O3.04.7Contextualized phishing warningdesignresearch

An isolated, context-free warning does not connect users to the risk

Aliases: contextual phishing warning · risk-action explanation · contextual security warning

What it is

A contextualized phishing warning explains a specific anomaly, consequence, and safe alternative where the risky action occurs: “This login domain differs from your usual workplace site; reopen it from your bookmark.” A detached “beware of scams” banner makes the user infer the connection to the current object and task, so it readily becomes background noise.

Why it happens

The user's primary goal is the task promised by the message, and a generic warning neither challenges that premise nor supplies a next step. Warnings that appear early, frequently, or identically at every risk train bypass. Co-locating trigger evidence, imminent action, and a low-cost alternative reduces the translation from abstract knowledge to present risk and makes the benefit of stopping visible.

Studying it

At the same risk event, compare a generic banner, anomaly-only text, and anomaly plus consequence plus alternative. Have participants handle legitimate and malicious tasks; measure comprehension, continuation, correct rerouting, false blocking, task time, and later recall, stratified by context and message difficulty. High exit is not automatically success if legitimate work is broadly abandoned through fear or unusability.

Where it stops holding

Signals may be uncertain, so wording should state evidence and confidence boundaries rather than fabricate confirmed attack. When exact detection details aid evasion, communicate the user-relevant anomaly without disclosing thresholds. High-risk events may justify a hard block and extra verification; low-risk ones may not justify modal interruption. Contextual warnings still do not replace filtering or phishing-resistant authentication.

Applying it

  • Before credential submission, login approval, payment, or download, show the object-specific anomaly, plausible harm, and recommended alternative.
  • Offer a direct safe action—close and open the authenticated app, contact a saved person, or report the message—not only “continue/cancel.”
  • Retain domain, sender, device, or transaction summary for comparison, showing only evidence that can change the decision.
  • Validate correct rerouting and legitimate-task recovery, and monitor disregard after repeated exposure rather than counting dialog clicks alone.

Related

  • Same group: O3.04.1 Source-verification burden · O3.04.5 Vigilance decay · O3.04.6 Defense in depth
  • Adjacent: O3.05 Security-warning fatigue · O3.06 Trusted path
  • Search terms: contextual phishing warning · risk-specific warning · safe alternative action

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O3.04.7