Abstract
While attempts by malicious actors to compromise computer systems continue to increase, there have been limited success in educating corporate learners. Most corporations must rely upon firewalls, email filtering, and other tools to prevent compromises since their employees vary in prevention reliability. Recent studies have shown limited success of anti-phishing awareness corporate learning campaigns; however, these studies have mostly utilized students or individuals aware of their participation in an experiment. The current research utilized healthcare workers. Over the course of 18 months and three experiments, we evaluated if different anti-phishing awareness learning campaigns, simulated phishing email content, or the employee’s work location (remote vs. on-site) factored into their susceptibility to phishing. We found that those participants who received anti-phishing awareness interacted with the simulated phishing email less than those who didn’t receive training. Overall, an average of four percent of the workers in each experiment submitted their credentials on the fraudulent website. Our results suggest any type of anti-phishing training may provide optimal results, at least regarding anti-phishing training.
Document Type
Article
Source Publication
International Journal of Advanced Corporate Learning
Version
Published Version
Publication Date
2025
Volume
18
Issue
1
First Page
4
Last Page
15
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License.
Rights
The Author(s)
Recommended Citation
Challacombe, D.J., & McElhiney, E.N. (2025). Phishing Susceptibility Among Healthcare Workers: The Impact of Awareness, Email Type, and Location. International Journal of Advanced Corporate Learning (iJAC), 18(1). doi: 10.3991/ijac.v18i1.51671
Comments
For questions contact ScholarsRepository@fhsu.edu