Phishing emails are a representative form of dark patterns that visually deceive users and exploit psychological vulnerabilities. This study employed eye-tracking to empirically examine which features in phishing emails are most frequently overlooked. Two commonly encountered phishing categories—emails requiring immediate user action and those prompting account registration—were tested using prototypes modeled after Netflix and Adobe. Each email contained six widely recognized deceptive cues: fake sender address, generic greeting, urgent language, fake hyperlink, brand imitation, and false source assumption. Among these, brand imitation and urgent language received the least visual attention. These cues showed significantly lower fixation duration, fixation count, and revisit count. Paired t-tests revealed that these two cues were statistically less attended than the others (p <.001). Survey responses and heatmaps further confirmed the low detection rates for brand imitation and urgency cues. The findings suggest that visual trust cues (e.g., brand logos) and urgency-based persuasion techniques are particularly effective at bypassing user scrutiny. These results underscore critical perceptual blind spots and highlight the need for improved training and detection systems that incorporate human-computer interaction (HCI) perspectives, addressing subtle visual and psychological manipulation strategies beyond conventional technical indicators.
‹ All reading
Uncovering the Dark Patterns of Phishing Emails: An Eye-Tracking Analysis
Participants viewed prototype Netflix and Adobe messages containing six deceptive cues; gaze measures showed brand imitation and urgent language drew significantly less fixation duration, fixation count and revisiting than the other cues, marking them as perceptual blind spots.