English
Related papers

Related papers: Weak Links in Authentication Chains: A Large-scale…

200 papers

The escalating threat of phishing emails has become increasingly sophisticated with the rise of Large Language Models (LLMs). As attackers exploit LLMs to craft more convincing and evasive phishing emails, it is crucial to assess the…

Cryptography and Security · Computer Science 2024-11-22 Khalifa Afane , Wenqi Wei , Ying Mao , Junaid Farooq , Juntao Chen

We present the first large-scale characterization of lateral phishing attacks, based on a dataset of 113 million employee-sent emails from 92 enterprise organizations. In a lateral phishing attack, adversaries leverage a compromised…

Cryptography and Security · Computer Science 2019-10-03 Grant Ho , Asaf Cidon , Lior Gavish , Marco Schweighauser , Vern Paxson , Stefan Savage , Geoffrey M. Voelker , David Wagner

Email remains a central communication medium, yet its long-standing design and interface conventions continue to enable deceptive attacks. This research note presents a structured list of 42 email-based deception techniques, documented with…

Cryptography and Security · Computer Science 2026-04-07 Maxime Veit , Mattia Mossano , Tobias Länge , Melanie Volkamer

Phishing is one of the most prevalent and expensive types of cybercrime faced by organizations and individuals worldwide. Most prior research has focused on various technical features and traditional representations of text to characterize…

Cryptography and Security · Computer Science 2024-08-20 Tarini Saka , Rachiyta Jain , Kami Vaniea , Nadin Kökciyan

We show practical attacks against OpenPGP and S/MIME encryption and digital signatures in the context of email. Instead of targeting the underlying cryptographic primitives, our attacks abuse legitimate features of the MIME standard and…

Cryptography and Security · Computer Science 2019-04-18 Jens Müller , Marcus Brinkmann , Damian Poddebniak , Sebastian Schinzel , Jörg Schwenk

Phishing attacks pose a significant cybersecurity threat globally. This study investigates phishing susceptibility within the Pakistani population, examining the influence of demographic factors, technological aptitude and usage, previous…

Computers and Society · Computer Science 2025-10-13 Javara A. Bukhsh , Maya Daneva , Marten van Sinderen

Modern software development frequently uses third-party packages, raising the concern of supply chain security attacks. Many attackers target popular package managers, like npm, and their users with supply chain attacks. In 2021 there was a…

Cryptography and Security · Computer Science 2022-02-15 Nusrat Zahan , Thomas Zimmermann , Patrice Godefroid , Brendan Murphy , Chandra Maddila , Laurie Williams

This study explores the widespread perception that personal data, such as email addresses, may be shared or sold without informed user consent, investigating whether these concerns are reflected in actual practices of popular online…

Social and Information Networks · Computer Science 2025-02-20 Scott Seidenberger , Oluwasijibomi Ajisegiri , Noah Pursell , Fazil Raja , Anindya Maiti

Anomalies in emails such as phishing and spam present major security risks such as the loss of privacy, money, and brand reputation to both individuals and organizations. Previous studies on email anomaly detection relied on a single type…

Cryptography and Security · Computer Science 2022-03-22 Craig Beaman , Haruna Isah

Phishing attacks are one of the most common social engineering attacks targeting users emails to fraudulently steal confidential and sensitive information. They can be used as a part of more massive attacks launched to gain a foothold in…

Cryptography and Security · Computer Science 2022-01-27 Fatima Salahdine , Zakaria El Mrabet , Naima Kaabouch

Digital service providers often prioritize a frictionless user experience by adopting technologies that simplify access to their services. One widely used mechanism is the Short Message Service (SMS) to deliver links (URLs) that enable…

Cryptography and Security · Computer Science 2026-01-15 Muhammad Danish , Enrique Sobrados , Priya Kaushik , Bhupendra Acharya , Muhammad Saad , Abdullah Mueen , Sazzadur Rahaman , Afsah Anwar

Spam messes up users inbox, consumes resources and spread attacks like DDoS, MiM, phishing etc. Phishing is a byproduct of email and causes financial loss to users and loss of reputation to financial institutions. In this paper we examine…

Cryptography and Security · Computer Science 2011-08-09 Cynthia Dhinakaran , Dhinaharan Nagamalai , Jae Kwang Lee

Researchers that work for the same institution use their email as the main communication tool. Email can be one of the most fruitful attack vectors of research institutions as they also contain access to all accounts and thus to all private…

Cryptography and Security · Computer Science 2021-04-01 Asier Gutiérrez-Fandiño , Jordi Armengol-Estapé , Marta Villegas

In this paper, we present findings from a large-scale and long-term phishing experiment that we conducted in collaboration with a partner company. Our experiment ran for 15 months during which time more than 14,000 study participants…

Cryptography and Security · Computer Science 2021-12-15 Daniele Lain , Kari Kostiainen , Srdjan Capkun

Nowadays, cybersecurity is crucial. Therefore, cybersecurity awareness should be a concern for businesses, particularly critical infrastructure organizations. The results of this study, using simulated phishing attacks, indicate that in the…

Cryptography and Security · Computer Science 2024-10-29 Patsita Sirawongphatsara , Phisit Pornpongtechavanich , Nattapong Phanthuna , Therdpong Daengsi

Deep learning has revolutionized email filtering, which is critical to protect users from cyber threats such as spam, malware, and phishing. However, the increasing sophistication of adversarial attacks poses a significant challenge to the…

Cryptography and Security · Computer Science 2025-05-08 Esra Hotoğlu , Sevil Sen , Burcu Can

The most widespread type of phishing attack involves email messages with links pointing to malicious content. Despite user training and the use of detection techniques, these attacks are still highly effective. Recent studies show that it…

Cryptography and Security · Computer Science 2025-02-28 Daniele Lain , Yoshimichi Nakatsuka , Kari Kostiainen , Gene Tsudik , Srdjan Capkun

Emails today are often encrypted, but only between mail servers---the vast majority of emails are exposed in plaintext to the mail servers that handle them. While better than no encryption, this arrangement leaves open the possibility of…

Cryptography and Security · Computer Science 2017-03-01 Trinabh Gupta , Henrique Fingler , Lorenzo Alvisi , Michael Walfish

Traditional email encryption schemes are vulnerable to EFail attacks, which exploit the lack of message authentication by manipulating ciphertexts and exfiltrating plaintext via HTML backchannels. Swiss Post's IncaMail, a secure email…

Cryptography and Security · Computer Science 2023-06-26 Pascal Gerig , Jämes Ménétrey , Baptiste Lanoix , Florian Stoller , Pascal Felber , Marcelo Pasin , Valerio Schiavoni

Electronic mail services have become an important source of communication for millions of people all over the world. Due to this tremendous growth, there has been a significant increase in spam traffic. Spam messes up user's inbox, consumes…

Cryptography and Security · Computer Science 2010-12-09 Dhinaharan Nagamalai , Beatrice Cynthia Dhinakaran , Jae Kwang Lee