Do phishing alerts impact global corporations? A firm value analysis

作者:

Highlights:

• We study the impact of release of phishing alerts on firm value.

• We use a novel asset pricing model for conducting an event study.

• Phishing alerts negatively impact firm value for global companies.

• Financial holding companies are strongly affected by release of such alerts.

摘要

Phishing is a form of online identity theft that is increasingly becoming a global menace. In this research, we analyze the impact of phishing alerts released in public databases on the market value of global firms. Using a sample of 1942 phishing alerts related to 259 firms in 32 countries, we show that the release of each phishing alert leads to a statistically significant loss of market capitalization that is at least US$ 411 million for a firm. We propose a theoretical framework for analyzing the impact of threats on firm value, and determine that the negative investor reaction is strongly significant for alerts released in 2006–2007 and for those targeted to financial holding companies, and weakly significant for firms listed in the US. We derive and validate these results using a combination of event study, subsampling analysis, and cross-sectional regression analysis. Our research makes a contribution by providing a new model for conducting multi-country event studies. We also contribute to the information systems literature by quantifying the loss in market value caused by phishing, and provide compelling evidence to information security administrators of firms that urge them to adopt adequate countermeasures to prevent phishing attacks.

论文关键词:Abnormal returns,Event study,Financial holding companies,Firm value,Phishing,Trading volume

论文评审过程:Received 1 May 2013, Revised 15 April 2014, Accepted 22 April 2014, Available online 6 May 2014.

论文官网地址:https://doi.org/10.1016/j.dss.2014.04.006