Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A Comparative Study of Generic and Spear-phishing Simulations Based on Public Information
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This study explores how employees respond to generic versus spear-phishing emails, with a special focus on spear-phishing emails generated using publicly available open-source infor-mation (OSINT). As threat actors increasingly leverage personal information available online to build convincing spear-phishing emails, understanding employee vulnerabilities is crucial. One generic email and OSINT based spear-phishing email were used in the study to mimic phishing attempts inside an IT focused company. The generic phishing email was sent to 484 employees spread over different locations and roles, and the spear-phishing was sent to 41 employees working within the IT department. Selected individuals were interviewed again to learn more about their awareness and decision-making processes. The results showed that the generic phishing email produced more reports and more interactions overall, including higher open-rate and submission rates. Several interviews viewed the spear-phishing as more realistic and more difficult to spot as phishing, even though it had fewer opens, fewer reports and zero data submissions. The IT departments technological knowledge probably demonstrated by the fact that no users submitted the form to the spear-phishing email with important information (social security number). Interview analysis revealed high levels of awareness yet also highlighted a behavioural gap. Not all employees recognized suspicious elements, reported the email, or avoided inter-action. This aligns with Protection Motivation Theory (PMT), which suggests that awareness alone does not guarantee protective action. In conclusion, organisations should continue to invest in awareness training, simulate both generic phishing and spear-phishing, and critically evaluate the amount of personal and organisational information made publicly available. Even though generic phishing is still ef-fective producing interactions, spear-phishing poses a subtle threat by potentially evading detection.

Place, publisher, year, edition, pages
2025. , p. 36
Keywords [en]
OSINT, Phishing, Spear-phishing, Awareness, Social engineering
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-23723Local ID: EXD600OAI: oai:DiVA.org:hv-23723DiVA, id: diva2:1981469
Subject / course
Computer engineering
Educational program
Master in Cybersecurity
Supervisors
Examiners
Available from: 2025-07-22 Created: 2025-07-04 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 108 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf