|
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
|
| Volume 187 - Issue 123 |
| Published: July 2026 |
| Authors: Ankur Sharma |
10.5120/ijcaa3ca26c7d22f
|
Ankur Sharma . The Role of Human Behavior in Phishing Attacks: A Behavioral Cybersecurity Approach. International Journal of Computer Applications. 187, 123 (July 2026), 63-73. DOI=10.5120/ijcaa3ca26c7d22f
@article{ 10.5120/ijcaa3ca26c7d22f,
author = { Ankur Sharma },
title = { The Role of Human Behavior in Phishing Attacks: A Behavioral Cybersecurity Approach },
journal = { International Journal of Computer Applications },
year = { 2026 },
volume = { 187 },
number = { 123 },
pages = { 63-73 },
doi = { 10.5120/ijcaa3ca26c7d22f },
publisher = { Foundation of Computer Science (FCS), NY, USA }
}
%0 Journal Article
%D 2026
%A Ankur Sharma
%T The Role of Human Behavior in Phishing Attacks: A Behavioral Cybersecurity Approach%T
%J International Journal of Computer Applications
%V 187
%N 123
%P 63-73
%R 10.5120/ijcaa3ca26c7d22f
%I Foundation of Computer Science (FCS), NY, USA
Even with powerful tools to detect and prevent phishing attacks, the threat remains one of the most prevalent cybersecurity issues. Although cybersecurity tools increasingly integrate artificial intelligence (AI) and machine learning (ML), one area remains persistently exploited by cybercriminals: human behavior, targeted through social engineering. This study analyzes the role of human behavior in phishing attacks from a behavioral cybersecurity perspective, combining a conceptual, literature-based synthesis with an empirical evaluation of five machine learning classifiers on two public phishing datasets comprising 69,700 labeled instances in total. The key behavioral dimensions analyzed are trust, perceived urgency, fear, curiosity, digital literacy, cybersecurity awareness, and decision-making biases. In the empirical evaluation, the Random Forest classifier achieved 97.11% and 95.58% accuracy on the two datasets, confirming the maturity of technical detection. A complementary scenario analysis restricted to deception cues that are, in principle, visible to end users retained approximately 91% accuracy on both datasets, indicating that the information required to recognize most phishing attacks is present in what users can observe, and that victimization arises primarily from cognitive and emotional manipulation rather than from an absence of information. The results indicate that technological solutions alone are insufficient in the absence of human-centered cybersecurity strategies and regular behavioral interventions. By integrating recent findings with quantitative evidence, the study advances the field of behavioral cybersecurity and presents a case for adaptive behavioral approaches to minimize phishing risks.