Emotions help explain why people click phishing emails
People may click on a link designed to steal their data because they are afraid to get in trouble for ignoring the message. This was one of the findings of a new study, which examined the emotional responses triggered by scams and how emotions influence behaviour in an experimental setting modelled on a workplace.
Phishing attackers know how to exploit, for example, a recipient’s sense of urgency and stress. However, according to assistant professor Verena Distler from Aalto University, we still know relatively little about the psychological processes that take place in the target of a phishing attack.
‘Our study is one of the first attempts to gain a richer understanding of people’s emotions at the precise moment they encounter a phishing attempt. If we understand these psychological processes more deeply, we can do more to prevent scams and support technology users in making informed decisions, even in challenging situations,’ Distler says.
The study was carried out by Distler and doctoral researcher Raphael Weidhaas from Aalto University in Finland, and postdoctoral researcher Alexandra von Preuschen from CISPA Helmholtz Centre for Information Security in Germany.
An experiment in a fictional office
The experimental study involved 41 volunteers. In an experiment designed to simulate an office environment, the participants were asked to handle an absent colleague’s tasks in their absence as effectively as possible. They did not know that the study was related to phishing emails.
During the work task, the participants received an email that appeared to be related to their duties. However, the link in the message led to a phishing website created by the researchers. The email included different ‘red flags’ which allowed participants to detect the phishing email, such as the sender’s name or email address. To make the messages seem genuine and work-related, the researchers used relatively moderate wording, such as ‘please fill in your details’ and ‘your task is almost complete’.
More than half of the participants recognised the phishing attempt and did not click. Some clicked on the message, but only a few entered their details on the fraudulent website. Some participants did not notice the scam but did not click the link either.
Immediately after the experiment, the researchers used questionnaires and interviews to investigate the emotional responses triggered by the phishing attempt.
Concerns about losing face
The study found that participants clicked on the phishing email if they felt it was plausibly related to their work or to an unfinished task. Participants also clicked because of uncertainty: had they made a mistake earlier that now needed correcting? Would their manager be angry if they did not click? What would their colleagues think if they failed to complete the task?
‘Feelings of anxiety, worry and nervousness do not help with problem-solving in that moment – in other words, they do not help people recognise a scam,’ says doctoral researcher Raphael Weidhaas.
Those who clicked on the fraudulent link subsequently felt ashamed, disappointed and guilty.
‘We were surprised that, even though the participants knew that the ‘work’ was part of a study, those who clicked were still afraid of losing face in front of their colleagues if they did not complete the task requested in the scam email quickly,’ Weidhaas says.
According to Weidhaas, people should instead be encouraged to raise concerns about suspicious messages.
‘A phishing attack might be prevented simply by asking a colleague to look at the email and assess whether it appears genuine.’
The research also provided information on why people do not click suspicious links. For many who detected the phish, the email had interrupted their current workflow, which created a feeling of suspicion.
‘Many reported they intuitively felt something was odd in the email. They then applied detection strategies they had learned from previous trainings, such as checking the sender address. They reported that these detection skills made them feel safe and able to deal with the situation,’ says Weidhaas.
Improved anti-phishing trainings
According to Weidhaas, current approaches to teaching people how to recognise phishing attempts may even be counterproductive. Common methods used by organisations include online courses, awareness campaigns and simulated phishing emails.
‘Employees may be sent fake phishing emails, and if they click the link, they are shown educational material. However, these campaigns can cause shame and fear of the consequences,’ Weidhaas says.
Weidhaas believes that people learn better through positive emotions than negative ones. Awareness activities should not leave anyone feeling miserable.
‘Training could make use of genuine phishing emails received by the organisation, as these are often the most difficult to detect. Employees could analyse the messages together with an IT expert and discuss their concerns openly.’
A positive training experience can evoke emotions such as pride and confidence, which could support the development of people’s ability to recognise phishing attempts.
The study was published at the Symposium on Usable Privacy and Security (SOUPS 2026) conference in August 2026.
Read more news
Panu Miettinen Explores the Journey from Research to Business
Introduced the R2B funding instrument.’Learning doesn’t end with a degree’ – Heli Bergström fully embraced the AI transformation
Aalto University alum Heli Bergström aims to support the development of Aalto’s doctoral education through her legacy gift.
Aalto ARTS’s Eloseminaari event started the new academic year
The annual Eloseminaari event focused on reviewing and celebrating the work that has been done, meeting new professionals in the community and talking about the role of AI in society.