Abstract
This article integrates the insights of default-interventionist and parallel-competitive dual-process theories of judgment, decision-making, and social cognition to develop a novel account of how cyber criminals attempt to launch successful phishing attacks. Specifically, the framework differentiates four sets of mechanisms—cold automatic (Type 1a), hot automatic (Type 1b), cold controlled (Type 2a), and hot controlled (Type 2b) cognitive processes—which cyber criminals adopt, variously, both in isolation and in a dynamic interplay, in their efforts to induce ICT end users to succumb to their requests. The article challenges the notion that susceptibility to phishing attacks arises predominantly from lapses in systematic thinking, emphasizing instead the complex interaction between emotion and cognition afforded by each of these distinctive mechanisms and considers the attendant implications for enhancing organizational defences against such attacks. It concludes with an agenda for advancing the science and practice of cyber security in this rapidly evolving domain.