Deceptive Patterns
‹ All reading

Uncovering the Dark Patterns of Phishing Emails: An Eye-Tracking Analysis

Author
Seeung Oh, Yebin Bae, Isaiah Abraham Thompson, Young-Whan Im
Date
1 Jan 2025
Publisher
IEEE Access
Focus
HCI & Psychology
Category
Academic Scholar

Participants viewed prototype Netflix and Adobe messages containing six deceptive cues; gaze measures showed brand imitation and urgent language drew significantly less fixation duration, fixation count and revisiting than the other cues, marking them as perceptual blind spots.

Phishing emails are a representative form of dark patterns that visually deceive users and exploit psychological vulnerabilities. This study employed eye-tracking to empirically examine which features in phishing emails are most frequently overlooked. Two commonly encountered phishing categories—emails requiring immediate user action and those prompting account registration—were tested using prototypes modeled after Netflix and Adobe. Each email contained six widely recognized deceptive cues: fake sender address, generic greeting, urgent language, fake hyperlink, brand imitation, and false source assumption. Among these, brand imitation and urgent language received the least visual attention. These cues showed significantly lower fixation duration, fixation count, and revisit count. Paired t-tests revealed that these two cues were statistically less attended than the others (p <.001). Survey responses and heatmaps further confirmed the low detection rates for brand imitation and urgency cues. The findings suggest that visual trust cues (e.g., brand logos) and urgency-based persuasion techniques are particularly effective at bypassing user scrutiny. These results underscore critical perceptual blind spots and highlight the need for improved training and detection systems that incorporate human-computer interaction (HCI) perspectives, addressing subtle visual and psychological manipulation strategies beyond conventional technical indicators.