Does the source and distinctiveness of misinformation in social media posts affect its believability? Across two studies, we examine this question utilizing vignette experimental survey designs that manipulated the source, accuracy of information, and whether the information was familiar or distinctive (unfamiliar). Four different topics with different political or moral positions were used to assess how effects varied across topics. True posts were found to be more believable than misinformation posts across the four topics in Study one (n = 595). In study two (n = 514), misinformation was rated as more believable, more accurate, and more trustworthy if it was unfamiliar rather than familiar. Source effects were significant but smaller than the distinctiveness effect. Posts from the source of authority were rated as more believable than those from a friend. Distinctive messages receive initial assessments of higher credibility, suggesting a heuristic process. However, the personally relevant topic of COVID, showed higher believability for unfamiliar misinformation, but also a higher percentage intending to verify the information through additional research. Those supporting more conservative views perceived misinformation as more believable. These findings are consistent with the Elaboration Likelihood Model of Persuasion. Implications and directions for future research are discussed.
With unfolding crises such as the COVID-19 pandemic, it is essential that factual information is dispersed at a rapid pace. One of the major setbacks to mitigating the effects of such crises is misinformation. Advancing technologies such as transformer-based architectures that can pick up underlying patterns and correlational information that constitutes information provide tools that can be used to identify what is misinformation/information. To identify and analyze the spread of misinformation, this work performs a quantitative analysis that uses X (previously Twitter) as the data source and a BERT-based model to identify misinformation. The information of the posts, users, and followers was collected based on hashtags and then processed and manually labeled. Furthermore, we tracked the spread of misinformation related to COVID-19 during the year 2021 and determined how communities that spread information and/or misinformation on social networks interact from an analytical perspective. Our findings suggest that users tend to post more misinformation than information, possibly intentionally spreading misinformation. Our model showed good performance in classifying tweets as information/misinformation, resulting in an accuracy of 86%.
Research on phishing, a prevalent cybercrime, has not addressed which dispositional and knowledge antecedents are related to reporting suspicious emails to their organizations and has provided limited attention to emotions as a predictor of being phished. Our prospective design involved two phases where employees and students at a university (N = 538) first completed a survey and then, after 1 month, were sent three phishing emails spaced weeks apart without their knowledge. Trained members were more likely to have knowledge about safe URLs and this accurate knowledge was associated with a lower rate of being phished and a higher rate of reporting phishing emails. Untrained members had a higher rate of clicking on links and a lower rate of reporting suspicious emails than recently trained members, though training efficacy dissipates over time. Members with high generalized anxiety were more likely to click on links and less likely to report phishing emails, suggesting a gap in training curriculum. High avoidant cognitive styles were less likely to report phishing emails, and these styles are more prevalent among those with high anxiety. Policies and training curriculum need to address anxiety to create a stronger defense against phishing and hacking attacks.
This chapter looks at phishing, more specifically why phishing is profitable, the different types of phishing attacks, why people fall victim to phishing, and some techniques that phishers use to increase their likelihood of success. The chapter also covers behaviors of people, such as whether vulnerable behaviors lead to a higher chance of falling victim or whether protective behaviors lead to a lower chance of falling victim. Some technical aspects of a phishing campaign are also described such as how it can be launched, how a phishing attack can be detected, and some mechanisms to block/prevent phishing - this includes email, blocklisting and some newer methods such as using internationalized domain names, bitsquatting, etc.
Phishing victimization is prevalent and results in theft of personal identifiable information (PII) or installing malware to steal PII. Drawing upon social psychological and criminological theories, we conducted a prospective study to assess three groups of predictors to being phished or not: a) prior victimization; b) protective or vulnerable habitual strategies, and c) emotional and cognitive decision-making styles. Students (N = 236) completed a survey assessing these predictors and then about 4 weeks later received a phishing e-mail using the university's phishing testing system. The e-mail requested that they click on a link and enter their student ID to avoid having their account blocked. About half (50.8%) clicked on the link, and 81.6% of those phished entered their PII. Individuals who had low avoidant style and high generalized anxiety were four times more likely to be phished, after controlling for the significant effects of vulnerable habitual strategies and using dating apps. Machine learning analyses also found cognitive styles and generalized anxiety are the better predictors of getting phished compared to vulnerable and protective strategies and prior victimization. These findings suggest that cybersecurity training needs to be expanded to address the emotional and cognitive processing of deceptive appeals in e-mails.
Phishing is a common vector for cybercrime and hacking. This research examines participants' personality styles (e.g. decision-making styles, self-control) and the likelihood of falling victim to phishing attacks. Over 300 participants completed an online survey assessing protective and vulnerable strategies, personality styles, trust in people, prior victimization from catphishing or identity theft, and demographics information. Unbeknownst to the participants, 2 to 4 weeks after completing the survey they received a phishing e-mail asking them to click on a link. Individuals with a stronger systematic decision-making style were more likely to have a greater number of protective strategies, and those with greater protective strategies were less likely to be a victim of catphishing and identity theft. Individuals with low avoidant decision-making styles and prior vulnerable strategies were more likely to be phished. These findings suggest that learning protective strategies and not using vulnerable strategies are insufficient to lower substantially the risk of being phished. Training might be improved through considering the match between decision-making styles and the content of the training.
Phishing is a common vector for cybercrime and hacking. This research examines participants' personality styles (e.g. decision-making styles, self-control) and the likelihood of falling victim to phishing attacks. Over 300 participants completed an online survey assessing protective and vulnerable strategies, personality styles, trust in people, prior victimization from catphishing or identity theft, and demographics information. Unbeknownst to the participants, 2 to 4 weeks after completing the survey they received a phishing e-mail asking them to click on a link. Individuals with a stronger systematic decision-making style were more likely to have a greater number of protective strategies, and those with greater protective strategies were less likely to be a victim of catphishing and identity theft. Individuals with low avoidant decision-making styles and prior vulnerable strategies were more likely to be phished. These findings suggest that learning protective strategies and not using vulnerable strategies are insufficient to lower substantially the risk of being phished. Training might be improved through considering the match between decision-making styles and the content of the training.
Most research on internet-frauds has focused on victims' cognitive and personality vulnerabilities and ignored that scammers often have been victims of financial cyber-crimes [1]. These victim-offenders expressed retaliation as a motive to offend and highlight the overlooked emotions and social learning contributing to cyber-scams [2]. A broader understanding of the motives, emotions and knowledge of victim-offenders, solely offenders and solely victims might improve awareness campaigns and security training [3]. In this talk, I use a life-course perspective of social learning [4] to examine media and social sources, prior victimization, and knowledge and attitudes about relationships contribute to committing internet frauds. Data are drawn from two large self-report surveys of victimization and perpetration of a wide range of internet frauds. Deviant friends and family members, mentors, online discussions, and contacts in the dark web increase support for retaliation and provide praise for perpetrating internet-fraud. Those who attended victim support groups and have knowledge of dating app etiquette have more accurate knowledge about suspicious communications on dating apps. Beyond low self-control, psychopathy and committing frauds in the real world, those with higher rates of victimization more often perpetrated cyber-frauds. The life-course perspective suggests a broader view of the emotional and social context of offending might improve the content and focus of awareness campaigns and security training. These campaigns and training often ignore how scammers learn manipulative tactics from friends, family, media, and online sources. This focus also might enhance AI tools to detect and intercept fraudulent messages on dating and social media sites.
In this paper, we explore third parties who unexpectedly fell within the legal definition of a sex trafficker. The anti-trafficking lobby and media stories frequently portray traffickers as organised, psychopathic, violent, and child kidnappers. We dismantle these depictions by showing the unexpected people who qualify as traffickers. This paper incorporates findings from two studies involving eighty-five third parties in New York City and forty-nine in Chicago. We analyse how teenagers, drivers, and boyfriends qualify as traffickers under US law. We find that two-thirds of them hold inaccurate views about the difference between sex trafficking and facilitating prostitution. Trafficking can be incidental or temporary, and traffickers in these samples were often oblivious to their legal status, potentially resulting in lengthy prison sentences. We conclude by calling for differential sentencing based on traffickers' age, and awareness campaigns designed to alert third parties of the legal distinctions between pandering and sex trafficking.
This study employs classification tree analysis (CTA) to address whether 3 groups of violent offenders have similar or different risk factors for violent recidivism while on probation. A sample of 1,344 violent offenders on probation was classified as generalized aggressors (N = 302), family only aggressors (N = 321), or nonfamily only aggressors (N = 717). The strongest predictor of violent recidivism while on probation was whether the offender was a generalized aggressor or not, with generalized aggressors more likely to be arrested for new violent crimes. Prior arrests for violent crimes predicted violent recidivism of generalized aggressors, but did not significantly predict violent recidivism of family only and nonfamily only aggressors. For generalized aggressors and family only batterers, treatment noncompliance was an important risk predictor of violent recidivism. CTA compared to logistic regression classified a higher percentage of cases into low-risk and high-risk groups, provided higher improvement in classification accuracy of violent recidivists beyond chance performance, and provided a better balance of false positives and false negatives. The implications for the risk assessment and domestic violence literature are discussed.
Identity, values, and emotional processes underlying desistance and persistence in the illicit sex trade have received little empirical attention. An analysis of qualitative interviews of 49 active pimps or drivers managing sex workers showed that persisting pimps and those leading double lives assigned different meanings to their participation in legitimate employment. Persisters valued legitimate work as a strategy to evade arrest, whereas pimps with "double lives" emphasized legitimate work as providing long-term financial security and enhanced social identity. Analysis yielded contextualized understanding of their self-narratives (e.g.) that underlie reflections upon who they are and who they want to become, and the moral contemplations and emotional processes involved in stigma management.