"Now I'm a bit angry:" Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them

Mayer, Peter ORCID iD icon; Zou, Yixin; Schaub, Florian; Aviv, Adam J.

Despite the prevalence of data breaches, there is a limited understanding of individuals' awareness, perception, and responses to breaches that affect them. We provide novel insights into this topic through an online study (n=413) in which we presented participants with up to three data breaches that had exposed their email addresses and other personal information. Overall, 73% of participants were affected by at least one breach, 5.36 breaches on average. Many participants attributed the cause of being affected by a breach} to their poor email and security practices; only 14% correctly attributed the cause to external factors such as breached organizations and hackers. Participants were unaware of 74% of displayed breaches and expressed various emotions when learning about them. While some reported intending to take action, most participants believed the breach would not impact them. Our findings underline the need for user-friendly tools to improve consumers' resilience against breaches and accountability for breached organizations to provide more proactive post-breach communications and mitigations.

Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 11.08.2021
Sprache Englisch
Identifikator ISBN: 978-1-939133-24-3
KITopen-ID: 1000132793
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in 30th USENIX Security Symposium, Vancouver, CDN, August 11-13, 2021
Veranstaltung 30th USENIX Security Symposium (2021), Online, 11.08.2021 – 13.08.2021
Verlag Advanced Computing Systems Association (USENIX)
Seiten 393-410
Vorab online veröffentlicht am 01.04.2021
Externe Relationen Siehe auch
