We believe we're less likely than others are to fall for online scams
Listen to this article
We believe we are less likely than others are to fall for phishing scams, thereby underestimating our own exposure to risk, a new cybersecurity study has found. The research also reports that this occurs, in part, because we overlook data, or “base rate information,” that could help us recognize risk when assessing our own behavior yet use it to predict that of others.
Together, the results suggest that those who are not informed of the risk that, for instance, work-from-home situations pose to online security, may be more likely to jeopardize the safety of themselves and those they work for.
COVID-19 has had a devastating impact on the physical and mental health of people around the globe. Now, with so many more working online during the pandemic, the virus threatens to wreak havoc on the world’s “cyber health,” the researchers note.
What the researchers say: “This study shows people ‘self-enhance’ when assessing risk, believing they are less likely than others to engage in actions that pose a threat to their cyber security—a perception that, in fact, may make us more susceptible to online attacks because it creates a false sense of security,” said the lead author of the study, which appears in the journal Comprehensive Results in Social Psychology.
“This effect is partially explained by differences in how we use base rate information, or actual data on how many people are actually victimized by such scams,” she continued. “We avoid it when assessing our own behavior but use it in making judgments about actions others might take. Because we’re less informed in assessing our actions, our vulnerability to phishing may be greater.”
Through March, more than two million U.S. federal employees had been directed to work from home. This overhaul of working conditions has created significantly more vulnerabilities to criminal activity—a development recognized by the Department of Homeland Security. Its Cybersecurity and Infrastructure Security Agency issued an alert in March that foreshadowed the specific cyber vulnerabilities that arise when working from home rather than in the office.
In their study, the researchers sought to capture how people perceive their own vulnerabilities in relation to others’.
To do so, they conducted a series of experiments on computer screens in which subjects were shown emails that were phishing scams and were told these requests, which asked people to click links, update passwords, and download files, were illegitimate. To tempt the study’s subjects they were told complying with the requests would give them a chance to win an iPad in a raffle, allow them to have their access restored to an online account, or other outcomes they wanted or felt they needed.
Half of the subjects were asked how likely they were to take the requested action while the other half was asked how likely another, specifically, “someone like them,” would do so.
On the screen that posed these questions, the researchers also provided the subjects with “base rate information”: The actual percentage of people at other locations who actually did the requested behavior (One, for instance, read: “37.3% of undergraduate students at a large American university clicked on a link to sign an illegal movie downloading pledge because they thought they must in order to register for classes”).
The researchers then deployed an innovative methodology to determine if the subjects used this “base rate information” in reporting the likelihood that they and “someone like them” would comply with the requested phishing action. Using eye-tracking technology, they could determine when the subjects read the provided information when reporting their own likelihood of falling for phishing attempts and when reporting the likelihood of others doing the same.
Overall, they found that the subjects thought they were less likely than others to fall for phishing scams—evidence of“self-enhancement.” But the researchers also discovered that the subjects were less likely to rely on “base rate information” when answering the question about their own behavior yet more likely to use it when answering the question about how others would act.
“In a sense, they don’t think that base rate information is relevant to their own personal likelihood judgments, but they do think it’s useful for determining other people’s risk,” observed the researchers.
“The patterns of social judgment we observed may be the result of individuals’ biased and motivated beliefs that they are uniquely able to regulate their risk and hold it at low or nonexistent levels,” the lead researchers added. “As a result, they may in fact be less likely to take steps to ensure their online safety.”
So, what? This study backs up what a lot of other researchers of “self enhancement” have discovered: we are really bad at judging ourselves. For example, 70% of college professors believe they are “above average,” a statistical impossibility. Nearly 80% of drivers who have been in multiple accidents over the previous three years say that they are better drivers than most. Most alcoholics deny that they drink to excess. Nearly all CEOs of failed corporations think that they were right in the decisions they made. Almost 100% of surgeons say they wash their hands before every operation when in fact nearly 50% of them don’t.
Join the discussion
More from this issue of TR
Study finds stronger links between automation and inequality
In some white-collar jobs—designer, engineer—people become more productive with sophisticated software at their side. In other cases, forms of automation have simply replaced factory workers, receptionists, and many other kinds of employees.
Cost transparency can increase sales 20%
Retailers who reveal something about themselves may notice an increase in sales as customers feel they are buying into a relationship and developing a perceived support network.
You might be interested inBack to Today's Research
In making decisions, are you an ant or a grasshopper?
In one of Aesop's famous fables, we are introduced to the grasshopper and the ant, whose decisions about how to spend their time affect their lives and future. The jovial grasshopper has a blast all summer singing and playing, while the dutiful ant toils away preparing for the winter.
Don't make major decisions on an empty stomach
New research suggests that people might want to avoid making any important decisions about the future on an empty stomach.
Inequality is bad for society, economic prosperity good
In a cross-national comparison, countries with a bigger income gap between rich and poor indeed have more social ills. Inequality is bad for society as it goes along with weaker social bonds between people, which in turn makes health and social problems more likely. At the same time, richer countries have fewer social ills. Economic prosperity goes along with stronger social bonds in society and thereby makes health and social problem less likely.
Join our tribe
Subscribe to Dr. Bob Murray’s Today’s Research, a free weekly roundup of the latest research in a wide range of scientific disciplines. Explore leadership, strategy, culture, business and social trends, and executive health.