Computer Science ETDs

Publication Date

Summer 7-28-2026

Abstract

Survey platforms such as Google Forms and Microsoft Forms are widely used for feedback, data collection, and engagement, but scammers increasingly exploit them to distribute phishing and deceptive attacks. This thesis presents a large-scale study of survey-form abuse across ten major providers. We collected 140,000 forms from three sources: public posts on X, search-engine results, and web pages from the top 10 million DomCop-ranked domains. Using automated filtering and manual qualitative review, we identified 2,645 forms requesting sensitive information and classified 566 as scams. These forms used techniques including phishing, private-secret theft, account and personal-data harvesting, financial deception, and psychological coercion. We then automatically engaged with 392 scamming forms to examine scammer behavior and found that most forms function primarily as harvesting tools with limited follow-up communication. Finally, network analysis revealed more than 3,200 accounts involved in scam distribution. We disclose findings and provide mitigation recommendations for future security research.

Language

English

Keywords

Online Scam, Security and Privacy, Survey Forms

Document Type

Thesis

Degree Name

Computer Science

Level of Degree

Masters

Department Name

Department of Computer Science

First Committee Member (Chair)

Afsah Anwar

Second Committee Member

Mueen Abdullah

Third Committee Member

Sazzadur Rahaman

Included in

Cybersecurity Commons

Share

COinS