Literature Review: Misconceptions About Phishing

Mossano, Mattia ORCID iD icon 1; Volkamer, Melanie ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)


Phishing is a danger to both private users and businesses.
Industry and academia have proposed several approaches to deal with this threat, many of which developed with a supposedly human-centric design.
Yet, to our knowledge, there is no research focused on the misconceptions that users might have on phishing.
This glaring gap is a problem, as previous research has shown that not engaging with the mental model of users can lead to lack of effectiveness of an approach in the real world.
To address this gap, we conducted a systematic literature review starting from papers published at CHI in the last ten years, and expanding to other venues through a backward and a forward search based on the initial relevant CHI papers.
We identified 15 misconceptions about phishing in 21 papers that researchers should address in their solutions to enhance the effectiveness of their approaches.

