Phishing is usually explained as a failure of user attention, which is why twenty years of telling people to be careful has not fixed it. A better explanation is that a convincing message arrives at a moment when it fits, and fitting is cheap to arrange.
The standard explanation, and why it has not worked
The usual account is that users are careless and need training. Two decades of training later, phishing remains among the most effective ways into an organisation.
At some point the explanation has to be held responsible for the result. A defence that requires every person to be alert every time, including at half past four on a Friday with forty unread messages, is not a defence. It is a hope with a budget.
What actually makes a message land
Expectation, mostly.
A delivery notice lands when you are waiting for a parcel. An invoice lands at month end, at a company that receives invoices. A password reset lands seconds after you asked for one. The message does not have to be clever. It has to be unremarkable, and unremarkable is a property of timing rather than of craft.
Those windows are cheap to arrange. Send enough messages and some arrive during somebody's window by arithmetic alone. Or buy a breach and learn what a person recently bought, which airline they use, who their employer is. Or simply know what month it is — the payroll window, the renewal window, the tax window — because everybody is in one of those at predictable times.
Why the good signals stopped being reliable
Most public advice concerns signals that no longer function.
Spelling and grammar once filtered the clumsy. They now filter nobody: the text is as carefully written as any other marketing email, sometimes more so.
The padlock and the certificate mean the connection is encrypted, which a fraudulent site also wants. They were never a statement about honesty and are now routinely present on both sides.
Sender addresses are close enough to plausible for anyone reading at speed on a phone, where the display name is often all that is shown.
And personal detail proves nothing. Knowing your name, your employer, your last four digits and your street is not evidence of legitimacy — it is evidence of access to a breach, which is inexpensive.
The pressure move
Urgency, authority, and an interruption to something you were already doing.
The mechanism is economic rather than psychological. Verification costs time: leave the message, open a browser, find the real number, wait on hold. The message is constructed so that spending that time feels expensive — the account will be suspended, the payment will fail, the colleague is waiting.
It is not a trick on the gullible. It is a trick on the busy, and everybody is busy.
What defends, in order
Strongest first, which is not the order these usually get listed in.
Authentication that cannot be handed over even by somebody who has been completely fooled. This is first by a distance, because it is the only control that survives the user believing the attacker.
Verification through a channel the message did not arrive on. Not the number in the email. The number on the card, or the app you already have.
Systems where the safe path is also the fast path. If checking properly takes four minutes and complying takes ten seconds, the design has chosen the outcome.
Awareness training last. It helps at the margin. It should not be carrying the weight, and when it is, the weight is on the person least able to bear it.
For an organisation
A simulation that punishes clicking teaches people to conceal mistakes, and concealment is the expensive part — the damage is done in the hours between the click and the report.
Measure time-to-report rather than click rate. They point in opposite directions more often than is comfortable.
Close
One question settles whether a control is real: does it still work when the person is tired, busy, and genuinely expecting this message?
If the answer is no, it was not protecting them. It was documenting whose fault it would be.
