Awareness, Intention, (In)Action: Individuals’ Reactions to Data Breaches

Mayer, Peter ORCID iD icon 1; Zou, Yixin; Lowens, Byron M.; Dyer, Hunter A.; Le, Khue; Schaub, Florian; Aviv, Adam J.
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)


Data breaches are prevalent. We provide novel insights into individuals’ awareness, perception, and responses to breaches that affect them through two online surveys: a main survey (n = 413) in which we presented participants with up to three breaches that affected them, and a follow-up survey (n = 108) in which we investigated whether the main study participants followed through with their intentions to act. Overall, 73% of participants were affected by at least one breach, but participants were unaware of 74% of breaches affecting them. Although some reported intention to take action, most participants believed the breach would not impact them. We also found a sizable intention-behavior gap. Participants did not follow through with their intention when they were apathetic about breaches, considered potential costs, forgot, or felt resigned about taking action. Our findings suggest that breached organizations should be held accountable for more proactively informing and protecting affected consumers.

DOI: 10.5445/IR/1000164146
Veröffentlicht am 09.01.2024
DOI: 10.1145/3589958
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsdatum 31.10.2023
Sprache Englisch
Identifikator ISSN: 1073-0516, 1557-7325
KITopen-ID: 1000164146
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in ACM Transactions on Computer-Human Interaction
Verlag Association for Computing Machinery (ACM)
Band 30
Heft 5
Seiten 1–53
Vorab online veröffentlicht am 23.09.2023
Nachgewiesen in Dimensions
Web of Science
