
), “
Detection method of phishing email based on persuasion principle
”,
Proceedings of 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference, ITNEC 2020.
Limna
,
P.
(
2023
), “
The impact of NVivo in qualitative research: perspectives from graduate students
”,
Journal of Applied Learning and Teaching
, Vol.
6
No.
2
, doi: .
Mouton
,
F.
,
Malan
,
M.M.
,
Leenen
,
L.
and
Venter
,
H.S.
(
2014
), “
Social engineering attack framework
”,
2014 Information Security for South Africa.
Naz
,
A.
,
Madiha Sarwar
,
M.K.
,
Mushtaq
,
M.A.
and
Rashid
,
S.
(
2024
), “
A comprehensive survey on social engineering-based attacks on social networks
”,
International Journal of Advanced and Applied Sciences
, Vol.
11
No.
4
, pp.
139
-
154
, doi: .
Ojugo
,
A.A.
and
Nwankwo
,
O.
(
2021
), “
Tree-Classification algorithm to ease user detection of predatory hijacked journals: empirical analysis of journal metrics rankings
”,
International Journal of Engineering and Manufacturing
, Vol.
11
No.
4
, pp.
1
-
9
, doi: .
Parsons
,
K.
,
Butavicius
,
M.
,
Delfabbro
,
P.
and
Lillie
,
M.
(
2019
), “
Predicting susceptibility to social influence in phishing emails [article]
”,
International Journal of Human-Computer Studies
, Vol.
128
, pp.
17
-
26
, doi: .
Sharma
,
T.
and
Bashir
,
M.
(
2020
), “
An analysis of phishing emails and how the human vulnerabilities are exploited
”,
Advances in Human Factors in Cybersecurity: AHFE 2020 Virtual Conference on Human Factors in Cybersecurity, July 16–20, 2020, USA.
Shi
,
H.
,
Silva
,
M.
,
Capecci
,
D.
,
Giovanini
,
L.
,
Czech
,
L.
,
Fernandes
,
J.
and
Oliveira
,
D.
(
2021
), “
Lumen: a machine learning framework to expose influence cues in text
”, doi: .
Stajano
,
F.
and
Wilson
,
P.
(
2011
), “
Understanding scam victims: seven principles for systems security
”,
Communications of the ACM
, Vol.
54
No.
3
, pp.
70
-
75
.
Taib
,
R.
,
Yu
,
K.
,
Berkovsky
,
S.
,
Wiggins
,
M.
, and
Bayl-Smith
,
P.
(
2019
), “
Social engineering and organisational dependencies in phishing attacks
”,
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
.
Tambe Ebot
,
A.
(
2019
), “
How stage theorizing can improve recommendations against phishing attacks
”,
Information Technology and People
, Vol.
32
No.
4
, pp.
828
-
857
, doi: .
Vishwanath
,
A.
,
Herath
,
T.
,
Chen
,
R.
,
Wang
,
J.
and
Rao
,
H.R.
(
2011
), “
Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model
”,
Decision Support Systems
, Vol.
51
No.
3
, pp.
576
-
586
.
Williams
,
E.J.
and
Polage
,
D.
(
2019
), “
How persuasive is phishing email? The role of authentic design, influence and current events in email judgements
”,
Behaviour and Information Technology
, Vol.
38
No.
2
, pp.
184
-
197
.
Williams
,
E.J.
,
Beardmore
,
A.
and
Joinson
,
A.N.
(
2017
), “
Individual differences in susceptibility to online influence: a theoretical review
”,
Computers in Human Behavior
, Vol.
72
, pp.
412
-
421
, doi: .
Workman
,
M.
(
2008
), “
Wisecrackers: a theory‐grounded investigation of phishing and pretext social engineering threats to information security
”,
Journal of the American Society for Information Science and Technology
, Vol.
59
No.
4
, pp.
662
-
674
.
Zielinska
,
O.A.
,
Welk
,
A.K.
,
Mayhorn
,
C.B.
, and
Murphy-Hill
,
E.
(
2016
), “
A temporal analysis of persuasion principles in phishing emails
”,
Proceedings of the Human Factors and Ergonomics Society
.
Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence may be seen at http://creativecommons.org/licences/by/4.0/

Data & Figures

Figure 1.
A bar chart compares the frequency of persuasion principles in phishing emails across three analyses, with distraction and deception highest in entire email content analysis.The bar chart shows the frequency of occurrence for five persuasion principles: authority, deception, distraction, integrity, and social proof in phishing emails, comparing three analyses which are Ferreira and Teles (2019), subject line analysis, and entire email content analysis. The horizontal axis lists the persuasion principles, and the vertical axis shows frequency counts. Entire email content analysis records the highest values overall, with distraction and deception peaking. Ferreira and Teles (2019) and subject line analysis show lower frequencies, with social proof being minimal in all datasets. This highlights how persuasion tactics vary depending on the email component analysed.

Comparison of persuasion principles in phishing emails

Source: Authors’ own work

Figure 1.
A bar chart compares the frequency of persuasion principles in phishing emails across three analyses, with distraction and deception highest in entire email content analysis.The bar chart shows the frequency of occurrence for five persuasion principles: authority, deception, distraction, integrity, and social proof in phishing emails, comparing three analyses which are Ferreira and Teles (2019), subject line analysis, and entire email content analysis. The horizontal axis lists the persuasion principles, and the vertical axis shows frequency counts. Entire email content analysis records the highest values overall, with distraction and deception peaking. Ferreira and Teles (2019) and subject line analysis show lower frequencies, with social proof being minimal in all datasets. This highlights how persuasion tactics vary depending on the email component analysed.

Comparison of persuasion principles in phishing emails

Source: Authors’ own work

Close modal
Figure 2.
A line graph compares yearly values from 2014 to 2023 for deception, distraction, integrity, and social proof, showing varying trends with social proof consistently at zero.The line graph illustrates yearly values from 2014 to 2023 for four persuasion principles: deception, distraction, integrity, and social proof. The horizontal axis represents years, and the vertical axis shows values ranging from zero to eighteen. Integrity starts highest in 2014, drops until 2016, then fluctuates with peaks in 2018 and declines afterwards. Distraction shows alternating rises and falls, peaking in 2017 and 2021. Deception starts moderately high, declining after 2015 with slight fluctuations. Social proof remains at zero throughout the entire period. The graph enables clear comparison of changes in each persuasion principle over the years.

Trends over the different years in email subject

Source: Authors’ own work

Figure 2.
A line graph compares yearly values from 2014 to 2023 for deception, distraction, integrity, and social proof, showing varying trends with social proof consistently at zero.The line graph illustrates yearly values from 2014 to 2023 for four persuasion principles: deception, distraction, integrity, and social proof. The horizontal axis represents years, and the vertical axis shows values ranging from zero to eighteen. Integrity starts highest in 2014, drops until 2016, then fluctuates with peaks in 2018 and declines afterwards. Distraction shows alternating rises and falls, peaking in 2017 and 2021. Deception starts moderately high, declining after 2015 with slight fluctuations. Social proof remains at zero throughout the entire period. The graph enables clear comparison of changes in each persuasion principle over the years.

Trends over the different years in email subject

Source: Authors’ own work

Close modal
Figure 3.
A line graph compares yearly trends from 2014 to 2023 for authority, deception, distraction, integrity, and social proof, showing fluctuations with social proof consistently near zero.The line graph displays yearly values from 2014 to 2023 for five persuasion principles: authority, deception, distraction, integrity, and social proof. The horizontal axis marks the years, and the vertical axis shows values from zero to eighty. Authority begins low, rises steadily, and peaks in 2021 before slightly declining. Deception remains relatively high with peaks in 2019 and fluctuations in other years. Distraction shows moderate levels with notable peaks in 2019 and 2021, followed by stability. Integrity begins moderately high, drops in 2020, then peaks in 2021 before a decline. Social proof stays close to zero across all years. The graph highlights variations in the use of these principles over time.

Trends of the principles over different years in entire email contents

Source: Authors’ own work

Figure 3.
A line graph compares yearly trends from 2014 to 2023 for authority, deception, distraction, integrity, and social proof, showing fluctuations with social proof consistently near zero.The line graph displays yearly values from 2014 to 2023 for five persuasion principles: authority, deception, distraction, integrity, and social proof. The horizontal axis marks the years, and the vertical axis shows values from zero to eighty. Authority begins low, rises steadily, and peaks in 2021 before slightly declining. Deception remains relatively high with peaks in 2019 and fluctuations in other years. Distraction shows moderate levels with notable peaks in 2019 and 2021, followed by stability. Integrity begins moderately high, drops in 2020, then peaks in 2021 before a decline. Social proof stays close to zero across all years. The graph highlights variations in the use of these principles over time.

Trends of the principles over different years in entire email contents

Source: Authors’ own work

Close modal
Figure 4.
A horizontal bar chart ranks the ten most frequent code combinations, with authority and distraction being the most common, followed closely by authority and integrity.The horizontal bar chart displays the top ten code combinations by frequency, with combinations listed on the vertical axis and frequency on the horizontal axis. Authority with distraction appears most frequently, slightly above fifty occurrences, followed by authority with integrity at slightly above forty-five. Distraction with integrity ranks third with around twenty-four occurrences. Other combinations such as authority with deception, authority with distraction and integrity, and deception with integrity range between approximately eight and fifteen occurrences. Less frequent combinations like authority with deception and distraction, and deception with distraction and integrity, occur fewer than five times. The chart highlights authority and distraction as the dominant pairing.

Top 10 combinations of principles in email subject lines

Source: Authors’ own work

Figure 4.
A horizontal bar chart ranks the ten most frequent code combinations, with authority and distraction being the most common, followed closely by authority and integrity.The horizontal bar chart displays the top ten code combinations by frequency, with combinations listed on the vertical axis and frequency on the horizontal axis. Authority with distraction appears most frequently, slightly above fifty occurrences, followed by authority with integrity at slightly above forty-five. Distraction with integrity ranks third with around twenty-four occurrences. Other combinations such as authority with deception, authority with distraction and integrity, and deception with integrity range between approximately eight and fifteen occurrences. Less frequent combinations like authority with deception and distraction, and deception with distraction and integrity, occur fewer than five times. The chart highlights authority and distraction as the dominant pairing.

Top 10 combinations of principles in email subject lines

Source: Authors’ own work

Close modal
Figure 5.
A horizontal bar chart ranks the top ten whole email content code combinations, with deception and distraction occurring most often, followed closely by deception with integrity and distraction with integrity.The horizontal bar chart shows the top ten code combinations by frequency for whole email content analysis. The vertical axis lists code combinations, while the horizontal axis measures frequency. Deception with distraction is the most frequent, slightly above one hundred fifty occurrences, closely followed by deception with integrity and distraction with integrity, each also near one hundred fifty. Deception with distraction and integrity occurs around one hundred thirty-five times. Authority with deception, authority with integrity, and authority with distraction have frequencies just above one hundred. Less frequent combinations such as authority with deception and distraction, authority with deception and integrity, and authority with distraction and integrity range between approximately eighty-five and ninety-five occurrences. The chart highlights deception-related combinations as the most prevalent.

Combinations of principles of persuasion in entire email content

Source: Authors’ own work

Figure 5.
A horizontal bar chart ranks the top ten whole email content code combinations, with deception and distraction occurring most often, followed closely by deception with integrity and distraction with integrity.The horizontal bar chart shows the top ten code combinations by frequency for whole email content analysis. The vertical axis lists code combinations, while the horizontal axis measures frequency. Deception with distraction is the most frequent, slightly above one hundred fifty occurrences, closely followed by deception with integrity and distraction with integrity, each also near one hundred fifty. Deception with distraction and integrity occurs around one hundred thirty-five times. Authority with deception, authority with integrity, and authority with distraction have frequencies just above one hundred. Less frequent combinations such as authority with deception and distraction, authority with deception and integrity, and authority with distraction and integrity range between approximately eighty-five and ninety-five occurrences. The chart highlights deception-related combinations as the most prevalent.

Combinations of principles of persuasion in entire email content

Source: Authors’ own work

Close modal
Table 1.

Absolute frequencies of references coded by category in email subject lines

CategorySourcesReferences
Authority (P1)104105
Social Proof (P2)00
Deception (P3)2121
General Deception (P3.1)1515
Deceptive Relationship (P3.2)66
Liking and Similarity (P3.3)00
Distraction (P4)109120
Scarcity (P4.1)2929
Scarcity of Time (P4.1.1)22
Scarcity by Other Factors (P4.1.2) excluding scarcity of time)2727
Overloading (P4.2)4545
Overloading by Time (P4.2.1)2222
Overloading by Other Factors (P4.2.2) excluding the time1919
Strong Affect (P4.3)2931
Need and Greed (P4.4)1515
Integrity (P5)9495
Integrity (P5.1)3333
Consistency (P5.2)00
Commitment (P5.3)1111
Commitment by dishonesty (excluding commitment by other factors) (P5.3.1)44
Commitment by other factors (excluding commitment by dishonesty) (P5.3.2)88
Reciprocation (P5.4)5151
Source(s): Authors’ own work
Table 2.

Absolute frequencies of references coded by category in entire email contents

CategorySources/filesReferences
Authority (P1)117197
Social Proof (P2)1516
Herd (P2.1)77
Diffusion of Responsibility (P2.2)11
Moral Duty (P2.3)77
Deception (P3)175520
General Deception (P3.1)115228
Deceptive Relationship (P3.2)101121
Liking and Similarity (P3.3)98171
Distraction (P4)171537
Scarcity (P4.1)68103
Overloading (P4.2)115180
Strong Affect (P4.3)110191
Need and Greed (P4.4)4163
Integrity (P5)170507
Integrity (P5.1)74106
Consistency (P5.2)67102
Commitment (P5.3)6888
Reciprocation (P5.4)129211
Source(s): Authors’ own work
Table 3.

Trends over the different years in email subject

YearAuthority (P1)Deception (P3)Distraction (P4)Integrity (P5)Social Proof (P2)
201411512170
2015865110
20165211100
201711114100
201812210160
20191011260
20201421270
20211221440
20221301150
2023901280
Source(s): Authors’ own work
Table 4.

Frequency of coding based on different year of entire email contents

YearsAuthority (P1)Deception (P3)Distraction (P4)Integrity (P5)Social Proof (P2)
201494735450
201564827370
2016114945421
2017135135364
2018153142361
2019206964430
2020162313370
2021425154480
2022342552291
2023253755340
Source(s): Authors’ own work
Table 5.

Combinations of different principles in email subject line

CombinationCount
(‘Authority (P1)’, ‘Distraction (P4)’)52
(‘Authority (P1)’, ‘Integrity (P5)’)46
(‘Distraction (P4)’, ‘Integrity (P5)’)24
(‘Authority (P1)’, ‘Deception (P3)’)12
(‘Authority (P1)’, ‘Distraction (P4)’, ‘Integrity (P5)’)9
(‘Deception (P3)’, ‘Integrity (P5)’)7
(‘Authority (P1)’, ‘Deception (P3)’, ‘Integrity (P5)’)5
(‘Deception (P3)’, ‘Distraction (P4)’)4
(‘Authority (P1)’, ‘Deception (P3)’, ‘Distraction (P4)’)3
(‘Deception (P3)’, ‘Distraction (P4)’, ‘Integrity (P5)’)1
(‘Authority (P1)’, ‘Deception (P3)’, ‘Distraction (P4)’, ‘Integrity (P5)’)1
Source(s): Authors’ own work
Table 6.

Combinations of principles of persuasion in entire email content

CombinationCount
(‘Deception (P3)’, ‘Distraction (P4)’)151
(‘Deception (P3)’, ‘Integrity (P5)’)147
(‘Distraction (P4)’, ‘Integrity (P5)’)145
(‘Deception (P3)’, ‘Distraction (P4)’, ‘Integrity (P5)’)128
(‘Authority (P1)’, ‘Deception (P3)’)105
(‘Authority (P1)’, ‘Integrity (P5)’)102
(‘Authority (P1)’, ‘Distraction (P4)’)100
(‘Authority (P1)’, ‘Deception (P3)’, ‘Distraction (P4)’)92
(‘Authority (P1)’, ‘Deception (P3)’, ‘Integrity (P5)’)92
(‘Authority (P1)’, ‘Distraction (P4)’, ‘Integrity (P5)’)88
(‘Authority (P1)’, ‘Deception (P3)’, ‘Distraction (P4)’, ‘Integrity (P5)’)81
(‘Integrity (P5)’, ‘Social Proof (P2)’)6
(‘Distraction (P4)’, ‘Social Proof (P2)’)6
(‘Authority (P1)’, ‘Social Proof (P2)’)6
(‘Deception (P3)’, ‘Social Proof (P2)’)5
(‘Authority (P1)’, ‘Deception (P3)’, ‘Social Proof (P2)’)5
(‘Authority (P1)’, ‘Distraction (P4)’, ‘Social Proof (P2)’)5
(‘Authority (P1)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)5
(‘Distraction (P4)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)5
(‘Deception (P3)’, ‘Distraction (P4)’, ‘Social Proof (P2)’)4
(‘Authority (P1)’, ‘Deception (P3)’, ‘Distraction (P4)’, ‘Social Proof (P2)’)4
(‘Deception (P3)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)4
(‘Authority (P1)’, ‘Deception (P3)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)4
(‘Authority (P1)’, ‘Distraction (P4)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)4
(‘Deception (P3)’, ‘Distraction (P4)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)3
(‘Authority (P1)’, ‘Deception (P3)’, ‘Distraction (P4)’, ‘Integrity (P5)’, ‘Social Proof (P2)’)3
Source(s): Authors’ own work

Supplements

References

Abroshan
,
H.
,
Devos
,
J.
,
Poels
,
G.
and
Laermans
,
E.
(
2021
), “
A phishing mitigation solution using human behaviour and emotions that influence the success of phishing attacks
”, pp.
345
-
350
, doi: .
ACCC
(
2024
), “
Scam statistics
”.
Ahmad
,
R.
,
Terzis
,
S.
, and
Renaud
,
K.
(
2023
), “
Content analysis of persuasion principles in mobile instant message phishing
”,
International Symposium on Human Aspects of Information Security and Assurance
.
Akbar
,
N.
(
2014
),
Analysing Persuasion Principles in Phishing Emails
,
University of Twente
.
Akdemir
,
N.
and
Yenal
,
S.
(
2021
), “
How phishers exploit the coronavirus pandemic: a content analysis of covid-19 themed phishing emails
”,
Sage Open
, Vol.
11
No.
3
, p.
21582440211031879
.
Aleroud
,
A.
and
Zhou
,
L.
(
2017
), “
Phishing environments, techniques, and countermeasures: a survey
”,
Computers and Security
, Vol.
68
, pp.
160
-
196
.
Alsharif
,
M.
,
Mishra
,
S.
and
AlShehri
,
M.
(
2022
), “
Impact of human vulnerabilities on cybersecurity
”,
Computer Systems Science and Engineering
, Vol.
40
No.
3
, pp.
1153
-
1166
,
available at:
Link to Impact of human vulnerabilities on cybersecurityLink to the cited article
APWG
(
2024
), “
Unifying the global response to cybercrime (phishing activity trends report 2nd quarter 2024
”,
Issue
.
Atkins
,
B.
and
Huang
,
W.
(
2013
), “
A study of social engineering in online frauds
”,
Open Journal of Social Sciences
, Vol.
1
No.
3
, pp.
23
-
32
.
Bakhshi
,
T.
,
Papadaki
,
M.
and
Furnell
,
S.
(
2009
), “
Social engineering: assessing vulnerabilities in practice
”,
Information Management and Computer Security
, Vol.
17
No.
1
, pp.
53
-
63
.
Bayl-Smith
,
P.
,
Taib
,
R.
,
Yu
,
K.
and
Wiggins
,
M.
(
2021
), “
Response to a phishing attack: persuasion and protection motivation in an organizational context
”,
Information and Computer Security
, Vol.
30
No.
1
.
Butavicius
,
M.
,
Parsons
,
K.
,
Pattinson
,
M.
and
McCormac
,
A.
(
2016
), “
Breaching the human firewall: social engineering in phishing and spear-phishing emails
”,
arXiv preprint
.
Cialdini
,
R.B.
(
2007
),
Influence: The Psychology of Persuasion
,
Collins New York, NY
, Vol.
55
.
Do
,
N.Q.
,
Selamat
,
A.
,
Krejcar
,
O.
and
Fujita
,
H.
(
2022
), “
Deep learning for phishing detection: taxonomy, current challenges and future directions
”,
IEEE Access
, Vol.
10
, pp.
36429
-
36463
, doi: .
Ferreira
,
A.
, and
Lenzini
,
G.
(
2015
), “
An analysis of social engineering principles in effective phishing
”,
Proceedings - 5th Workshop on Socio-Technical Aspects in Security and Trust, STAST 2015
.
Ferreira
,
A.
and
Teles
,
S.
(
2019
), “
Persuasion: how phishing emails can influence users and bypass security measures [article]
”,
International Journal of Human Computer Studies
, Vol.
125
, pp.
19
-
31
, doi: .
Ferreira
,
A.
,
Coventry
,
L.
, and
Lenzini
,
G.
(
2015
),
Principles of Persuasion in Social Engineering and Their Use in Phishing
.
Springer International Publishing
, pp.
36
-
47
, doi: .
Frauenstein
,
E.D.
and
Flowerday
,
S.
(
2020
), “
Susceptibility to phishing on social network sites: a personality information processing model
”,
Computers and Security
, Vol.
94
, p.
101862
, doi: .
Goodman-Delahunty
,
J.
and
Howes
,
L.M.
(
2016
), “
Social persuasion to develop rapport in high-stakes interviews: qualitative analyses of Asian-Pacific practices
”,
Policing and Society
, Vol.
26
No.
3
, pp.
270
-
290
.
Gragg
,
D.
(
2003
), “
A multi-level defense against social engineering
”,
SANS Reading Room
, Vol.
13
, pp.
1
-
21
.
Harrison
,
B.
,
Svetieva
,
E.
and
Vishwanath
,
A.
(
2016
), “
Individual processing of phishing emails
”,
Online Information Review
, Vol.
40
No.
2
, pp.
265
-
281
, doi: .
Jakobsson
,
M.
, and
Myers
,
S.
(
2007
),
Phishing and Countermeasures: understanding the Increasing Problem of Electronic Identity Theft
,
John Wiley and Sons
.
Jones
,
K.S.
,
Armstrong
,
M.E.
,
Tornblad
,
M.K.
and
Namin
,
A.S.
(
2020
), “
How social engineers use persuasion principles during vishing attacks
”,
Information and Computer Security.
Kalio
,
S.
(
2022
), “
Phishing attack: raising awareness and protection techniques
”, doi: .
Khadka
,
K.
,
Ullah
,
A.B.
,
Ma
,
W.
,
Marroquin
,
E.M.
and
Alem
,
Y.
(
2023
), “
A survey on the principles of persuasion as a social engineering strategy in phishing
”,
2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom).
Kheruddin
,
M.S.
,
Zuber
,
M.A.E.M.
and
Radzai
,
M.M.M.
(
2024
), “
Phishing attacks: unraveling tactics, threats, and defenses in the cybersecurity landscape
”, doi: .
Kim
,
D.
and
Hyun Kim
,
J.
(
2013
), “
Understanding persuasive elements in phishing e-mails
”,
Online Information Review
, Vol.
37
No.
6
, pp.
835
-
850
, doi: .
Lawson
,
P.A.
,
Crowson
,
A.D.
and
Mayhorn
,
C.B.
(
2019
), “
Baiting the hook: exploring the interaction of personality and persuasion tactics in email phishing attacks
”,
Advances in Intelligent Systems and Computing.
Lawson
,
P.
,
Zielinska
,
O.
,
Pearson
,
C.
, and
Mayhorn
,
C.B.
(
2017
), “
Interaction of personality and persuasion tactics in email phishing attacks
”,
Proceedings of the Human Factors and Ergonomics Society Annual Meeting
, Vol.
61
No.
1
, pp.
1331
-
1333
, doi:
Li
,
X.
,
Zhang
,
D.
and
Wu
,
B.
(
2020
), “
Detection method of phishing email based on persuasion principle
”,
Proceedings of 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference, ITNEC 2020.
Limna
,
P.
(
2023
), “
The impact of NVivo in qualitative research: perspectives from graduate students
”,
Journal of Applied Learning and Teaching
, Vol.
6
No.
2
, doi: .
Mouton
,
F.
,
Malan
,
M.M.
,
Leenen
,
L.
and
Venter
,
H.S.
(
2014
), “
Social engineering attack framework
”,
2014 Information Security for South Africa.
Naz
,
A.
,
Madiha Sarwar
,
M.K.
,
Mushtaq
,
M.A.
and
Rashid
,
S.
(
2024
), “
A comprehensive survey on social engineering-based attacks on social networks
”,
International Journal of Advanced and Applied Sciences
, Vol.
11
No.
4
, pp.
139
-
154
, doi: .
Ojugo
,
A.A.
and
Nwankwo
,
O.
(
2021
), “
Tree-Classification algorithm to ease user detection of predatory hijacked journals: empirical analysis of journal metrics rankings
”,
International Journal of Engineering and Manufacturing
, Vol.
11
No.
4
, pp.
1
-
9
, doi: .
Parsons
,
K.
,
Butavicius
,
M.
,
Delfabbro
,
P.
and
Lillie
,
M.
(
2019
), “
Predicting susceptibility to social influence in phishing emails [article]
”,
International Journal of Human-Computer Studies
, Vol.
128
, pp.
17
-
26
, doi: .
Sharma
,
T.
and
Bashir
,
M.
(
2020
), “
An analysis of phishing emails and how the human vulnerabilities are exploited
”,
Advances in Human Factors in Cybersecurity: AHFE 2020 Virtual Conference on Human Factors in Cybersecurity, July 16–20, 2020, USA.
Shi
,
H.
,
Silva
,
M.
,
Capecci
,
D.
,
Giovanini
,
L.
,
Czech
,
L.
,
Fernandes
,
J.
and
Oliveira
,
D.
(
2021
), “
Lumen: a machine learning framework to expose influence cues in text
”, doi: .
Stajano
,
F.
and
Wilson
,
P.
(
2011
), “
Understanding scam victims: seven principles for systems security
”,
Communications of the ACM
, Vol.
54
No.
3
, pp.
70
-
75
.
Taib
,
R.
,
Yu
,
K.
,
Berkovsky
,
S.
,
Wiggins
,
M.
, and
Bayl-Smith
,
P.
(
2019
), “
Social engineering and organisational dependencies in phishing attacks
”,
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
.
Tambe Ebot
,
A.
(
2019
), “
How stage theorizing can improve recommendations against phishing attacks
”,
Information Technology and People
, Vol.
32
No.
4
, pp.
828
-
857
, doi: .
Vishwanath
,
A.
,
Herath
,
T.
,
Chen
,
R.
,
Wang
,
J.
and
Rao
,
H.R.
(
2011
), “
Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model
”,
Decision Support Systems
, Vol.
51
No.
3
, pp.
576
-
586
.
Williams
,
E.J.
and
Polage
,
D.
(
2019
), “
How persuasive is phishing email? The role of authentic design, influence and current events in email judgements
”,
Behaviour and Information Technology
, Vol.
38
No.
2
, pp.
184
-
197
.
Williams
,
E.J.
,
Beardmore
,
A.
and
Joinson
,
A.N.
(
2017
), “
Individual differences in susceptibility to online influence: a theoretical review
”,
Computers in Human Behavior
, Vol.
72
, pp.
412
-
421
, doi: .
Workman
,
M.
(
2008
), “
Wisecrackers: a theory‐grounded investigation of phishing and pretext social engineering threats to information security
”,
Journal of the American Society for Information Science and Technology
, Vol.
59
No.
4
, pp.
662
-
674
.
Zielinska
,
O.A.
,
Welk
,
A.K.
,
Mayhorn
,
C.B.
, and
Murphy-Hill
,
E.
(
2016
), “
A temporal analysis of persuasion principles in phishing emails
”,
Proceedings of the Human Factors and Ergonomics Society
.

Languages

or Create an Account

Close Modal
Close Modal