PhishGuru logo

  PhishGuru




ABOUT

PhishGuru is an email-based anti-phishing training system in which training messages are designed to look like phishing messages. When users "fall" for our messages, we take advantage of the "teachable moment" and immediately teach them how to avoid falling for real scams. Our studies demonstrate that PhishGuru effectively teaches people what cues to look for to distinguish scams from legitimate email.

EDUCATIONAL MATERIALS


Phisher



NEWS AND EVENTS

September 2008: Phishguru is being commercialized by Wombat Security Technologies. This web site will be transitioning soon.


PUBLICATIONS

P. Kumaraguru, Y. Rhee, S. Sheng, S. Hasan, A. Acquisti, L. Cranor and J. Hong. Getting Users to Pay Attention to Anti-Phishing Education: Evaluation of Retention and Transfer. Proceedings of the 2nd Annual eCrime Researchers Summit, October 4-5, 2007, Pittsburgh, PA, p. 70-81.
Sheng, S., Magnien, B., Kumaraguru, P., Acquisti, A., Cranor, L. F., Hong, J., and Nunge, E. Anti-phishing phil: The Design and Evaluation of a Game that Teaches People Not to Fall for Phish. In SOUPS '07: Proceedings of the 3rd symposium on Usable privacy and security, New York, NY, USA, March 2007, ACM, pp. 88 - 99.
P. Kumaraguru, S. Sheng, A. Acquisti, L. Cranor, F. L., and J. Hong. Teaching Johnny Not to Fall for Phish. Tech. rep., Cranegie Mellon University, February, 2007.
P. Kumaraguru, Y. Rhee, A. Acquisti, L. Cranor, J. Hong, and E. Nunge. Protecting People from Phishing: The Design and Evaluation of an Embedded Training Email System. CHI 2007: Conference on Human Factors in Computing Systems, San Jose, California, 28 April - May 3, 2007, 905-914. [Originally published as CyLab Technical Report CMU-CyLab-06-017, 2006]

More CMU anti-phishing research papers



CREDITS

The PhishGuru is developed by members of the CMU Usable Privacy and Security Laboratory with funding from the US National Science Foundation (Cyber Trust initiative) and ARO/CyLab. The PhishGuru team is led by Ponnurangam Kumaraguru (PK) and include Alessandro Acquisti, Lorrie Cranor, Jason Hong,Yong Woo Rhee, Steve Sheng, Zhen Zeng and Elizabeth Nunge. Thanks to all members of the Supporting Trust Decisions project for their feedback on early versions of the PhishGuru.



GAME

Anti-Phishing Phil game Anti-Phishing Phil is an interactive game that teaches users how to identify phishing URLs, where to look for cues in web browsers, and how to use search engines to find legitimate sites.

Play now!




CONTACT US

For more information about PhishGuru or our other anti-phishing work, please contact CUPS Director, Lorrie Cranor.