The Human Firewall's Cracks: How Personality Drives Phishing Susceptibility on Social Media
Computers & Security
This study proposes a theoretical model to explore phishing susceptibility on Social Network Sites (SNSs) by integrating the Big Five personality traits with the Heuristic-Systematic Model (HSM) of information processing. Using structural equation modeling (SEM) on data from 215 respondents, it identifies that specific personality traits, particularly low conscientiousness and high neuroticism, significantly influence the cognitive "shortcuts" that lead to successful phishing victimization.
TL;DR
Why do some people click on obvious "Clickbait" while others remain skeptical? This research dives into the psychology of Social Network Site (SNS) phishing. By linking the Big Five Personality Traits to the Heuristic-Systematic Model (HSM) of information processing, the study proves that our personality determines whether we use cognitive "shortcuts" (heuristics) that phishers love or analytical thinking (systematic processing) that keeps us safe.
Problem & Motivation: The "Weakest Link" Reframed
For decades, the industry has termed the human user as the "weakest link" in security. However, this is an oversimplification. As technological filters improve, attackers have pivoted to Social Engineering (SE)—using psychological triggers like fear, curiosity, and authority to bypass technical defenses.
The authors argue that existing research on personality and phishing is inconsistent. Some studies say Extraverts are more prone to attacks; others say they aren't. THE INSIGHT: The missing link is Information Processing. Personality doesn't just dictate what we do; it dictates how we think when we see a message.
Methodology: Mapping the Mind to the Attack
The researchers built a model (visualized below) that examines how the Big Five traits influence two modes of thinking:
- Heuristic Processing: Fast, low-effort, relying on "rules of thumb" (e.g., "It has a Facebook logo, so it's safe").
- Systematic Processing: Slow, high-effort, analytical (e.g., checking the actual sender address vs. the display name).

Using 215 students and a series of simulated Facebook phishing attacks (e.g., fake vouchers, "breaking news" videos, and account updates), the study measured the cognitive responses of the participants.
Key Insights: Who is Most Vulnerable?
The results from the Structural Equation Modeling (SEM) revealed a complex psychological landscape:
- The Conscientiousness Shield: Conscientious individuals (organized, rule-following) were significantly less likely to use heuristic processing. They are the "skeptics" of the social media world.
- The Neuroticism Paradox: High neuroticism (anxiety-prone) was found to correlate with higher heuristic processing, likely because the stress or "fear appeals" used in phishing messages overwhelm their cognitive resources, leading to impulsive clicks.
- The Heuristic Trap: The study confirmed that Heuristic Processing is the primary driver of susceptibility (β = 0.287). If an attacker can trigger a heuristic response—through curiosity or urgency—the battle is largely won.

Critical Analysis & Industry Impact
One of the most striking findings was that Systematic Processing (analytical thinking) did not significantly decrease susceptibility. This suggests that even when users "think" about a message, they might not have the correct knowledge to identify the subtle technical cues of a sophisticated attack.
Future Implications:
- Personalised Security Training: Organizations should move away from generic "Don't Click" videos. Instead, use personality assessments to identify "at-risk" employees and provide targeted training that specifically counters their heuristic tendencies.
- Designing for Friction: SNS platforms could implement "intentional friction" for users identified (via behavior) as high-heuristic processors, forcing a switch to systematic evaluation.
Conclusion
Phishing is not just a technical problem; it is a behavioral one. By understanding that personality acts as a filter for information processing, we can better predict and mitigate the success of social engineering. Conscientious habits are our best defense, but even the most analytical user is at risk if they lack the specific "cues" to look for.
Takeaway: Our online safety is as much about how we process information as it is about what information we are given.
