Skip to main content

A systematic literature review of profiling victims of cyber scams: setting up a framework for future research

Monica Therese Whitty (2025) — Cogent Social Sciences

What do these research terms mean?
Preprint
A manuscript shared before formal peer review and publication. Check whether a later published version is available.
Dataset
A collection of data or examples for others to inspect or reuse. It can appear in Library search and topic mapping, but RSRC does not use dataset records as evidence in Research Insights.
Dissertation or thesis
Research submitted for an academic degree. This describes its format, not its reliability.
Journal article
An article published in a journal. This label alone does not establish peer review, study quality, or how well the findings apply elsewhere.
Qualitative research
Examines experiences, meanings, or processes, often through interviews or observations. It can explain how something happens without estimating how common it is.
Quantitative research
Uses numerical measurements to describe patterns or test relationships. A relationship between two measurements does not by itself show that one causes the other.
Systematic review
Uses a planned, documented method to find and assess research addressing a question. Its conclusions still depend on the included studies and what the search covered.
Meta-analysis
Statistically combines results from multiple studies. Combining studies does not remove weaknesses in their design or make unlike populations interchangeable.
Not classified
This record has no recognized label in this filter. It does not mean the publication used no method, or that no research exists.

Definitions draw on DataCite resource types; Cochrane review methods; NLM: association and causation. RSRC’s dataset and classification rules are explained in our methodology.

Citation tools


              
              

Transparency

Evidence and review status

This page contains AI-generated content. No human content review or subject-matter-expert review is recorded.

Source basis
Downloaded PDF
Source updates
No notice found at last check
AI-generated page content
Yes
Automated checks
Passed
Administrative approval
Yes
Human content review
Not recorded
Subject-matter-expert review
Not recorded
How this was prepared
Source basis

RSRC downloaded and privately stored a copy of the paper for internal analysis. The PDF is not offered to viewers from this page.

  • PDF added to RSRC:
Source updates

No incoming update notice was found in the dated Crossref response. Coverage is incomplete, particularly for corrections and expressions of concern; this is not a guarantee that the source is valid or unchanged.

  • Last source-status attempt:
AI-generated page content

AI-generated research notes displayed on this page: Synopsis, Identified gaps, Methods, Limitations, Future work. The paper itself is not described as AI-generated.

  • Document analysis recorded:
  • Page record updated:
Automated checks

The current, source-bound synopsis passed the recorded versioned publication checks.

  • Checks completed:
View passed checks (3)
  • Length, completeness, repetition, refusal, boilerplate, and active-markup screening
  • Numerical claims checked against the available source text
  • English-source lexical grounding check
Administrative approval

The record is approved for public display, but a complete historical administrator action is not recorded.

Human content review

No human review is recorded for the AI-generated content displayed on this page.

Subject-matter-expert review

RSRC has not recorded review of this content by a subject-matter or methods expert.

Review-state definitions
Found a possible error? Request a correction.

Synopsis

This article presents a systematic literature review (SLR) of research profiling victims of cyber scams, aiming to establish a framework for future studies. The review was motivated by the rapid global growth of cyber scams, which cause profound financial and psychological harm while being difficult to prosecute due to their transnational nature. The study argues that profiling victims is more feasible and impactful than profiling offenders, given the challenges in apprehending cybercriminals. The review followed PRISMA 2020 guidelines, analyzing 22 empirical, quantitative studies published between 2000 and 2025. Eligible research focused on adult scam victims and examined psychological characteristics or behaviors linked to victimization. Most studies used surveys; a few employed questionnaires or longitudinal designs. Scam types included general cyber fraud, romance scams, investment scams, phishing, and consumer fraud. Two theories dominated the literature: Routine Activities Theory (RAT) and Personality Theory. RAT studies emphasized how exposure, guardianship, and online routines influence risk, while personality-focused research linked traits such as impulsivity, addictive personality, internal locus of control, optimism, and low openness to victimization. Other factors included loneliness, materialism, low inquisitiveness, low kindness, low trustworthiness, and low truth-seeking. Some findings were inconsistent—awareness, for example, was protective in one study but a risk factor in another—highlighting the complexity of measuring vulnerability. The review also identified behavioral clusters relevant to victimization: financial transactions (shopping, investing, donating), communication/social interaction (dating, social media use), information seeking, general internet use, risky behaviors (opening unknown attachments, sharing passwords), and safe behaviors (strong passwords, antivirus use). However, methodologies for measuring behaviors varied widely, limiting comparability. Whitty proposes a heuristic model of predictors (Figure 5, p. 19) that organizes risk factors into six domains: personality, individual characteristics, behaviors, cognition, self-esteem, and attitudes/beliefs. This model highlights how dispositional traits may interact with online routines and cognitive appraisals to shape victimization outcomes. The review suggests that neglected theories such as Information Processing Theory, Theory of Planned Behavior, Protection Motivation Theory, and Social Identity Theory could strengthen future research. The article concludes that research on profiling scam victims remains fragmented and heterogeneous, with inconsistent definitions and measures across studies. To advance the field, Whitty calls for standardized outcome measures, theory-driven designs, and longitudinal studies to clarify causal relationships. By focusing on resilience-building and identifying risk factors without stigmatization, this line of research can inform more effective prevention campaigns, education programs, and therapeutic interventions.

Identified Gaps

Research is early-stage, methodologically heterogeneous, and dominated by general cyber-scam studies rather than scam-specific analyses. Cognitive abilities, self-esteem, and attitudes/beliefs are rarely tested. Studies use inconsistent definitions, timeframes, outcome measures, predictors, statistical tests, and reporting, preventing meta-analysis. Limited theory-driven work makes it unclear whether candidate traits are predispositional risks or consequences of victimisation.

Methods

Systematic literature review following PRISMA 2020. Searches of Scopus, Web of Science, EBSCOhost, OVID, PsychINFO, and IEEE identified peer-reviewed English quantitative studies (2000–2025) of real adult cyber-scam victims compared with non-victims/other victims and assessed on psychological measures. After screening 1,611 deduplicated records and full texts, 22 studies were included. Two blinded reviewers conducted adapted CASP quality assessment; Rayyan AI-assisted dual screening showed κ=0.87. Narrative and thematic synthesis were used because heterogeneity precluded meta-analysis.

Limitations

Relevant grey literature may have been missed because the review deliberately restricted inclusion to peer-reviewed sources. The field is recent and has a dispersed authorship base. Included samples ranged from 280 to 11,534, complicating generalisable inference. Studies often provided limited recruitment and measurement detail. Inconsistent construct definitions, statistical models, outcome metrics, and missing variance/effect-size information prevented weighted meta-analysis, sensitivity analyses, and quantitative assessment of small-study or publication bias.

Future Work

Compare predictors across scam types and populations using consistent, theory-driven measures; develop standardised questionnaires for behavioural clusters; establish consensus fraud-victimisation definitions and measurement protocols; test cognitive, planned-behaviour, protection-motivation and social-identity theories; and use adequately powered longitudinal moderated/mediated models with transparent effect-size reporting.

See how this publication connects to RSRC's living evidence syntheses through current citations and research-topic mapping.