Cyberpsychology and power: how emotions are manipulated
Not a week goes by without talk of "manipulation": in the media, on social networks, through AI, in political campaigns or information crises.

Not a week goes by without talk of "manipulation": in the media, on social networks, through AI, in political campaigns or information crises.
We know it exists. But we keep imagining it concerns other people. The ones who are impressionable, distracted, "not critical enough".
What if we were wrong?
You don't manipulate intelligence, you manipulate emotions
When we think of a cyberattack, we think of a booby-trapped file, a ransomware, a virus. But most of the time, what brings an organisation down is not malicious code. It is a human reaction.
A click. A moment of panic. A moment of confusion. A loss of trust.
The figures confirm it. Nearly 68% of the data breaches analysed in the Verizon 2024 report involve a human factor, a proportion that stayed around 60% in the 2025 edition. In France, phishing remains the leading threat for every audience: Cybermalveillance.gouv.fr handled more than 420,000 assistance requests in 2024, up by almost 50%, and phishing alone accounts for 64,000 of them.
The lever is rarely technical. It is stress, urgency, the fear of getting it wrong, the need to move fast.
This is where cyberpsychology comes in: understanding how our cognitive biases, our emotional states and our perception of reality shape our decisions when facing digital systems.

Which emotional levers do cybercriminals exploit?
Power lies with whoever triggers the right emotion, at the right moment. A fake security alert, an email that plays on fear, a message that seems to come from your management: these are not mistakes. They are strategic tools.
Cybercriminals understand emotional levers very well:
- Urgency to cut off your analysis.
- Authority to make you obey without checking.
- Guilt to destabilise you.
- Curiosity to trigger a click.
And they move fast, faster than our critical thinking. According to Verizon, the median time to click a phishing link is 21 seconds after the message is opened, then only 28 seconds more to enter your data: less than a minute between the bait and the mistake. Emotion needs no more than that. And when this machinery targets a company, the bill climbs: business email compromise, BEC, cost 2.77 billion dollars to the victims recorded by the FBI in 2024 alone.
The most unsettling part is that these same levers are also used, sometimes unconsciously, inside organisations themselves:
- Constant pressure.
- A culture of reactivity.
- Hunting for mistakes rather than learning.
In other words: we weaken our own psychological defences.
Why does digital manipulation go unnoticed?
It is not one big lie. It is a gradual shift:
- A well-placed algorithmic suggestion.
- A trend artificially pushed to the top.
- A feeling that "everyone thinks like me".
And here again, it is not a matter of intelligence. It is a matter of mental load, fatigue, information overload. The brightest minds can get caught, simply because they are human.
Artificial intelligence only amplifies the phenomenon. It industrialises the personalisation of the message and the activation of our emotions at scale. CrowdStrike measured a 442% rise in voice phishing attacks, vishing, between the first and second half of 2024, driven by impersonation tactics boosted by AI. The voice of a "colleague", the tone of a "manager", the urgency of an "IT department": what used to be expensive to fabricate is now generated in a few seconds.
What can we do in practice against manipulation?
No, we are not all going to become experts in cognitive psychology. But we can put a bit of clarity back into our practices:
- Accept that we all have biases. All of us.
- Create environments where it is possible to say "I don't know" without fear.
- Develop simple verification reflexes, even internally.
- Teach cyberpsychology in an accessible way.
And above all: slow down. Take a breath between stimulus and response. Because that is often where everything is decided. Twenty-one seconds are enough to click; a few seconds of stepping back are sometimes enough not to.
Emotion is not the problem, the silence around it is
No cybersecurity policy will hold if it does not account for the human being. And the human being is their skills, yes. But also their fears, their reflexes, their need for recognition, their fatigue.
Until we have built this dimension in, we will be building sandcastles.
It is time to stop seeing "users" as the weak link. And to see them for what they really are: the heart of the system.
Learn more about my activities
Sources
- Human factor in data breaches, nearly 68% in 2024 and around 60% in 2025: Verizon, Data Breach Investigations Report 2024 and 2025.
- Median time to click a phishing link, 21 seconds, then 28 seconds to enter one's data: Verizon, Data Breach Investigations Report 2024.
- Phishing, the leading threat in France, more than 420,000 assistance requests in 2024: Cybermalveillance.gouv.fr, 2024 activity report.
- Business email compromise (BEC), 2.77 billion dollars in 2024: FBI, IC3 2024 report, CyberScoop summary.
- 442% rise in voice phishing (vishing) in the second half of 2024: CrowdStrike, Global Threat Report 2025.
Frequently asked questions
What is cyberpsychology?
It is the understanding of how our cognitive biases, our emotional states and our perception of reality shape our decisions when facing digital systems.
Which emotional levers do cybercriminals exploit?
Urgency to cut off analysis, authority to make people obey without checking, guilt to destabilise and curiosity to trigger a click.
Why do cyberattacks so often succeed through the human factor?
Because the technical side is only the way in. Nearly 68% of data breaches involve a human factor according to the Verizon 2024 report, and phishing remains the number one threat in France according to Cybermalveillance.gouv.fr.
Do you have to be uncritical to be manipulated?
No. It is not a matter of intelligence: even the brightest minds get caught, simply because they are human, tired or overwhelmed with information.
Does artificial intelligence make manipulation more effective?
Yes. Voice phishing attacks jumped 442% in the second half of 2024 according to CrowdStrike, with AI making it possible to personalise messages and trigger our emotions at scale.
What can we do in practice?
Accept that we all have biases, create environments where saying "I don't know" is possible, develop simple verification reflexes, teach cyberpsychology and, above all, slow down between the stimulus and the response.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
