This study aims to investigate the conditions under which people are inclined to engage with social engineering propositions. Using the contributions of Prospect Theory, the role of individual utility evaluations and risk perception were examined.
A laboratory experiment was conducted with a sample of 82 people from Germany. Participants were asked to work on tasks when they were approached by a third-party social engineer who offered to help them complete the task in exchange for their social media password. The experiment was conducted in a laboratory setting to control for extraneous factors.
The results showed that participants were more likely to share their password when the perceived profitability of doing so was high, when they expected that the trust would be rewarded, and when they perceived the stranger to be trustworthy. The findings suggest that this framework could be used to develop more effective strategies to prevent social engineering attacks.
This study uniquely contributes to the literature by applying a Prospect Theory framework to explore the decision-making processes of individuals in the context of social engineering, offering novel insights into the psychosociological mechanisms that influence individuals’ susceptibility to phishing tactics.
1. Introduction
Despite being discouraged due to security risks, password sharing remains common, often within trusted relationships such as families and friends, but occasionally extending to strangers (Singh et al., 2007; Ouytsel, 2021; Ferreira et al., 2013). Malevolent actors may attempt to gain the trust of a person to subsequently obtain unauthorized access to private accounts. This form of deception is known as social engineering, which involves the psychological manipulation of individuals into performing actions or divulging confidential information. Social engineering is regarded as one of the leading threats to information security in the contemporary era (Washo, 2021; Airehrour et al., 2018). Its prevalence has been particularly evident in the context of social media (Chetioui et al., 2022).
The present study addresses a critical gap in the literature on information security by focusing on password-sharing behaviours with strangers, a context that has received limited attention in prior research. Singh et al. (2007) examine password-sharing practices in various social and cultural contexts, such as within families, among couples and in remote Indigenous communities in Australia, where such behaviours are often driven by trust and practical necessity. However, their study does not explore scenarios involving interactions with strangers, leaving a significant gap in understanding how and why individuals might share sensitive credentials in less familiar contexts. Similarly, Ouytsel (2021) highlights that even password sharing between close friends remains poorly understood, indicating a broader research gap in understanding unsafe password-sharing behaviours across varying relationship contexts. Uddin et al. (2023) emphasize that password-sharing behaviours significantly increase the risk of cybercrime victimization, particularly in interactions with strangers, yet little is known about the behavioural mechanisms driving such decisions (Uddin et al., 2023).
Building on these findings, the present study bridges the gap in understanding how individuals make decisions about password sharing with strangers in social engineering scenarios. This investigation draws on Prospect Theory (PT) (Kahneman and Tversky, 1979), which provides a framework for understanding decision-making under uncertainty. To examine these processes, a realistic social engineering scenario is simulated in a controlled laboratory environment: Participants are approached by a stranger who offers a monetary incentive in exchange for their social media credentials. This setup mirrors critical aspects of real-world social engineering tactics while ensuring experimental control, enabling a systematic investigation of how individuals balance perceived risks and rewards in these situations.
Unlike previous surveys and role-playing investigations concerning social engineering (Jakobsson et al., 2007; Salahdine and Kaabouch, 2019; Chatchalermpun and Daengsi, 2021; Algarni et al., 2017), this laboratory study enhances ecological validity; By simulating realistic interactions, it captures key behavioural patterns in a way that prior research could not, enabling a deeper understanding of the sociopsychological mechanisms behind password-sharing decisions.
This study contributes to the literature by extending PT to the domain of information security, specifically within the context of social engineering. The research explores how individuals weigh potential rewards against risks when making decisions about password sharing, thus offering novel insights into the application of decision-making theories in security contexts. By focusing on the intersection of psychology, behavioural economics and cybersecurity, this study provides a theoretical foundation for future research aimed at understanding and mitigating the risks associated with social engineering.
While prior studies have explored phishing simulations in corporate email contexts that focus on link-clicking (Egelman et al., 2008; Moody et al., 2017), the broader spectrum of social engineering tactics on social media and private messages remains largely unexplored. This gap is crucial given the growing reliance on these platforms for everyday communication and their increasing exploitation as vectors for cyberattacks. Social engineering attacks, including phishing, often go beyond simple link-clicking. Many involve users being manipulated into logging into fake websites or directly sharing sensitive information, granting attackers extensive access to critical data and increasing the risk of identity theft. Although these tactics frequently rely on indirect methods or building trust over time, attackers sometimes exploit the element of surprise by making immediate requests for confidential information.
The present study captures and analyses these real-world scenarios in which individuals might choose to share their passwords, despite inherent risks. By applying PT, the study explores how participants’ evaluations of risks and rewards shape their behaviour in these interactions.
2. Related work
2.1 Authentication and passwords
Usernames and passwords remain the dominant form of authentication, making safe handling essential. Although many alternatives such as biometrics exist (Lyastani et al., 2020; Oesch and Ruoti, 2020; Bonneau et al., 2012; Bachmann, 2014; Mitchell and Shing, 2018; Ozan, 2017), they still depend on passwords for setup, recovery (Cherapau et al., 2015; Bud, 2018; Ryu et al., 2021) or multi-factor authentication (Ibrokhimov et al., 2019).
Common vulnerabilities include weak (Ur et al., 2015; Pearman et al., 2017), reused (Pearman et al., 2017; Wang and Reiter, 2018; Abbott et al., 2018) and even shared passwords, compromising account security. While biometric authentication and multi-factor authentication offer no sharing option or constant reminder for each login attempt, the traditional password – once shared – can be used and abused without the account owner’s control (until it is changed). Hence, the associated risk is not to be understated – yet passwords are frequently shared.
2.2 Disclosure of passwords
Passwords are frequently shared within families and close friends to simplify access and demonstrate trust (Singh et al., 2007; Ouytsel, 2021; Ferreira et al., 2013). In some cases, friends logged into an account using shared login information without informing or obtaining consent from the account owner, highlighting risks inherent even in trusted relationships (Ouytsel, 2021).
Passwords are also shared with strangers, particularly in successful phishing attacks. Phishing typically occurs as broad attacks or targeted spear-phishing campaigns aimed at specific individuals. Whether people fall for phishing seems to be dependent on a number of factors, that can be behavioural, educational and demographic in nature, as has been discussed in literature and demonstrated in empirical studies (Blythe et al., 2011; Sheng et al., 2010; Darwish et al., 2012; Moody et al., 2017; Dhamija et al., 2006; Tornblad et al., 2021). Highlighting the importance of understanding user characteristics in predicting susceptibility to phishing attacks, Tornblad et al. (2021) identified 32 predictors across various domains such as personality traits, demographics, cybersecurity experience and email behaviours (Tornblad et al., 2021). Atkins and Huang (2013) showed that the two primary triggers in social engineering attacks were signs of verification and the use of persuasion techniques by the attacker. Emotional persuasion and urgency, in particular, led to the people contacted dropping their guard (Atkins and Huang, 2013). Yang et al. (2022) developed a machine learning model to predict susceptibility to phishing. A notable correlation between personality and susceptibility to phishing has been demonstrated, with the personality trait most closely associated with vulnerability to phishing identified as extraversion (Yang et al., 2022).
Despite extensive work, few studies empirically examine users’ decision-making in phishing scenarios, highlighting a persistent research gap. A systematic literature review sheds light on this research deficit by revealing that a mere 13.9% of the 367 papers analysed focus on users and use empirical research methodologies such as interviews, surveys and in-lab studies. Furthermore, even within this limited subset, there is a striking lack of attention to essential methodological details and participant characteristics, indicating a critical need for further investigation into the human aspect of phishing vulnerability. It is therefore unsurprising that there has been little research conducted on specific phishing scenarios that deviate from the conventional phishing link via email.
Social media platforms, by design, foster information sharing and are thus highly vulnerable to phishing (Lei et al., 2023) while misplaced user trust further heightens the risk of exploitation. In the realm of social network security, investigations have revealed that common social engineering tactics such as spamming, identity replication and social bot manipulation, largely rely on counterfeit personas (Fire et al., 2014). The potentiality of this occurrence can be attributed to a number of factors, including the propensity of individuals to engage with phishing offers and subsequently grant access to their online accounts.
A theoretically-driven overview of social engineering attack types on social media platforms is provided by Chetioui et al. (2022) and Bishnoi et al. (2023), who also created an overview of the individual steps involved in social engineering (investigation, hook, play and exit) and reverse social engineering techniques (Bishnoi et al., 2023; Chetioui et al., 2022). Frauenstein and Flowerday (2016) discuss the evolving threat of phishing, particularly through social networks, where users’ habits of engaging with content can lead to increased susceptibility to so cial engineering attacks (Frauenstein and Flowerday, 2016). They argue that users’ constant interaction with information on social media may lead to information overload, causing them to be less vigilant about security. Another study by Qahri-Saremi and Turel (2023) identified situational variables, including sleep quality, social media ostracism, source likability and fear appeal, as potential predictors of users’ susceptibility to phishing messages on social media.
To date, empirical studies about social network platforms and social engineering have been relatively scarce. In a recent study, Ariani and colleagues (2023) examined the utilization of phishing tools on social media, investigating both the prevalence and the methods used (Ariani et al., 2023). In a role-playing experiment on Facebook, Algarni et al. (2017) analysed how different persuasion techniques and aspects of source credibility affect the success of social engineering attempts. Nevertheless, the authors themselves have also identified that while role-playing games offer versatility, they may not perfectly mirror real-life behaviours, thus advocating for validation through empirical investigation in authentic settings.
The present study addresses this gap using an alternative theoretical framework without varying specific persuasion techniques, as these lie outside its theoretical scope.
2.3 Rationale for using prospect theory
Phishing scenarios deliberately induce trust and risk-taking by offering potential monetary gains or avoiding losses (Beckers and Pape, 2016; Jakobsson, 2016; Ferreira et al., 2015). The broader field of behavioural science offers several theoretical frameworks for understanding decision-making in these uncertain contexts.
Several frameworks help explain behaviour under uncertainty, including the Theory of Planned behaviour (Ajzen, 1991), Protection Motivation Theory (Rogers, 1975, 1983), Social Exchange Theory (Blau, 1964), Technology Threat Avoidance Theory (Liang and Xue, 2009), Risk Perception Theory (Slovic, 1987) and Dual Process Theories (Kahneman, 2011). These approaches collectively highlight how perceived threat severity, coping appraisals, cognitive effort, and intuitive versus analytical reasoning shape security-related decisions. They offer valuable insights into why individuals form certain intentions or coping responses when confronted with cyber threats. However, these frameworks typically focus on motivational and cognitive antecedents of security behaviour rather than the evaluation of the risky choice itself. Unlike these intention-oriented models, PT directly models how individuals weigh potential gains and losses under uncertainty, making it particularly well suited for analyzing the specific decision structure exploited in phishing situations.
PT (Kahneman and Tversky, 1979) offers a more direct account of such decisions by describing how individuals evaluate potential gains and losses relative to a reference point, rather than through objective probabilities. It introduces mechanisms such as loss aversion, diminishing sensitivity and distorted probability perception (Tversky and Kahneman, 1992; Kahneman et al., 1982). In contrast to Expected Utility Theory, which serves as a normative baseline, PT captures how people actually respond to uncertain outcomes (Camerer, 1995), particularly in situations where subjective perceptions of risk matter more than objective calculations (Bleichrodt et al., 2001).
In phishing contexts, these mechanisms provide a compelling explanation for why individuals may comply with risky requests: trust cues influence the perceived balance of gains and losses, leading to systematically biased judgments under uncertainty (Nguyen et al., 2016). This makes PT particularly well suited for understanding decision-making in high-risk, high-uncertainty environments where individuals weigh immediate potential benefits (e.g. monetary incentives and social rewards) against potential losses (e.g. credential misuse).
Cumulative prospect theory (CPT) extends the original model by applying probability weighting to cumulative distribution functions and is especially useful for complex, multi-outcome lotteries (Tversky and Kahneman, 1992). In the present study, however, participants faced simple, discrete choices – accepting or rejecting a phishing-like offer – rather than continuous probability distributions. For such binary decisions, the qualitative components of the original PT, particularly loss aversion and reference dependence, are sufficient to capture the relevant psychological processes.
Although PT is often associated with formal parameter estimation, its original formulation is fundamentally a descriptive model of how individuals evaluate uncertain outcomes. In applied behavioural research, it is widely used without fitting full mathematical value or weighting functions, especially when the goal is to explain underlying cognitive mechanisms rather than derive quantitative utility estimates. Following this established practice, the present study draws on PT conceptually, without estimating its formal parameters. Instead of requiring participants to compute or report precise probabilities – which would not reflect naturalistic decision-making – the experiment elicits their subjective evaluations of risks and rewards and interprets disclosure behaviour through the lens of loss aversion, reference dependence and probability distortion. This approach provides a theoretically grounded yet practically applicable account of real-world decision-making in phishing situations.
2.4 Research model and hypotheses development
PT is applied to explain decision-making in response to phishing offers. Figure 1 depicts the research model used in the present study.
The diagram depicts a flowchart detailing the decision-making process regarding whether to share a password in response to an offer from a stranger. It begins with receiving an offer from a stranger, leading to a situational evaluation that involves a cost-benefit analysis considering financial incentives versus potential password loss. It branches into two attitudes: risk aversion, characterised by distrust towards strangers, leading to an expectation that sharing the password is harmful, and risk seeking, marked by trust towards strangers, suggesting that sharing the password is worthwhile. The strategic choice resulting from this evaluation is either to not share the password or to share it, based on the assessed attitudes and expected utility. Boxes and arrows depict relationships and decision paths clearly.The pathways of the decision-making process in a social engineering situation.
Source(s): Authors’ contribution
The diagram depicts a flowchart detailing the decision-making process regarding whether to share a password in response to an offer from a stranger. It begins with receiving an offer from a stranger, leading to a situational evaluation that involves a cost-benefit analysis considering financial incentives versus potential password loss. It branches into two attitudes: risk aversion, characterised by distrust towards strangers, leading to an expectation that sharing the password is harmful, and risk seeking, marked by trust towards strangers, suggesting that sharing the password is worthwhile. The strategic choice resulting from this evaluation is either to not share the password or to share it, based on the assessed attitudes and expected utility. Boxes and arrows depict relationships and decision paths clearly.The pathways of the decision-making process in a social engineering situation.
Source(s): Authors’ contribution
The model assumes that password-sharing decisions depend on perceived benefits, trustworthiness of the stranger and risk evaluation (Simpson, 2007). General attitudes such as risk tolerance and trust influence the decision path, consistent with PT’s assumption that individuals evaluate potential gains and losses relative to a reference point rather than in purely objective terms. As illustrated in the model, these processes ultimately culminate in a decision regarding password sharing.
Risk-taking, trust, incentive and initial contact (including reciprocity) are delineated to model the decision-making process regarding password sharing under risk and uncertainty. This experiment investigates how these factors shape subjective evaluations of potential gains and losses in the context of a phishing-like offer.
2.4.1 Risk taking.
Sociologically, risk-taking refers to assessing potential negative outcomes within social contexts (Beck, 1992; Lidskog and Sundqvist, 2012). Prior studies link higher risk-taking to greater phishing susceptibility (Abroshan et al., 2021; Ayyagari and Crowell, 2020). People differ in their willingness to take risks (Zuckerman, 2007) because risk-taking depends on personality, experience and social environment (Lam and Ozorio, 2013; Gardner and Steinberg, 2005; Kennison and Chan-Tin, 2020). The general willingness to take risks can be measured using the validated short scale by Beierlein et al. (see Appendix Table A1 and Beierlein, Kovaleva, Kemper, and Rammstedt, 2015) which incorporated items querying the self-assessment of risk-taking and the assessment of the social environment pertaining to risk-taking.
According to PT (Kahneman and Tversky, 1979: 269), individuals evaluate outcomes based on perceived gains and losses rather than objective probabilities. Due to loss aversion, potential losses weigh more heavily than equivalent gains, shaping risk behaviour. In the context of phishing, this framework suggests that individuals who do not recognize or undervalue the risks associated with sharing passwords (e.g. the potential misuse of personal information) are more likely to engage with the phishing attempt. The lack of awareness diminishes the perceived severity of potential losses, thereby increasing the likelihood of compliance with the phishing request (H1). Conversely, when risks are explicitly recognized and evaluated as significant, individuals are more likely to avoid risky behaviours, such as sharing sensitive credentials (H2). Risk-averse individuals reject phishing offers emphasizing potential losses, whereas risk-seeking individuals focus on possible rewards (H3):
If there is little or no awareness of a potential abuse of trust, the password is more likely to be passed on to the stranger.
The greater the perceived risk of disclosing passwords, the less likely it is that passwords will be disclosed.
Those who are risk-averse are less likely to accept a phishing offer that presents a potential gain than those who are risk-seeking.
2.4.2 Trust.
Trust – the expectation that others will act benevolently – is a necessary condition for sharing sensitive data. According to Luhmann (2000), system trust reflects assumptions about a system’s stability and reliability and can be applied to the Internet as a social system (Thiedeke, 2004; Baltra, 2011; Falk and Kosfeld, 2006).
On the micro level, trust is shaped by personal preferences, perceptions of the situation and the relationship with the other party (Coleman, 1990) Trust inherently involves a degree of vulnerability, as it requires an advance payment from the trust giver, who risks potential exploitation by the trusted party. Certain conditions facilitate or impede the formation of trust: For example, the perception of the trustworthiness of the counterpart, the way a situation presents itself, and the incentive that exists when trust has paid off (Deutsch, 1960; Conviser, 1973; Coleman, 1990).
Online trust in strangers depends on general Internet confidence, situational perception and expectations of others’ behaviour (Freitag and Traunmüller, 2009; Uslaner, 2002; Bialski and Batorski, 2009; Bauer and Freitag, 2018).
While trust is not explicitly addressed in Tversky and Kahneman’s original work on PT (1979), subsequent research has demonstrated its role in shaping subjective risk perception in decision-making under uncertainty (Nguyen et al., 2016; Uslaner, 2007). Trust acts as a contextual factor that influences how individuals evaluate potential outcomes, particularly by altering the perceived likelihood and severity of risks. Trust reduces perceived losses, whereas distrust amplifies them.
In phishing scenarios, trust significantly influences decision-making processes. If an individual perceives the stranger as trustworthy, they are more likely to downplay the associated risks and focus on the potential benefits of compliance (H4). Similarly, the perception of a situation as safe and trustworthy reduces the subjective evaluation of risk, encouraging engagement (H5). Furthermore, broader assumptions about the likelihood of trust being honoured, such as the belief that the stranger will not exploit the trust given, can override rational assessments of risk, making individuals more susceptible to phishing attempts (H6).
By incorporating trust as a contextual factor, PT offers a nuanced explanation of how trust shapes the balance between perceived risks and rewards, influencing individuals’ willingness to share sensitive information in uncertain scenarios:
If the stranger is perceived as trustworthy, the password is more likely to be passed on.
If the situation is perceived as trustworthy, the password is more likely to be passed on.
If there is a general expectation that the stranger will not exploit the trust, the password is more likely to be passed on.
2.4.3 Money as an incentive.
Financial incentives exploit the “need-and-greed principle” and are common in social engineering, especially phishing (Stajano and Wilson, 2011; Fischer and Evans, 2009) The motivational effect of money varies with personality, situation and perceived value (Jin and Huang, 2014; Lawler, 1981). Although often treated as universal motivators, monetary rewards are socially and individually shaped (Kraemer et al., 2020; Morduch, 2017). The attribution of meaning to money can vary widely, and assuming it as static risks distorting findings (Frey, 1997; Kraemer et al., 2020). Therefore, it is crucial to account for individual differences in the significance ascribed to monetary rewards when assessing their role in decision-making processes.
According to PT, subjective valuation of monetary rewards can distort risk evaluation, leading individuals to prioritize potential gains over losses. In phishing scenarios, the offered monetary reward serves as a key factor shaping the decision to comply with a request. Individuals who assign substantial value to the reward are more likely to engage in risky behaviour, as the perceived benefit outweighs the potential risks (H7). Conversely, for those who perceive the reward as insignificant, the same decision might not justify the associated risks. This dynamic highlights how the subjective importance of incentives interacts with individuals’ broader evaluations of trust and risk in guiding behaviour.
The greater the participants place the importance of money, the more willing they are to engage in the trade.
2.4.4 Initial contact.
Despite limited emotional cues, familiarity and trust can develop online through psychological and social mechanisms (Jones and Moncur, 2018). Empirical studies in e-commerce show that reputation mechanisms and platform trust enable rapid development of initial trust (Liu and Tang, 2018; Li et al., 2012). By contrast, social media platforms lack fiduciary responsibility and make it difficult to assess credibility. The potential trust-giver is initially unacquainted with the trust-requester and may even harbour suspicions of the trust-requester and must first overcome this scepticism so that trust can be established (Bachmann and Zaheer, 2013). In social engineering, several psychological mechanisms are at work to alleviate these doubts and to establish sufficient trust (Aleroud and Zhou, 2017; Fatima et al., 2019; Mouton et al., 2016). For instance, initial reciprocity – even if it is done without risk on the part of the person who subsequently wants to receive trust, can be an icebreaker (Kolm, 2000). Communicative interaction can also help build trust online between strangers (Kim and Kim, 2013). These techniques are referred to in the scientific literature as trust generation.
PT provides a framework for understanding how individuals evaluate potential gains and losses under conditions of uncertainty. Although the theory does not explicitly address mechanisms such as reciprocity, these mechanisms can influence the subjective evaluation of risks and benefits central to the theory. Reciprocity, in particular, creates a psychosociological obligation to reciprocate, which can shift individuals’ focus from potential risks to perceived rewards, even when only the promise of a gift is presented (Chao, 2018).
Such gestures of reciprocity could reduce perceived uncertainty and foster an expectation of mutual exchange (H8). This dynamic alters the individual’s cost-benefit analysis by emphasizing the potential social or relational gains, which may outweigh the consideration of associated risks. In phishing scenarios, this shift can lead individuals to downplay potential risks associated with compliance, increasing their likelihood of sharing sensitive information:
Subjects who had recently interacted with the phisher and received an initial gift were more likely to respond positively to the phisher’s subsequent request for their password.
3. Methodology
A combined experiment and post-survey were used to capture decision behaviour under uncertainty, avoiding biases typical of self-assessments, as individuals may provide socially desirable responses or evaluate themselves differently from their actual behaviour in the given situation (Ben-Ner and Halldorsson, 2010; Glaeser et al., 2000).
The experimental design is loosely based on a game theory design, as the expected benefit of PT can be effectively visualized within this framework. Traditionally, these experimental games involve two individuals engaging in competitive decision-making. However, in this simplified game, the decision of the counterpart is not determined by an actual person but is simulated by the experimental administration and all participants acted as trust-givers; the counterpart’s responses were simulated. This setup enables measurement of trust and perceived risk (Evans and Krueger, 2011).
After the experiment, participants completed a short questionnaire tailored to their decision path. This mixed-methods approach of lab study involving the experimental game and subsequent survey aims to provide comprehensive and diverse perspectives regarding the generation of trust in strangers on the Internet.
3.1 Experimental design
The experiment was conducted in a controlled laboratory setting to examine password-sharing behaviour under realistic conditions. To prevent bias, participants were unaware of the phishing element and were initially asked to complete unrelated timed research tasks. The true purpose of the study – assessing whether and under which conditions individuals would grant a stranger access to their Facebook accounts – was revealed only during debriefing, and participants who disclosed their passwords received appropriate support in line with ethical standards.
To ensure ethical integrity while maintaining ecological validity, the study was conducted in accordance with the institutional behavioural research guidelines of a German university. At the time of data collection, deception-based minimal-risk studies in the social and behavioural sciences were not subject to mandatory review by a central ethics board under the institutional policies in place. Although participants entered their real Facebook passwords during the task, passwords were changed together with each participant immediately after debriefing, and no authentication data were stored or accessible to the researchers at any point. All participation was voluntary and based on informed consent, and all data were anonymized upon collection and processed in compliance with GDPR requirements.
After completing the experimental task, participants answered a follow-up survey that captured both quantitative and qualitative predictors of disclosure as well as the perceived influence of the trust-building elements. To ensure consistent experimental conditions, all participants received the same instructions and time limits, and every interaction with the purported stranger followed an identical scripted sequence. The study used a between-subjects design with two conditions that differed solely in the interaction preceding the password request. In the gift condition, participants received unsolicited help from the stranger before the offer was made; in the no-gift condition, the stranger contacted them only once with the same request. This manipulation targeted the initial-contact component of the social engineering scenario, while task structure, timing, incentives and instructions were held constant across conditions. The procedural sequence of both conditions is shown in Figure 2, and the resulting survey branches are outlined in Figure A1.
The flowchart depicts a sequence of steps in a research experiment. It begins with a declaration of consent, followed by preliminary inquiries. The next step instructs participants to log into Facebook and join a group to view questions. Two conditions branch from the initial steps. Condition 1 details interactions where a foreign person named Ben Schroter asks participants if they wish to gain an advantage for more money at a specified time. Condition 2 notes that Ben Schroter makes contact via Facebook at a certain minute after the experiment starts. Both conditions lead to a follow-up questionnaire, concluding with debriefing, payout, and assistance with secure password reset if needed. Rectangular boxes and directional arrows depict the flow of the process, with distinct groupings for each condition.Procedure of the experiment
Source(s): Authors’ contribution
The flowchart depicts a sequence of steps in a research experiment. It begins with a declaration of consent, followed by preliminary inquiries. The next step instructs participants to log into Facebook and join a group to view questions. Two conditions branch from the initial steps. Condition 1 details interactions where a foreign person named Ben Schroter asks participants if they wish to gain an advantage for more money at a specified time. Condition 2 notes that Ben Schroter makes contact via Facebook at a certain minute after the experiment starts. Both conditions lead to a follow-up questionnaire, concluding with debriefing, payout, and assistance with secure password reset if needed. Rectangular boxes and directional arrows depict the flow of the process, with distinct groupings for each condition.Procedure of the experiment
Source(s): Authors’ contribution
3.2 Procedure of the experiment
The experiment was conducted at a German university with student and visitor volunteers. All participants provided informed consent, were briefed on purpose and risks, and could withdraw at any time. Eligibility required age ≥18, sufficient language skills and a Facebook account.
Participants joined a private Facebook group to complete timed research tasks for monetary rewards. In the referred group, participants were presented with posts containing formulated questions, necessitating research on the designated topics, with the subsequent task of recording their findings on a digital notepad. They had eight minutes to answer as many questions as possible for payment per correct answer.
Participants were assigned to the two experimental conditions (see Figure 2 and Figure A1). Random assignment via RNG ensured equal group allocation; participants were blind to their condition. Group 1 received no prior contact and was approached later by an anonymous user offering extra payment. Group 2 first received unsolicited help (see Figure A2) from the same user, followed by the same reward offer.
Those who accepted were asked to share their Facebook password so the user could allegedly double their payout. Afterward, participants completed a questionnaire adjusted to their experimental branch.
3.3 Statistical procedures
To test the hypotheses (H1–H8), various statistical methods were used, chosen based on the nature of the data and the specific hypotheses. For hypotheses involving ordinal data measured on Likert scales (H2, H3, H4, H5, H6 and H7), Kendall’s Tau correlation coefficient was used. Kendall’s Tau as chosen because it has a smaller gross error sensitivity and a smaller asymptotic variance, making it more robust for ordinal data (Croux and Dehon, 2010; Khamis, 2008; Howell, 2010). Given the strongly imbalanced outcome distribution and the high intercorrelations among the trust-related predictors, multivariate logistic regression was not suitable due to issues of separation and unstable coefficient estimates. The hypotheses were therefore tested using bivariate methods that are robust to the distributional properties of the data.
The formula for Kendall’s Tau is given by:
where represents the number of concordant pairs and the number of discordant pairs. Confidence intervals for Kendall’s Tau were estimated using the normal approximation method based on its asymptotic distribution. While this approach is more accurate with large samples, it is also commonly applied in smaller samples as an approximation when exact or resampling-based methods (e.g. bootstrapping) are not used.
For hypotheses H1 and H8, which involve binary variables, Fisher’s Exact Test was used. This test is appropriate when sample sizes are small and expected frequencies in the contingency table are low, as it does not rely on the assumptions of the Chi-Square test. This method allows for accurate inference about the association between the variables of interest, even when conventional tests may fail due to small sample sizes. The test is based on the hypergeometric distribution and is expressed as:
where a, b, c and d represent the frequencies in the contingency table, and n is the total number of observations. In addition to the exact p-value, Fisher’s Exact test also provides a confidence interval for the odds ratio, calculated using exact methods based on the noncentral hypergeometric distribution. This interval quantifies the uncertainty around the strength and direction of the observed association, making it especially valuable in small-sample contexts.
In addition to reporting uncorrected p-values for the eight planned hypothesis tests (H1–H8), p-values were adjusted for multiple comparisons using the Benjamini–Hochberg false discovery rate (FDR) procedure. For completeness, Bonferroni-corrected p-values were also computed.
A post-hoc power analysis was conducted for the trust-related hypotheses (H4–H7) to evaluate the sensitivity of the correlational tests. The reported Kendall’s τ coefficients (τ = 0.40, 0.31, 0.37 and 0.24) were converted into their approximate Pearson r values and analysed using standard correlation power calculations with α = 0.05 and n = 82. The resulting power estimates exceeded 0.99 for τ = 0.40, τ = 0.31 and τ = 0.37 and reached 0.93 for τ = 0.24. These values indicate that the study design provided sufficient statistical power to detect the medium to large associations observed in the trust-related variables.
4. Data analysis and results
4.1 Descriptive analysis
The sample consisted of 82 participants (31 females, 51 males) with a median age of 21 years (SD: 6.68). They were randomly assigned to one of the experimental conditions. To examine whether randomization resulted in comparable groups, baseline equivalence between conditions was assessed. Age, gender and selected dispositional variables (general risk-taking, internet use and social media use) were compared across conditions using t-tests, χ2-tests, Fisher’s exact tests and Wilcoxon rank-sum tests, as appropriate. Regarding internet usage, 97.5% of the sample (n = 80) reported regular internet use. In addition, 80.5% (n = 66) indicated they regularly used social networks. A total of 46 individuals reported a general sense of safety online, in contrast to the 36 who did not. Among the respondents, 17 individuals indicated that they had already been the victims of internet-facilitated crimes, while 20 respondents expressed concern about becoming victims in the future. A significant relationship was observed between past victimization and the probability of future victimization, as indicated by Fisher’s Exact test (p < 0.001, 95% CI [2.92, 51.19], Cohen’s w = 0.482).
To gain further insights into participants’ general risk-taking behaviour, a detailed analysis was conducted. The distribution of risk-taking behaviour revealed two distinct patterns within the sample. A total of 31 participants (37.8%) were classified as “Rather not willing to take risks”, indicating a reluctance to engage in risky activities. In contrast, 22 participants (26.8%) were categorized as “Rather willing to take risks”, showing a higher propensity for risk-taking behaviour. Together, these two groups make up more than half of the entire sample. The remaining participants exhibited moderate or intermediate levels of risk-taking tendencies, falling between these two extremes (see Figure 3).
The image depicts a bar graph illustrating responses regarding willingness to take risks. The X-axis lists four categories, Not at all willing to take risks, Rather not willing to take risks, Rather willing to take risks, and Very willing to take risks. The Y-axis represents the number of responses, ranging from 0 to 30. The bars depict varying response levels for each category, with the highest bar corresponding to Rather not willing to take risks, followed by Rather willing to take risks and Very willing to take risks. The bar for Not at all willing to take risks is significantly shorter, indicating a lower response count.Risk taking propensity of the sample measured with the short scale for willingness to take risks (Beierlein, Kovaleva, Kemper, and Rammstedt, 2015)
Source(s): Authors’ contribution
The image depicts a bar graph illustrating responses regarding willingness to take risks. The X-axis lists four categories, Not at all willing to take risks, Rather not willing to take risks, Rather willing to take risks, and Very willing to take risks. The Y-axis represents the number of responses, ranging from 0 to 30. The bars depict varying response levels for each category, with the highest bar corresponding to Rather not willing to take risks, followed by Rather willing to take risks and Very willing to take risks. The bar for Not at all willing to take risks is significantly shorter, indicating a lower response count.Risk taking propensity of the sample measured with the short scale for willingness to take risks (Beierlein, Kovaleva, Kemper, and Rammstedt, 2015)
Source(s): Authors’ contribution
In light of these findings, it is also crucial to understand how participants perceived and responded to specific risks within the context those risks were presented (Figure 4). An overwhelming majority of the sample (74%) perceived sharing their password as a risk. Furthermore, a high degree of variability emerges when evaluating the situation’s trustworthiness. After all, 26% rated it as neutral, and another 51% experienced the stimulus an (rather) untrustworthy occurrence. The tagged free-text responses show that most participants rated the situation as untrustworthy because the stranger contacted them via Facebook and they had no prior face-to-face contact that could have reduced the perceived stranger status. Moreover, an unencrypted Facebook chat was deemed an unreliable medium for password sharing. Facebook, as a platform, was generally perceived as untrustworthy, with commitments made on it often being disregarded due to the nature of the platform. Other study participants indicated that they found the situation trustworthy because they were in a secure study environment and did not expect anything to happen to them or their account. Finally, data is heterogeneous as to whether sharing passwords is perceived as worthwhile for participants, whereas a clear skewness in the distributions shows that sharing passwords was not perceived as a practice paying off. The majority of the sample (63%) does not perceive password sharing in this specific situation to be beneficial.
The image depicts a horizontal bar graph illustrating three statements related to password sharing, Sharing my password is a huge risk, I consider the situation trustworthy, and I benefit from sharing my password. Each statement includes percentage values indicating participant responses, with categories ranging from Strongly Disagree to Strongly Agree. The bars are stacked to represent the distribution of responses across levels of agreement. The Y-axis lists the statements, while the X-axis indicates percentage values from 0 to 100 percent. The graph shows variation in responses across the three statements, with higher concentrations in Agree and Strongly Agree for the last two statements.Assessment of the situation
Source(s): Authors’ contribution
The image depicts a horizontal bar graph illustrating three statements related to password sharing, Sharing my password is a huge risk, I consider the situation trustworthy, and I benefit from sharing my password. Each statement includes percentage values indicating participant responses, with categories ranging from Strongly Disagree to Strongly Agree. The bars are stacked to represent the distribution of responses across levels of agreement. The Y-axis lists the statements, while the X-axis indicates percentage values from 0 to 100 percent. The graph shows variation in responses across the three statements, with higher concentrations in Agree and Strongly Agree for the last two statements.Assessment of the situation
Source(s): Authors’ contribution
To further understand the nuances of these perceptions, it is essential to consider the assessment of the stranger involved in the scenario (Figure 5). Most study participants (59%) rated the person who messaged them on Facebook as untrustworthy, while another 18% said they found the person trustworthy. When looking at the tagged free text responses, it is stated that unknown persons are generally not trusted and certainly not on the anonymous Internet. Those who answered “neutral” specified in the free text question that they had ignored the person either intentionally or unintentionally and did not attach any further importance to him. Those who found him trustworthy indicated that he had seemed likeable in his manner of conversation and honoured that he had given them answers they needed for the study.
The horizontal stacked bar chart depicts responses to three statements about trust in a stranger. The X-axis is labelled Percentage and ranges from 0 to 100. The Y-axis lists three statements: I consider the stranger trustworthy, I expect that the stranger will not take advantage of me, and My trust in the stranger will pay off. For the first statement, 59 percent fall under Strongly Disagree and Disagree combined, 23 percent are Neutral, and 18 percent fall under Agree and Strongly Agree combined. For the second statement, 55 percent fall under Strongly Disagree and Disagree combined, 27 percent are Neutral, and 18 percent fall under Agree and Strongly Agree combined. For the third statement, 52 percent fall under Strongly Disagree and Disagree combined, 33 percent are Neutral, and 15 percent fall under Agree and Strongly Agree combined. A legend identifies the response categories Strongly Disagree, Disagree, Neutral, Agree, and Strongly Agree.Assessment of the stranger
Source(s): Authors’ contribution
The horizontal stacked bar chart depicts responses to three statements about trust in a stranger. The X-axis is labelled Percentage and ranges from 0 to 100. The Y-axis lists three statements: I consider the stranger trustworthy, I expect that the stranger will not take advantage of me, and My trust in the stranger will pay off. For the first statement, 59 percent fall under Strongly Disagree and Disagree combined, 23 percent are Neutral, and 18 percent fall under Agree and Strongly Agree combined. For the second statement, 55 percent fall under Strongly Disagree and Disagree combined, 27 percent are Neutral, and 18 percent fall under Agree and Strongly Agree combined. For the third statement, 52 percent fall under Strongly Disagree and Disagree combined, 33 percent are Neutral, and 15 percent fall under Agree and Strongly Agree combined. A legend identifies the response categories Strongly Disagree, Disagree, Neutral, Agree, and Strongly Agree.Assessment of the stranger
Source(s): Authors’ contribution
The majority (55%) rejects the proposition that the stranger does not gain an advantage from them. Another 27% rate the statement as neutral, and only 18% agree (strongly). Another item asked whether trust in the stranger would pay off, or would have paid off if the offer had been accepted. Just under one-third took a neutral stance, while the majority, with 53% of votes, disagreed that trust in the stranger would pay of and 15% expected a positive outcome. The items “I consider the stranger trustworthy” and “I expect that the stranger will not take advantage of me” are correlated according to relatively conservative Kendall’s tau (p < 0.001, tau 0.562), and also “My trust in the stranger will pay off” and “I expect that the stranger will not take advantage of me” (p < 0.001, tau = 0.487) as well as “My trust in the stranger will pay off” and “I consider the stranger trustworthy” (p < 0.001, tau = 0.494).
Throughout the study, a total of 15 participants disclosed their passwords, while the remaining 67 subjects did not. Among those who made their passwords available, 11 were in the first experimental condition. Four of them were in the second experimental condition and received a gift in the form of knowledge from the person subsequently requesting trust. With regard to the demographic factors, a significant correlation of the covariate age at p = 0.001 (t (80) = −3.34, 95% CI [−9.59, −2.43]) on the disclosure of the password was found with a small to medium effect of 0.31. For the covariate gender, no significant correlation could be found for the given alpha level of 0.05 (χ2 (1, n) = 1.16, p = 0.281).
4.2 Statistical testing
To examine the psychological and contextual determinants of participants’ willingness to disclose their passwords to a stranger (see Appendix Figure A1), eight hypotheses (H1–H8) were tested. These covered cognitive risk awareness, individual differences in risk preferences, trust perceptions and situational or motivational factors. The results of the statistical analysis for each hypothesis (H1–H8) are summarized in Table 1.
Hypotheses results with estimates, p-values, confidence intervals and effect magnitudes
| Variable | Test | Estimate | p | CI lower | CI upper | Effect |
|---|---|---|---|---|---|---|
| H1: Awareness of potential abuse of trust and password disclosure | Fisher’s exact test | 3.28 | 0.225 | 0.5 | 21.64 | Large (OR) |
| H2: Perceived risk of disclosing passwords | Kendall’s tau | 0.06 | 0.549 | −0.09 | 0.22 | Negligible (τ) |
| H3: Risk Aversion and Phishing Offer Acceptance | Kendall’s tau | 0.19 | 0.055 | 0.05 | 0.33 | Small (τ) |
| H4: Perceived trustworthiness of the stranger | Kendall’s tau | 0.4 | 0.0001 | 0.27 | 0.52 | Moderate–large (τ) |
| H5: Perceived trustworthiness of the situation | Kendall’s tau | 0.31 | 0.0022 | 0.17 | 0.43 | Moderate (τ) |
| H6: Expectation that trust will not be exploited | Kendall’s tau | 0.37 | 0.0002 | 0.24 | 0.49 | Moderate (τ) |
| H7: Importance of money | Kendall’s tau | 0.24 | 0.017 | 0.1 | 0.38 | Small (τ) |
| H8: Prior interaction with the phisher | Fisher’s exact test | 0.29 | 0.084 | 0.09 | 1.02 | Large (protective OR) |
| Variable | Test | Estimate | p | Effect | ||
|---|---|---|---|---|---|---|
| H1: Awareness of potential abuse of trust and password disclosure | Fisher’s exact test | 3.28 | 0.225 | 0.5 | 21.64 | Large ( |
| H2: Perceived risk of disclosing passwords | Kendall’s tau | 0.06 | 0.549 | −0.09 | 0.22 | Negligible (τ) |
| H3: Risk Aversion and Phishing Offer Acceptance | Kendall’s tau | 0.19 | 0.055 | 0.05 | 0.33 | Small (τ) |
| H4: Perceived trustworthiness of the stranger | Kendall’s tau | 0.4 | 0.0001 | 0.27 | 0.52 | Moderate–large (τ) |
| H5: Perceived trustworthiness of the situation | Kendall’s tau | 0.31 | 0.0022 | 0.17 | 0.43 | Moderate (τ) |
| H6: Expectation that trust will not be exploited | Kendall’s tau | 0.37 | 0.0002 | 0.24 | 0.49 | Moderate (τ) |
| H7: Importance of money | Kendall’s tau | 0.24 | 0.017 | 0.1 | 0.38 | Small (τ) |
| H8: Prior interaction with the phisher | Fisher’s exact test | 0.29 | 0.084 | 0.09 | 1.02 | Large (protective |
Note(s): Estimates represent Kendall’s τ for H2–H7 and odds ratios for H1 and H8. Effect magnitude thresholds follow conventional guidelines for τ (< 0.10 negligible, 0.10–0.29 small, 0.30–0.49 moderate, ≥ 0.50 large) and for odds ratios (OR ≈ 1.22, 1.86, and 3.00 indicating small, medium and large effects, respectively; Chen, Cohen and Chen, 2010; protective effects interpreted symmetrically for OR < 1)
The post-hoc power analysis indicated high statistical power for the trust-related hypotheses. Based on the observed Kendall’s τ values (τ = 0.40, 0.31, 0.37 and 0.24), the resulting power estimates exceeded 0.99 for the first three effects and reached 0.93 for the smallest of the four. These values suggest that the study was sufficiently sensitive to detect the medium-to-large associations identified in the trust-related analyses. When controlling the false discovery rate across the eight planned hypothesis tests, all previously significant trust-related associations with password disclosure (H4–H7) remained statistically significant at q < 0.05 (Benjamini-Hochberg adjustment). Under the more conservative Bonferroni correction (α_Bonferroni = 0.00625), the three strongest trust-related effects (H4–H6) remained statistically significant, whereas the smaller effect in H7 did not meet the adjusted threshold. The overall pattern of results therefore continues to support the central role of trust-related evaluations in participants’ willingness to disclose their passwords.
4.2.1 Trust-related perceptions.
Trust-related variables emerged as particularly strong predictors of disclosure behaviour.
H4 hypothesized that participants who perceived the stranger as trustworthy would be more likely to share their password. The analysis confirmed this assumption, revealing a strong positive association, τ = 0.40, 95% CI [0.27, 0.52], p < 0.001, representing a moderate–large effect.
Similarly, H5 proposed that perceived trustworthiness of the situation would increase the likelihood of disclosure. This hypothesis was also supported, τ = 0.31, 95% CI [0.17, 0.43], p = 0.002, indicating a moderate effect.
H6 focused on participants’ expectations about whether the stranger would exploit their trust. Participants who assumed that their trust would not be taken advantage of were significantly more likely to disclose their password, τ = 0.37, 95% CI [0.24, 0.49], p < 0.001, again reflecting a moderate effect.
Taken together, these findings highlight the central role of interpersonal and contextual trust in participants’ decision-making.
4.2.2 Risk-related factors.
The role of risk perception and individual risk preference was assessed in H2 and H3.
H2 posited that higher perceived risk would reduce the likelihood of disclosure. However, the data showed no significant association, τ = 0.06, 95% CI [−0.09, 0.22], p = 0.549, indicating that perceived risk alone did not deter participants from engaging in potentially compromising behaviour.
In contrast, H3 focused on dispositional risk aversion, predicting that risk-averse individuals would be less likely to disclose. This hypothesis was not supported, although the data showed a small positive association that narrowly missed conventional significance thresholds, τ = 0.19, 95% CI [0.05, 0.33], p = 0.055. This pattern suggests that trait-level risk sensitivity may play a role in disclosure behaviour, though the effect should be interpreted with caution.
4.2.3 Cognitive awareness and motivational influences.
H1 examined the effect of participants’ awareness of potential trust abuse on disclosure behaviour. While the odds ratio suggested a trend towards increased disclosure when awareness was low, OR = 3.28, 95% CI [0.50, 21.64], p = 0.225, the result did not reach statistical significance, and thus the hypothesis was not supported. Instrumental motivation was addressed in H7, which proposed that participants who placed greater importance on monetary gain would be more likely to share their passwords. The analysis revealed that a higher valuation of money was a significant predictor of password disclosure, τ = 0.24, 95% CI [0.10, 0.38], p = 0.017, representing a small effect. Finally, H8 examined whether prior interaction with the phisher, including receiving a gift beforehand, increased the likelihood of password disclosure. While there was a trend in the expected direction, the association was not statistically significant, p = 0.084 and the odds ratio, OR = 0.29, 95% CI [0.09, 1.02], did not provide sufficient evidence to support the hypothesis. In summary, the findings support hypothesis H4, H5, H6 and H7 (Table 1).
5. Discussion and implications
5.1 Key findings
The findings of this experiment focus on several key areas related to the likelihood of password disclosure within a social media context, guided by the principles of PT. The discussion is structured to highlight the unique contributions of this research, comparing and contrasting with existing studies, and addressing the specific hypotheses in detail. Before discussing the hypotheses, the demographic effects – being the most easily comparable across studies – are evaluated.
5.1.1 Age.
The analysis revealed an age-related pattern: older participants were more willing to disclose their passwords than younger ones. Prior research has produced mixed findings, with some studies reporting greater caution among older adults (Sarno et al., 2020) and others showing reduced discrimination of phishing attempts (Grilli et al., 2021; Oliveira et al., 2017). Younger adults have, in turn, been found to share passwords more frequently (Whitty et al., 2015). Although the age range in this sample is relatively narrow, the present results suggest that susceptibility may vary gradually across age rather than only between extreme groups.
5.1.2 Gender.
No gender differences were observed. This aligns with the largely inconsistent evidence on gender and cybersecurity behaviour (Moody et al., 2017; Leukfeldt, 2014; Abroshan et al., 2021; Broadhurst et al., 2019). Studies reporting gender effects (Verkijika, 2019; Anwar et al., 2017) typically involve highly heterogeneous samples; such patterns are less likely to appear in a relatively homogeneous academic context.
5.1.3 Awareness of potential trust abuse (H1).
Awareness of potential trust abuse did not reduce disclosure. This contrasts with work suggesting that awareness can improve phishing resistance (Sarno et al., 2020; Alnajim and Munro, 2009), but it is consistent with evidence that knowledge often fails to translate into behaviour (Downs et al., 2007). Within the PT framework, this can be explained by the limited personal relevance of the threat in a controlled setting, reducing the salience of potential losses.
5.1.4 Perceived risk of disclosing passwords (H2).
Perceived risk showed no association with disclosure. Previous studies also indicate that perceived severity alone is a poor predictor of protective behaviour (Downs et al., 2007). The laboratory setting may have reduced the subjective relevance of potential negative outcomes, diminishing the expected effect of loss aversion.
5.1.5 Risk aversion (H3).
Dispositional risk aversion showed only a small, nonsignificant association with password disclosure. Earlier studies linked risk attitudes to susceptibility (Sheng et al., 2010; Abroshan et al., 2021), but the present findings indicate that such traits can be overshadowed by situational cues. PT accounts for this by emphasizing that framing effects may outweigh stable risk preferences during decisions under uncertainty.
5.1.6 Perceived trustworthiness of the stranger (H4).
Perceived trustworthiness of the stranger was a strong predictor of password disclosure. Participants who viewed the counterpart as sincere and reliable were substantially more willing to share their credentials, which aligns with prior research demonstrating that perceived credibility is central to social engineering success (Algarni et al., 2017). In terms of PT, trust acts as a framing cue: when the interaction partner appears trustworthy, individuals mentally downweigh the probability of negative outcomes and attend more to the potential benefits of cooperation (Kahneman and Tversky, 1979). This shift in subjective evaluation offers a coherent explanation for the significant impact of interpersonal trust in the present experiment.
5.1.7 Perceived trustworthiness of the situation (H5).
Trust in the situation also significantly influenced disclosure. Participants who rated the overall context as credible were more likely to comply, indicating that situational cues can be as influential as interpersonal trust. Social media phishing benefits from precisely this effect: familiar interfaces and everyday communication patterns create a misleading sense of safety, whereas email phishing often contains detectable irregularities (McAlaney and Hills, 2020; Kleitman et al., 2018). From a PT perspective, a credible setting reduces the perceived likelihood of losses (Tversky and Kahneman, 1992), making individuals less vigilant and more susceptible to manipulation. The present findings support this mechanism.
5.1.8 Expectation regarding trust exploitation (H6).
Expectations regarding whether trust would be exploited had a similarly strong effect. Participants who believed the stranger would not misuse their password were markedly more willing to disclose it. This pattern suggests that decisions were shaped less by objective risk evaluation and more by anticipated interpersonal outcomes. PT offers a clear explanation: individuals assess potential gains and losses relative to their expectations rather than objective probabilities. When a positive outcome is expected, the subjective weight of potential losses decreases, making disclosure appear less risky (Tversky and Kahneman, 1992). This aligns with the strong association observed in the present data.
5.1.9 Importance of money (H7).
Participants who attached greater importance to the monetary incentive were more likely to disclose, reflecting the effectiveness of financial lures in social engineering (Atkins and Huang, 2013). PT explains this through reference-dependent valuation, whereby potential gains draw attention away from uncertain losses.
5.1.10 Prior interaction with the phisher (H8).
Prior interaction and gifting did not increase disclosure. This suggests that reciprocity alone is insufficient to elicit trust in the absence of stronger credibility cues, which is consistent with research on persuasion in phishing contexts (Algarni, 2019) and PT’s certainty effect (Tversky and Kahneman, 1992; Chao, 2018).
5.2 Limitations
Before examining the theoretical and practical implications of this study, it is essential to consider its limitations. Due to the location of recruitment, the sample consisted primarily of students and members of the university and is therefore limited in its representativeness. Moreover, because all participants were recruited at a single German university, the findings reflect one specific cultural and institutional context and may not readily generalize to other countries or cultural settings. In addition, the sample shows limited diversity with respect to academic background and digital literacy. Because recruitment took place exclusively on campus, participants shared similar educational trajectories and digital habits, which precludes meaningful analysis of whether these factors systematically influence disclosure behaviour. Future studies would need to draw on more heterogeneous, non-academic populations to examine whether the dynamics observed here differ in groups with broader demographic profiles. Furthermore, the relatively complex execution of the experiment and the subsequent follow-up survey limit the total number of subjects with whom the experiment can be conducted due to time constraints. Although the sample size was inherently limited by the structure of the experimental procedure, the post-hoc analyses indicate that the study was adequately powered to detect medium to large effects in the trust-related hypotheses. Nonetheless, smaller effects may not have been reliably identified under these conditions, and non-significant findings should therefore be interpreted with caution. It is also plausible that physical proximity to the university environment fostered a social desirability effect, leading individuals to exhibit a heightened sense of being well-informed and cautious in handling their data.
In addition, there are some difficulties inherent to laboratory experiments, especially in modelling complex phenomena and the control of all possibly influencing variables. Besides, it is noteworthy that under time-constrained circumstances, there is a discernible elevation in the overall propensity for cooperation, as evidenced by numerous laboratory experiments, including those featuring competitive conditions (Cone and Rand, 2014; Rand et al., 2012). Because time stress is inherent in many real-world phishing situations, this variable was not experimentally altered, but it could be worthwhile to investigate in further research whether omitting time stress influences the willingness to respond to the phishing offer and, in this case, to make the password accessible. This consideration is particularly relevant because, remarkably, in the evaluation of the free text responses, 19 respondents subsequently stated that they had intentionally or unintentionally ignored or not read the message and eight other respondents felt under too much pressure to react due to time pressure.
5.3 Theoretical implications
The findings of this study contribute to theoretical work on social engineering by clarifying how trust cues influence subjective evaluations of risk and reward within the framework of PT. Rather than relying on general attitudes towards risk, participants responded primarily to interpersonal and situational trust signals. This supports the view that decision-making in phishing contexts is shaped by reference-dependent evaluations and framing effects rather than objective probability assessments. Trust reduced the perceived likelihood of loss, allowing potential gains to take precedence – an effect consistent with PT’s account of how individuals weigh outcomes under uncertainty.
The results also complement cognitive and behavioural cybersecurity models by demonstrating where PT extends beyond intention-focused frameworks such as Protection Motivation Theory or Technology Threat Avoidance Theory. While these models explain how users form threat perceptions and coping appraisals, PT explains the final choice behaviour: how users trade off potential losses and benefits when confronted with a concrete disclosure request. The strong influence of trust-related cues in this study illustrates the importance of incorporating psychological framing mechanisms into existing models of phishing susceptibility.
Finally, the absence of significant effects for several dispositional variables, including risk aversion, suggests that situational framing may override stable traits when individuals make rapid decisions in social engineering encounters. This highlights the need for future theoretical work to integrate PT with contextual and interpersonal factors, and to examine how trust and framing shape decision dynamics across different digital environments.
5.4 Managerial implications
Security awareness initiatives should account for the trust-based nature of social media attacks. In this study, participants disclosed credentials not because they lacked technical knowledge, but because their trust was deliberately manipulated. organizations should therefore complement conventional, technically oriented training with psychosocial awareness programmes that teach users to critically evaluate contextual cues such as tone, familiarity and timing, using realistic simulations of seemingly benign social interactions involving rewards or peer-like communication.
Technical and monitoring measures on social media platforms also need to reflect these dynamics. Passwords were revealed despite two-factor authentication, indicating that interface protections alone are insufficient when social trust is exploited. Platforms can respond by introducing adaptive trust warnings, real-time detection of manipulative behaviour, and brief confirmation prompts when users attempt to share credentials in chats. Building on Aun et al. (2023), integrating deep-learning-based phishing detection into social-media messaging could support timely, context-sensitive intervention.
Finally, platform and interface design strongly shape perceived safety. Many participants felt secure simply because the interaction took place in a controlled environment, illustrating how environmental cues can override technical literacy. UX and UI designers should counter this illusion of safety by incorporating trust indicators and carefully placed friction prompts when credentials are shared in unverified conversations. User-centred design that reduces cognitive load and encourages brief reflection can help curb impulsive disclosure.
Beyond immediate organizational practices, the results also highlight broader implications for cybersecurity policy and digital literacy. Because the decision to disclose a password emerged not from lack of technical knowledge but from trust-driven distortions in evaluating gains and losses, interventions must extend beyond teaching factual indicators of phishing. Integrating these psychological mechanisms into digital literacy curricula – whether in schools, vocational training or community programmes – can help users recognize how interpersonal cues shape subjective risk assessments. At the policy level, emphasizing trust awareness and decision-making under uncertainty in national cybersecurity guidelines could strengthen preventive efforts and reduce the societal impact of social engineering attacks. In this sense, the findings not only inform organizational training but also contribute to a wider cultural shift towards recognizing social manipulation as a central cybersecurity threat. In essence, organizations and developers should move from reactive cybersecurity to anticipatory, behaviourally informed strategies based on how trust and interface dynamics shape user decisions.
6. Conclusion and future directions
This study has made several original contributions to understanding how individuals assess the risks and benefits of disclosing passwords to strangers on social media, using the framework of PT. The innovative methodological approach combines a controlled laboratory experiment featuring actual simulated phishing attempts with subsequent detailed surveys – a significant advancement over previous studies that relied primarily on surveys or role-playing scenarios (Algarni, et al., 2017; Algarni, et al., 2016; Das, et al., 2019; Ouytsel, 2021; Whitty, et al., 2015). This dual-method approach provides more reliable insights into real-world behaviour while maintaining experimental control, offering a new standard for research in this field.
The findings underscore the complexity of decision-making in social engineering scenarios, particularly how trust and expected benefits significantly influence cybersecurity behaviours. The application of PT to social media phishing represents a novel theoretical contribution, demonstrating how trust-related considerations influence the evaluation of gains and losses. In social engineering and phishing contexts, individuals do not merely rely on a generalized inclination to assume or eschew risks; rather, they engage in nuanced decision-making processes guided by their subjective assessments of potential gains and losses in these scenarios.
The study revealed that trust can significantly influence these evaluations, prompting a re-assessment of potential risks and benefits that may lead to a higher likelihood of password disclosure. This re-evaluation process is crucial, as it underscores the importance of situational factors – like the perceived trustworthiness of the phisher and the specific context of the interaction – over broad dispositional traits.
Beyond explaining the underlying psychological mechanisms, the findings also offer several implications for practice, policy and digital literacy. In theoretical terms, the results demonstrate that the mechanisms described by PT; particularly framing effects, reference-dependent evaluations and the down weighting of negative outcomes under trust, provide a robust explanation for why individuals disclose sensitive information in socially engineered situations. Practically, the findings indicate that interventions must address not only technical knowledge but also the interpersonal and situational cues that shape subjective evaluations of gains and losses. This includes designing phishing awareness programmes that simulate social interaction patterns, updating organizational policies to create clearer rules for verifying interpersonal requests, and developing digital literacy training that teaches users how trust cues distort risk perception. More broadly, these insights can support efforts to strengthen cybersecurity culture by shifting users from purely technical vigilance towards socially informed decision-making.
Building on these insights, future work and practice should focus on how trust-induced distortions in risk evaluation can be mitigated at both user and system level. At the user level, training programmes can emphasize the recognition of interpersonal manipulation and encourage verification and slow-down strategies when sensitive information is requested. At the system level, platforms and organizations can experiment with lightweight friction and context-sensitive warnings that prompt users to reconsider disclosing credentials in private conversations. Evaluating such measures in longitudinal and field studies would deepen our understanding of how trust, risk perception, and interface design jointly shape disclosure decisions in everyday digital environments.
References
Further references
Appendix
The image contains a structured format with two main sections titled "Condition 1" and "Condition 2." Each section includes two bullet points. The first bullet point in each condition states, "The password is given to the phisher," while the second states, "The password is not given to the phisher." The text is clearly arranged, featuring bold headers for each condition, which assists in distinguishing between them visually. The information is presented in a clear, straightforward manner.The four possible branches that determine the wording of the final survey
The image contains a structured format with two main sections titled "Condition 1" and "Condition 2." Each section includes two bullet points. The first bullet point in each condition states, "The password is given to the phisher," while the second states, "The password is not given to the phisher." The text is clearly arranged, featuring bold headers for each condition, which assists in distinguishing between them visually. The information is presented in a clear, straightforward manner.The four possible branches that determine the wording of the final survey
Closing questionnaire (not all items were used in this paper)
| Question | Evaluation | Theoretical concept/empirical measurement tool | Branches and wording differences |
|---|---|---|---|
| Q1: How high did you find the incentive to take up the phisher’s offer (the person who wrote to you on Facebook)? | 5-point-Likert scale, 1 = no incentive; 5 = very high incentive | Situational awareness and personal preferences (risk, social) according to Coleman (1990) | none |
| Q2: How high did you perceive the risk of permanently losing your password by sharing it with the phisher? | 5-point-Likert scale, 1= no risk; 5 = very high risk | Situational awareness and personal preferences (risk, social) according to Coleman (1990) | none |
| Q3: I expect that the stranger will not/would not have take/took advantage of me | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Expectations of the other person’s behaviour | Wording depends on the decision for or against password sharing |
| Q4: I believe I can/could have benefited from this exchange | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Situational awareness and personal preferences (risk, social) according to Coleman (1990) | Wording depends on the decision for or against password sharing |
| Q5: The person who made me the offer seemed trustworthy to me | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Conditions under which trust can be established according to Coleman (1990) | none |
| Q6: Why did the person (not) seem trustworthy to you? | Free text box | Conditions under which trust can be established according to Coleman (1990) | Wording according to the answer from Q5 |
| Q7: The situation in which the offer was made to me seemed trustworthy | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Conditions under which trust can be established according to Coleman (1990) | none |
| Q8: Why did the situation (not) seem trustworthy to you? | Free text box | Conditions under which trust can be established according to Coleman (1990) | Wording according to the answer from Q7 |
| Q9: Did the conversation with the person on Facebook have any influence on you (not) sharing your password? | Free text box | Conditions under which trust can be established according to Coleman (1990) | Only for condition 2 (prior contacting of the person taking the trust) |
| Q10: I took/would take a risk by giving away my password | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Awareness of taking a risk | Wording depends on the decision for or against password sharing |
| Q11: I expect to receive/have received the promised additional money | Binary (yes/no) | Social expectations and willingness to trust/distrust according to Falk and Kosfeld (2006) | none |
| Q12: I expect my trust to pay off/have paid off | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Social expectations and willingness to trust/distrust according to Falk and Kosfeld (2006) | Wording depends on the decision for or against password sharing |
| Q13: How do you personally rate yourself: Are you generally a risk-taker, or do you try to avoid risk? | 7-point-Likert | Single-item scale for assessing risk tolerance by Beierlein et al. (2015). | none |
| Q14: How often do you use the Internet? | often/rarely/never | Risk exposure/frequency of use | none |
| Q15: How often do you use social networks (e.g. Twitter, Facebook and Snapchat)? | often/rarely/never | Risk exposure/frequency of use | none |
| Q16: I am familiar with the Internet and the social network I use | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Perceived empowerment - how familiar subjects are with digital environment | none |
| Q17: I am confident that the Internet is safe | Yes/No/I don’t’ know | System trust according to Luhmann, adapted by Thiedeke (2004) for cyberspace | none |
| Q18: I am confident that the social network I use is secure | Yes/No/ I don’t’ know | System trust according to Luhmann, adapted by Thiedeke (2004) for cyberspace | none |
| Q19: Internet security is important to me in general | Binary (yes/no) | Personal security relevance | none |
| Q20: It is important to me to protect myself on the Internet | Binary (yes/no) | Personal security relevance | none |
| Q21: I find that the protective measures to guard yourself on the Internet are easy to apply | Binary (yes/no) | Perceived empowerment cybersecurity | none |
| Q22: I believe that there is no point in taking protective measures on the Internet | Binary (yes/no) | System trust according to Luhmann, adapted by Thiedeke (2004) for cyberspace | none |
| Q23: Why (not)? | Free text box | Specify the reasons | Wording according to the answer from Q22 |
| Q24: I do not feel safe on the Internet | Binary (yes/no) | System trust according to Luhmann, adapted by Thiedeke (2004) for cyberspace | none |
| Q25: I am worried about becoming a victim of a digital crime (e.g. identity theft, hacking, social engineering) | Binary (yes/no) | Fear of becoming a victim | none |
| Q26: I have been a victim of a digital crime in the past | Binary (yes/no) | Fear of becoming a victim | none |
| Q27: I think it is likely that I will be a victim of a digital crime (again) | Binary (yes/no) | Fear of becoming a victim | Wording according to the answer from Q26 |
| Q28: I limit my use of the Internet because of the dangers involved | Binary (yes/no) | Rejection or acceptance of the threat according to the technology acceptance model | Asked only when either Q24, Q25, Q26 or Q27 indicate that there are cybersecurity concerns |
| Q29: Please elaborate why | Free text box | Rejection or acceptance of the threat according to the technology acceptance model | Asked only if answer at Q28 is “Yes” |
| Q30: I limit my use of social media because of the dangers involved | Binary (yes/No) | Rejection or acceptance of the threat according to the technology acceptance model | Asked only when either Q24, Q25, Q26 or Q27 indicate that there are cybersecurity concerns |
| Q31: Please elaborate why | Free text box | Rejection or acceptance of the threat according to the technology acceptance model | Asked only if answer at Q30 is “Yes |
| Q32: I believe that it is difficult to commit a digital crime | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Digital crime assessment | none |
| Q33: I believe that it is difficult to track and punish a digital crime | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Digital crime assessment | none |
| Q34: I think that most people on the Internet do not want to harm me | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Social and personal expectations | none |
| Q35: My friends are willing to take risks on the Internet | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Risk behaviour of the social environment | none |
| Q36: In my social environment, security on the Internet is not a topic | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Security awareness of the social environment | none |
| Q37: How old are you? | Integer numbers between 18 and 129 | Sociodemographics | none |
| Q38: Which gender do you feel you belong to? | Free text box | Sociodemographics | none |
| Question | Evaluation | Theoretical concept/empirical measurement tool | Branches and wording differences |
|---|---|---|---|
| Q1: How high did you find the incentive to take up the phisher’s offer (the person who wrote to you on Facebook)? | 5-point-Likert scale, 1 = no incentive; 5 = very high incentive | Situational awareness and personal preferences (risk, social) according to | none |
| Q2: How high did you perceive the risk of permanently losing your password by sharing it with the phisher? | 5-point-Likert scale, 1= no risk; 5 = very high risk | Situational awareness and personal preferences (risk, social) according to | none |
| Q3: I expect that the stranger will not/would not have take/took advantage of me | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Expectations of the other person’s behaviour | Wording depends on the decision for or against password sharing |
| Q4: I believe I can/could have benefited from this exchange | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Situational awareness and personal preferences (risk, social) according to | Wording depends on the decision for or against password sharing |
| Q5: The person who made me the offer seemed trustworthy to me | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Conditions under which trust can be established according to | none |
| Q6: Why did the person (not) seem trustworthy to you? | Free text box | Conditions under which trust can be established according to | Wording according to the answer from Q5 |
| Q7: The situation in which the offer was made to me seemed trustworthy | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Conditions under which trust can be established according to | none |
| Q8: Why did the situation (not) seem trustworthy to you? | Free text box | Conditions under which trust can be established according to | Wording according to the answer from Q7 |
| Q9: Did the conversation with the person on Facebook have any influence on you (not) sharing your password? | Free text box | Conditions under which trust can be established according to | Only for condition 2 (prior contacting of the person taking the trust) |
| Q10: I took/would take a risk by giving away my password | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Awareness of taking a risk | Wording depends on the decision for or against password sharing |
| Q11: I expect to receive/have received the promised additional money | Binary (yes/no) | Social expectations and willingness to trust/distrust according to | none |
| Q12: I expect my trust to pay off/have paid off | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Social expectations and willingness to trust/distrust according to | Wording depends on the decision for or against password sharing |
| Q13: How do you personally rate yourself: Are you generally a risk-taker, or do you try to avoid risk? | 7-point-Likert | Single-item scale for assessing risk tolerance by | none |
| Q14: How often do you use the Internet? | often/rarely/never | Risk exposure/frequency of use | none |
| Q15: How often do you use social networks (e.g. Twitter, Facebook and Snapchat)? | often/rarely/never | Risk exposure/frequency of use | none |
| Q16: I am familiar with the Internet and the social network I use | 5-point-Likert scale, 1= strongly disagree; 5 = strongly agree | Perceived empowerment - how familiar subjects are with digital environment | none |
| Q17: I am confident that the Internet is safe | Yes/No/I don’t’ know | System trust according to Luhmann, adapted by | none |
| Q18: I am confident that the social network I use is secure | Yes/No/ I don’t’ know | System trust according to Luhmann, adapted by | none |
| Q19: Internet security is important to me in general | Binary (yes/no) | Personal security relevance | none |
| Q20: It is important to me to protect myself on the Internet | Binary (yes/no) | Personal security relevance | none |
| Q21: I find that the protective measures to guard yourself on the Internet are easy to apply | Binary (yes/no) | Perceived empowerment cybersecurity | none |
| Q22: I believe that there is no point in taking protective measures on the Internet | Binary (yes/no) | System trust according to Luhmann, adapted by | none |
| Q23: Why (not)? | Free text box | Specify the reasons | Wording according to the answer from Q22 |
| Q24: I do not feel safe on the Internet | Binary (yes/no) | System trust according to Luhmann, adapted by | none |
| Q25: I am worried about becoming a victim of a digital crime (e.g. identity theft, hacking, social engineering) | Binary (yes/no) | Fear of becoming a victim | none |
| Q26: I have been a victim of a digital crime in the past | Binary (yes/no) | Fear of becoming a victim | none |
| Q27: I think it is likely that I will be a victim of a digital crime (again) | Binary (yes/no) | Fear of becoming a victim | Wording according to the answer from Q26 |
| Q28: I limit my use of the Internet because of the dangers involved | Binary (yes/no) | Rejection or acceptance of the threat according to the technology acceptance model | Asked only when either Q24, Q25, Q26 or Q27 indicate that there are cybersecurity concerns |
| Q29: Please elaborate why | Free text box | Rejection or acceptance of the threat according to the technology acceptance model | Asked only if answer at Q28 is “Yes” |
| Q30: I limit my use of social media because of the dangers involved | Binary (yes/No) | Rejection or acceptance of the threat according to the technology acceptance model | Asked only when either Q24, Q25, Q26 or Q27 indicate that there are cybersecurity concerns |
| Q31: Please elaborate why | Free text box | Rejection or acceptance of the threat according to the technology acceptance model | Asked only if answer at Q30 is “Yes |
| Q32: I believe that it is difficult to commit a digital crime | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Digital crime assessment | none |
| Q33: I believe that it is difficult to track and punish a digital crime | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Digital crime assessment | none |
| Q34: I think that most people on the Internet do not want to harm me | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Social and personal expectations | none |
| Q35: My friends are willing to take risks on the Internet | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Risk behaviour of the social environment | none |
| Q36: In my social environment, security on the Internet is not a topic | 5-point-Likert, 1= strongly disagree; 5 = strongly agree | Security awareness of the social environment | none |
| Q37: How old are you? | Integer numbers between 18 and 129 | Sociodemographics | none |
| Q38: Which gender do you feel you belong to? | Free text box | Sociodemographics | none |
The image contains handwritten notes detailing a strategy for simulating a phishing attempt. It includes sequential time markers, beginning with zero minutes, indicating friendly greetings and identifying as a Facebook group member. Progressively, it outlines steps for engaging with the target, including encouraging them to share passwords under various pretexts and offering to provide extra benefits. Additionally, directives describe maintaining a friendly demeanor, responding to concerns, staying on topic, and avoiding further incentives. The layout features distinct sections for timing alongside instructions, demonstrating how the sender should interact with the target during the simulation.Chat protocol to simulate the phisher (translated into English)
The image contains handwritten notes detailing a strategy for simulating a phishing attempt. It includes sequential time markers, beginning with zero minutes, indicating friendly greetings and identifying as a Facebook group member. Progressively, it outlines steps for engaging with the target, including encouraging them to share passwords under various pretexts and offering to provide extra benefits. Additionally, directives describe maintaining a friendly demeanor, responding to concerns, staying on topic, and avoiding further incentives. The layout features distinct sections for timing alongside instructions, demonstrating how the sender should interact with the target during the simulation.Chat protocol to simulate the phisher (translated into English)

