Measuring the Impact of Embedded Phishing Training on Ransomware-Lure Click Behavior: A Field Study Across Three Organizations

Authors

  • Aminu Muhammad Auwal Faculty of Natural Sciences, University of Jos, Plateau State, Nigeria
  • Sulaiman Shehu Department of Software Engineering, Bayero University, Kano, Kano State, Nigeria

DOI:

https://doi.org/10.70112/ajsat-2026.15.1.4350

Keywords:

Phishing Simulation, Embedded Training, Ransomware Delivery, Field Experiment, Randomized Controlled Trial, Click-Through Rate, Lure Category, Urgency, Engagement, Time-On-Module, Protection Motivation Theory, Security Awareness

Abstract

Embedded anti-phishing training, redirecting employees who fail simulated phishing campaigns to immediate instructional content, is among the most widely deployed behavioral defenses against ransomware-delivering social engineering attacks. Despite this widespread adoption, recent large-scale randomized evaluations have produced evidence of only marginal absolute reductions in failure rates, raising fundamental questions about whether the current model of simulated phishing plus embedded training is an effective and efficient use of organizational security resources. A critical gap in the existing literature is the absence of lure-category-specific analyses: virtually all prior evaluations have used heterogeneous phishing campaign portfolios without examining whether training effectiveness varies systematically across the specific delivery techniques—fake software updates, spoofed invoices, and urgency-framed credential resets—most commonly associated with ransomware campaigns. This study aimed to: (1) determine whether embedded 90-second micro-training produces a statistically significant reduction in click-through rates for ransomware-style phishing lures compared with instructor-led training only and a no-training control in a randomized field experiment; (2) examine whether training effectiveness differs across three ransomware-relevant lure categories differing in their reliance on visual artifact inspection versus urgency-driven cognitive override; and (3) assess whether employee engagement with embedded training content as measured by time-on-module moderates the protective effect at the individual level. A six-month randomized field experiment was conducted across three mid-sized organizations (combined n = 1,284 employees). Employees were randomly assigned within department strata to embedded micro-training (n = 428), instructor-led annual training only (n = 426), or a control group receiving standard onboarding only (n = 430). Six monthly simulated campaign waves sent one email from each of three ransomware-relevant lure categories—fake software update notifications, spoofed invoices, and urgent credential-reset requests—to all participants. Click-through rates were compared within conditions using McNemar's test and between conditions using chi-square tests. Individual-level engagement (time-on-module) was assessed as a moderator among the embedded training group. The embedded micro-training group showed a significant overall click-rate reduction from 18.4% to 13.1% (−5.3 pp, p = 0.002), significantly larger than the instructor-led (−1.5 pp, p = 0.214) or control (−1.7 pp, p = 0.389) reductions. Effectiveness was highly lure-dependent: the fake software update category showed a 12.4 pp reduction (p < 0.001); the spoofed invoice category showed a 4.4 pp reduction (p = 0.038); the urgent credential-reset category showed only a 1.8 pp non-significant reduction (p = 0.412). Participants engaging with training content above the median time (>52 seconds) showed significantly larger individual-level reductions in subsequent click likelihood (OR = 0.52, p = 0.011) than below-median engagers (OR = 0.81, p = 0.204). Embedded micro-training produces a measurable but strongly lure-dependent reduction in ransomware-relevant phishing susceptibility. Urgency-based credential-reset lures, among the most common ransomware initial-access vectors, are largely resistant to this intervention, indicating that technical controls including multi-factor authentication and DNS-level phishing filtering are necessary complements regardless of training investment. Engagement with training content rather than mere completion is a key moderator of effectiveness, suggesting that addressing the engagement gap may be as important as content quality in improving training outcomes

References

[1] S. Razaulla, C. Fachkha, C. Markarian, A. Gawanmeh, W. Mansoor, B. C. Fung, and C. Assi, "The age of ransomware: A survey on the evolution, taxonomy, and research directions," IEEE Access, vol. 11, pp. 40698–40723, 2023, doi: 10.1109/ACCESS.2023.3268535.

[2] O. Oz, A. Aris, A. Levi, and A. S. Uluagac, "A survey on ransomware: Evolution, taxonomy, and defense solutions," ACM Comput. Surveys, vol. 54, no. 11s, pp. 1–37, Jan. 2022, doi: 10.1145/3514185.

[3] B. Longtchi, R. M. Rodriguez, L. Al-Shawaf, A. Atyabi, and S. Xu, "Internet-based social engineering attacks, defenses and psychology: A survey," arXiv preprint arXiv: 2203.08302, 2022.

[4] R. Mayer, "Applying the science of learning to multimedia instruction," in Psychol. Learn. Motivation, vol. 54, San Diego, CA: Academic Press, 2011, pp. 77–108, doi: 10.1016/B978-0-12-385527-5.00003-4.

[5] M. Han, H. Zhao, X. Ma, and R. Shi, "Influencing factors of information security behavior among college students based on protection motivation theory: Evidence from China," Front. Public Health, vol. 13, p. 1677024, 2025, doi: 10.3389/fpubh.2025.1677024.

[6] G. Ho, A. Mirian, E. Luo, G. Durumeric, and V. Paxson, "Understanding the efficacy of phishing training in practice," in Proc. IEEE Symp. Security Privacy (SP), San Francisco, CA, USA, 2025, doi: 10.1109/SP61157.2025.00076.

[7] G. Ho, A. Mirian, E. Luo, G. Durumeric, and V. Paxson, "Understanding the efficacy of phishing training in practice," Univ. of Chicago / UCSD Technical Report, 2025.

[8] M. De Bona and F. Paci, "A real world study on employees' susceptibility to phishing attacks," in Proc. 15th Int. Conf. Availability, Reliability and Security (ARES), Karlsruhe, Germany, 2020, pp. 4:1–4:10, doi: 10.1145/3407023.3409179.

[9] N. Marshall, D. Sturman, and J. C. Auton, "Exploring the evidence for email phishing training: A scoping review," Computers & Security, vol. 139, art. 103695, 2024, doi: 10.1016/j.cose.2023.103695.

[10] S. S. Alshammari, B. Soh, and A. Li, "Understanding social engineering victimisation on social networking sites: A comprehensive review of factors influencing user susceptibility to cyber-attacks," Information, vol. 16, no. 2, p. 153, 2025, doi: 10.3390/info16020153.

[11] T. Sommestad and H. Karlzen, "The unpredictability of phishing susceptibility: Results from a repeated measures experiment," J. Cybersecurity, vol. 10, no. 1, p. tyae021, 2024, doi: 10.1093/cybsec/tyae021.

[12] J. Li and A. Y. K. Chua, "Think or respond: Understanding the impact of cognitive appraisals on threat detection and phishing susceptibility," Proc. Assoc. Inf. Sci. Technol., vol. 62, pp. 384–395, 2025, doi: 10.1002/pra2.1264.

[13] C. Gerdenitsch, D. Wurhofer, and M. Tscheligi, "Working conditions and cybersecurity: Time pressure, autonomy and threat appraisal shaping employees' security behavior," Cyberpsychol. J. Psychosoc. Res. Cyberspace, vol. 17, no. 4, 2023, doi: 10.5817/CP2023-4-7.

[14] O. O. Blaise, I. Aaron, U. Alfred, and A. Amusa, "Evaluating the ethical frameworks of information security professionals: A comparative analysis," Asian J. Comput. Sci. Technol., vol. 13, no. 2, pp. 61–66, Nov. 2024, doi: 10.70112/ajcst-2024.13.2.4289.

[15] M. S. Islam, M. Sajjad, M. M. Hasan, and M. S. I. Mazumder, "Phishing attack detecting system using DNS and IP filtering," Asian J. Comput. Sci. Technol., vol. 12, no. 1, pp. 16–20, 2023, doi: 10.51983/ajcst-2023.12.1.3552.

[16] S. Ravichandran and K. L. N. Rao, "Design and development of an advancing web information stockpiling for engraved ontology in user contours," Asian J. Comput. Sci. Technol., vol. 11, no. 2, pp. 11–15, 2022, doi: 10.51983/ajcst-2022.11.2.3379.

[17] M. Auwal and S. Lazarus, "Sociological and criminological research of victimization issues: Preliminary stage and new sphere of cybercrime categorization," J. Digit. Technol. Law, vol. 2, no. 4, pp. 915–942, 2024, doi: 10.21202/jdtl.2024.44.

Downloads

Published

05-05-2026

How to Cite

Muhammad Auwal, A., & Shehu, S. (2026). Measuring the Impact of Embedded Phishing Training on Ransomware-Lure Click Behavior: A Field Study Across Three Organizations. Asian Journal of Science and Applied Technology, 15(1), 47–54. https://doi.org/10.70112/ajsat-2026.15.1.4350

Issue

Section

Research Article

Similar Articles

1 2 3 4 5 6 7 8 9 10 > >> 

You may also start an advanced similarity search for this article.