Marianne Junger

dblp:136/9942 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0002-9515-9860ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Relationships between cultural orientations, phishing victimization, and phishing recognition: A cross-cultural experiment
abstract
Background : Humans remain a critical vulnerability in the cybersecurity chain. While research has explored various behavioral factors influencing phishing susceptibility, the role of national culture and individual cultural orientations remains under-researched, representing a significant gap in the literature. Aims : This study investigates the impact of individual cultural orientations on phishing victimization, while taking into account other relevant factors, such as self-control, risk-taking, technical training, email management practices, demographics (age and gender), and country-level economic and ICT development. Methods : Data were collected via an online survey of university students (N = 2,143) across 12 countries in Asia, Africa, North America, and Europe. Outcomes measures included phishing victimization, phishing recognition, and legitimate email recognition; the last two measures were assessed via scenarios. Data were analyzed using Signal Detection Theory and mixed modelling. Results : Phishing victimization was significantly associated with low self-control, high risk-taking, high exposure, and poorer recognition of legitimate emails. Conversely, cultural orientations, religiosity, and country of origin had minimal effects. While phishing recognition was unrelated to victimization, the ability to recognize legitimate emails reduced victimization risk. For culturally diverse organizations, these findings suggest that cultural factors may be less critical to phishing victimization than has been previously assumed. Training users and improved self-control techniques may help protect against phishing victimization.
Marianne Junger, Pawel Olber, Rafal Plocki, J. W. (Hans) Luyten, Luka Koning, Caitlyn N. Muniz, Jan-Willem Bullee, Victoria Wang, Reinhardt A. Botha, C. Jordan Howell, Verena Distler, Xiaowei Chen 0013, Cong Hiep Pham 0001, Mohammed Aljohani, Newman U. Richards, Fabian Muhly, Abhishta, Steven Furnell
Comput. Secur.1
2024 Deception in double extortion ransomware attacks: An analysis of profitability and credibility
abstract
Ransomware attacks have evolved with criminals using double extortion schemes, where they signal data exfiltration to inflate ransom demands. This development is further complicated by information asymmetry, where victims are compelled to respond to ambiguous and often deceptive signals from attackers. This study explores the complex interactions between criminals and victims during ransomware attacks, especially focusing on how data exfiltration is communicated. We use a signaling game to understand the strategies both parties use when dealing with uncertain information. We identify five distinct equilibria, each characterized by the criminals' varied approaches to signaling data exfiltration, influenced by the strategic parameters inherent in each attack scenario. Calibrating the game parameters with real-world like values, we identify the most probable equilibrium, offering insights into anticipated ransom amounts and corresponding payoffs for both victims and criminals. Our findings suggest criminals are likely to claim data exfiltration, true or not, highlighting a strategic advantage for intensifying attack efforts. The study underscores the need for victims' caution towards criminals' claims and highlights the unintended consequences of policies making false claims costlier for criminals.
Tom Meurs, Edward J. Cartwright, Anna Cartwright 0001, Marianne Junger, Abhishta
Comput. Secur.4
2023 The development of phishing during the COVID-19 pandemic: An analysis of over 1100 targeted domains
abstract
To design preventive policy measures for email phishing, it is helpful to be aware of the phishing schemes and trends that are currently applied. How phishing schemes and patterns emerge and adapt is an ongoing field of study. Existing phishing works already reveal a rich set of phishing schemes, patterns, and trends that provide insight into the mechanisms used. However, there seems to be limited knowledge about how email phishing is affected in periods of social disturbance, such as COVID-19 in which phishing numbers have quadrupled. Therefore, we investigate how the COVID-19 pandemic influences the phishing emails sent during the first year of the pandemic. The email content (header data and html body, excl. attachments) is evaluated to assess how the pandemic influences the topics of phishing emails over time (peaks and trends), whether email campaigns correlate with momentous events and trends of the COVID-19 pandemic, and what hidden content revealed. This is studied through an in-depth analysis of the body of 500.000 phishing emails addressed to Dutch registered top-level domains collected during the start of the pandemic. The study reveals that most COVID-19 related phishing emails follow known patterns indicating that perpetrators are more likely to adapt than to reinvent their schemes.
Raphael Hoheisel, Guido van Capelleveen, Dipti Kapoor Sarmah, Marianne Junger
Comput. Secur.4
2020 How effective are social engineering interventions? A meta-analysis
abstract
Purpose Social engineering is a prominent aspect of online crime. Various interventions have been developed to reduce the success of this type of attacks. This paper aims to investigate if interventions can help to decrease the vulnerability to social engineering attacks. If they help, the authors investigate which forms of interventions and specific elements constitute success. Design/methodology/approach The authors selected studies which had an experimental design and rigorously tested at least one intervention that aimed to reduce the vulnerability to social engineering. The studies were primarily identified from querying the Scopus database. The authors identified 19 studies which lead to the identification of 37 effect sizes, based on a total sample of N = 23,146 subjects. The available training, intervention materials and effect sizes were analysed. The authors collected information on the context of the intervention, the characteristics of the intervention and the characteristics of the research methodology. All analyses were performed using random-effects models, and heterogeneity was quantified. Findings The authors find substantial differences in effect size for the different interventions. Some interventions are highly effective; others have no effect at all. Highly intensive interventions are more effective than those that are low on intensity. Furthermore, interventions with a narrow focus are more effective than those with a broad focus. Practical implications The results of this study show differences in effect for different elements of interventions. This allows practitioners to review their awareness campaigns and tailor them to increase their success. Originality/value The authors believe that this is the first study that compares the impact of social engineering interventions systematically.
Jan-Willem Bullee, Marianne Junger
Inf. Comput. Secur.2
2017 How Effective is Anti-Phishing Training for Children?
Elmer Lastdrager, Inés Carvajal Gallardo, Pieter H. Hartel, Marianne Junger
SOUPS4
2017 Spear phishing in organisations explained
abstract
Purpose The purpose of this study is to explore how the opening phrase of a phishing email influences the action taken by the recipient. Design/methodology/approach Two types of phishing emails were sent to 593 employees, who were asked to provide personally identifiable information (PII). A personalised spear phishing email opening was randomly used in half of the emails. Findings Nineteen per cent of the employees provided their PII in a general phishing email, compared to 29 per cent in the spear phishing condition. Employees having a high power distance cultural background were more likely to provide their PII, compared to those with a low one. There was no effect of age on providing the PII requested when the recipient’s years of service within the organisation is taken into account. Practical implications This research shows that success is higher when the opening sentence of a phishing email is personalised. The resulting model explains victimisation by phishing emails well, and it would allow practitioners to focus awareness campaigns to maximise their effect. Originality/value The innovative aspect relates to explaining spear phishing using four socio-demographic variables.
Jan-Willem Bullee, Lorena Montoya, Marianne Junger, Pieter H. Hartel
Inf. Comput. Secur.3