O3.04

Phishing Recognition Cues

Cards in this group · 7

  1. O3.04.1Users have difficulty verifying source authenticity
  2. O3.04.2Domains and sender fields are weak cues
  3. O3.04.3The system should provide a trustworthy source indicator
  4. O3.04.4Spelling and visual lookalikes can fool users during rapid domain scanning
  5. O3.04.5Vigilance gained from security education decays with time and fatigue
  6. O3.04.6Relying only on users to detect phishing is a limited defense
  7. O3.04.7An isolated, context-free warning does not connect users to the risk