Analisis Kesadaran dan Perilaku Mahasiswa IT Dalam Menghindari Ancaman Phishing Menggunakan Model TTAT
DOI:
https://doi.org/10.30865/json.v8i1.9851Keywords:
Phishing, TTAT, Kesadaran Keamanan Siber, Avoidance Motivation, Avoidance BehaviorAbstract
Phishing merupakan ancaman siber berbasis rekayasa sosial yang terus menyasar mahasiswa sebagai pengguna aktif layanan digital kampus, seperti email akademik, Learning Management System, dan sistem administrasi daring. Penelitian ini bertujuan menganalisis kesadaran dan perilaku menghindari ancaman phishing mahasiswa IT di Kota Depok menggunakan Technology Threat Avoidance Theory (TTAT). Penelitian menggunakan pendekatan kuantitatif dengan desain survei cross-sectional. Instrumen penelitian berupa kuesioner skala Likert 1-4 yang disusun berdasarkan tujuh konstruk TTAT, yaitu perceived severity, perceived susceptibility, safeguard effectiveness, safeguard cost, self-efficacy, avoidance motivation, dan avoidance behavior. Data valid yang dianalisis berjumlah 307 responden dan diolah menggunakan SPSS melalui uji validitas, reliabilitas, asumsi klasik, serta regresi dua tahap. Hasil penelitian memberikan dukungan parsial terhadap model TTAT. Pengujian hipotesis dilakukan melalui dua tahap regresi, yaitu regresi tahap pertama untuk menguji faktor-faktor pembentuk avoidance motivation dan regresi tahap kedua untuk menguji pengaruh avoidance motivation terhadap avoidance behavior. Pada regresi tahap pertama, self-efficacy dan safeguard effectiveness berpengaruh signifikan terhadap avoidance motivation, sedangkan perceived severity, perceived susceptibility, dan safeguard cost tidak berpengaruh signifikan. Pada regresi tahap kedua, avoidance motivation terbukti berpengaruh signifikan terhadap avoidance behavior. Model regresi menunjukkan nilai R Square sebesar 0,734 pada tahap pertama dan 0,540 pada tahap kedua. Temuan ini menunjukkan bahwa upaya peningkatan perilaku menghindari phishing pada mahasiswa IT sebaiknya tidak hanya berfokus pada penyampaian bahaya phishing, tetapi juga diarahkan pada penguatan self-efficacy dan pemahaman terhadap efektivitas tindakan pengamanan digital.
References
[1] National Institute of Standards and Technology, “Phishing – Glossary,” CSRC Glossary – NIST. Accessed: Jan. 05, 2026. [Online]. Available: https://csrc.nist.gov/glossary/term/phishing
[2] L. Ribeiro, I. S. Guedes, and C. S. Cardoso, “Which Factors Predict Susceptibility to Phishing? An Empirical Study,” Computers & Security, vol. 136, 2024, doi: 10.1016/j.cose.2023.103558.
[3] M. Mutlutürk, M. Wynn, and B. Metin, “Phishing and the Human Factor: Insights from a Bibliometric Analysis,” Information, vol. 15, no. 10, 2024, doi: 10.3390/info15100643.
[4] P. C. Verhoef et al., “Digital Transformation: A Multidisciplinary Reflection and Research Agenda,” Journal of Business Research, vol. 122, pp. 889–901, 2021, doi: 10.1016/j.jbusres.2019.09.022.
[5] SOCRadar Cyber Intelligence Inc., “Indonesia Threat Landscape Report 2024.” Accessed: Nov. 20, 2025. [Online]. Available: https://socradar.io/resources/report/indonesia-threat-landscape-report-2024/
[6] Indonesia Anti-Phishing Data Exchange, “Statistik Laporan Phishing Periode 2022–2025,” Indonesia Anti-Phishing Data Exchange. Accessed: Jan. 08, 2026. [Online]. Available: https://idadx.id/
[7] Badan Siber dan Sandi Negara, “Lanskap Keamanan Siber Indonesia 2023,” 2023. Accessed: Jan. 05, 2026. [Online]. Available: https://educsirt.kemendikdasmen.go.id/portal/berita/197
[8] European Union Agency for Cybersecurity (ENISA), “Enisa Threat Landscape 2023.” Accessed: Nov. 20, 2025. [Online]. Available: https://www.enisa.europa.eu/sites/default/files/publications/ENISA Threat Landscape 2023.pdf
[9] A. Pearson, R. Rath, G. Simches, B. Timberlake, R. Magaw, and J. Wilbur, “Phishing Campaigns Targeting Higher Education Institutions,” Google Cloud. Accessed: Jan. 10, 2026. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/phishing-targeting-higher-education/
[10] M. M. Quchi, M. Hakimi, and A. W. Fazil, “Human Factors in Cybersecurity: An in Depth Analysis of User Centric Studies,” Jurnal Ilmiah Multidisiplin Indonesia (JIM-ID), vol. 3, no. 01, pp. 20–33, 2024, doi: 10.58471/esaprom.v3i01.
[11] D. Jampen, G. Gür, T. Sutter, and B. Tellenbach, “Don’t Click: Towards an Effective Anti-Phishing Training. A Comparative Literature Review,” Human-centric Computing and Information Sciences, vol. 10, no. 1, 2020, doi: 10.1186/s13673-020-00237-7.
[12] S. Das, C. Nippert-Eng, and L. J. Camp, “Evaluating User Susceptibility to Phishing Attacks,” Information and Computer Security, vol. 30, no. 1, pp. 1–18, 2022, doi: 10.1108/ICS-12-2020-0204.
[13] N. Vadila and A. R. Pratama, “Analisis Kesadaran Keamanan Terhadap Ancaman Phishing,” Automata, vol. 2, no. 2, pp. 1–4, 2023.
[14] I. Daila Sari, D. Hariyadi, R. Sahtyawan, and N. I. Kusumaningtyas, “Analisis Tingkat Security Awareness-Personal Threat Terhadap Ancaman Phishing Dengan Metode Technology Threat Avoidance Theory (TTAT),” Teknomatika: Jurnal Informatika dan Komputer, vol. 16, no. 2, pp. 49–55, 2023, doi: 10.30989/teknomatika.v16i2.1250.
[15] A. K. Gwenhure, “University Students’ Security Behavior Against Email Phishing Attacks: Insights from the Health Belief Model,” Journal of Cybersecurity, vol. 11, no. 1, 2025, doi: 10.1093/cybsec/tyaf034.
[16] A. Rifai, A. Meliyani, P. Chyntia, and I. A. Sakti, “Penerapan Metode Technology Threat Avoidance Theory Terhadap Tingkat Kesadaran Data Privasi Pengguna Media Sosial,” Journal of Information System Research (JOSH), vol. 4, no. 3, pp. 1026–1032, 2023, doi: 10.47065/josh.v4i3.3081.
[17] R. J. Nur’aini and M. Simanjuntak, “Phishing Awareness and Security Concerns: Analyzing the Role of Anti-Phishing Knowledge and Internet Experience in Online Banking Users,” Jurnal Ilmu Keluarga dan Konsumen, vol. 18, no. 2, pp. 121–133, 2025, doi: 10.24156/jikk.2025.18.2.121.
[18] H. Liang and Y. Xue, “Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective,” Journal of the Association for Information Systems, vol. 11, no. 7, pp. 394–413, 2010, doi: 10.17705/1jais.00232.
[19] N. A. G. Arachchilage, S. Love, and K. Beznosov, “Phishing Threat Avoidance Behaviour: An Empirical Investigation,” Computers in Human Behavior, vol. 60, pp. 185–197, 2016, doi: 10.1016/j.chb.2016.02.065.
[20] Kemdiktisaintek, “Pangkalan Data Pendidikan Tinggi (PDDIKTI).” Accessed: Nov. 17, 2025. [Online]. Available: https://pddikti.kemdiktisaintek.go.id/
[21] Sugiyono, Metode Penelitian Kuantitatif, Kualitatif, dan R&D, 3rd ed. Bandung: Alfabeta, 2021.
[22] I. Ghozali, Aplikasi Analisis Multivariate dengan Program IBM SPSS 26, 10th ed. Semarang: Badan Penerbit Universitas Diponegoro, 2021.
[23] J. F. Hair Jr., W. C. Black, B. J. Babin, and R. E. Anderson, Multivariate Data Analysis, 8th ed. Hampshire: Cengage Learning, 2019.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Jurnal Sistem Komputer dan Informatika (JSON)

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

This work is licensed under a Creative Commons Attribution 4.0 International License
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under Creative Commons Attribution 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (Refer to The Effect of Open Access).

