Legal and ethical considerations when conducting phishing experiments in Germany
摘要
The damage caused to private individuals, organizations, and companies by phishing increases yearly. When writing phishing emails, phishers use various psychological tricks to lure the victims into releasing sensitive information or downloading and installing malware. To counteract this, cybersecurity and human-computer interaction research tries to simulate phishing emails and attacks to design various countermeasures. However, substantial research results can only be achieved in real-life studies – meaning that researchers become phishers themselves. Therefore, this article examines the legal and ethical problems phishing researchers face when conducting these real-life phishing studies. Based on the results, we propose a possible research design that is on a justifiable legal and ethical basis. Nonetheless, some issues persist, at least in Germany. Therefore, we call for introducing an exception for scientific research.