A Comparative Study of Generic and Spear-phishing Simulations Based on Public Information
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE credits
Student thesis
Abstract [en]
This study explores how employees respond to generic versus spear-phishing emails, with a special focus on spear-phishing emails generated using publicly available open-source infor-mation (OSINT). As threat actors increasingly leverage personal information available online to build convincing spear-phishing emails, understanding employee vulnerabilities is crucial. One generic email and OSINT based spear-phishing email were used in the study to mimic phishing attempts inside an IT focused company. The generic phishing email was sent to 484 employees spread over different locations and roles, and the spear-phishing was sent to 41 employees working within the IT department. Selected individuals were interviewed again to learn more about their awareness and decision-making processes. The results showed that the generic phishing email produced more reports and more interactions overall, including higher open-rate and submission rates. Several interviews viewed the spear-phishing as more realistic and more difficult to spot as phishing, even though it had fewer opens, fewer reports and zero data submissions. The IT departments technological knowledge probably demonstrated by the fact that no users submitted the form to the spear-phishing email with important information (social security number). Interview analysis revealed high levels of awareness yet also highlighted a behavioural gap. Not all employees recognized suspicious elements, reported the email, or avoided inter-action. This aligns with Protection Motivation Theory (PMT), which suggests that awareness alone does not guarantee protective action. In conclusion, organisations should continue to invest in awareness training, simulate both generic phishing and spear-phishing, and critically evaluate the amount of personal and organisational information made publicly available. Even though generic phishing is still ef-fective producing interactions, spear-phishing poses a subtle threat by potentially evading detection.
Place, publisher, year, edition, pages
2025. , p. 36
Keywords [en]
OSINT, Phishing, Spear-phishing, Awareness, Social engineering
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-23723Local ID: EXD600OAI: oai:DiVA.org:hv-23723DiVA, id: diva2:1981469
Subject / course
Computer engineering
Educational program
Master in Cybersecurity
Supervisors
Examiners
2025-07-222025-07-042025-09-30Bibliographically approved