Phishing exploits context, not stupidity
People fall for phishing because the message arrived at a plausible moment, not because they are careless.
An invoice during invoicing season, a delivery notice when you are expecting a parcel, a password reset just after you requested one. The attacker did not need to be clever; they needed to be unremarkable. Framing it as stupidity guarantees people conceal it when it happens.
More on Human factors
- A warning ignored every day stops being a warningThe bell nobody hears
- Security friction moves behaviour elsewhereSqueeze it here, it comes out there
- MFA fatigue weaponises repetitionAsk forty times
- Verify suspicious requests through a separate channelRing back on a line they never gave you
- People need a safe way to report mistakes quicklyThe shortest road back
- Security training decays without practiceWhat you knew in March
