Basecamp SecurityFundamentals

Phishing: Why Smart People Click

Phishing doesn't exploit stupidity — it exploits urgency, authority, and busy Tuesday afternoons. Understanding the mechanics beats mocking the victims.

The most dangerous myth in security is that phishing only catches careless or unintelligent people. Believe that and you'll conclude you're safe because you're smart — which is precisely the confidence phishing feeds on. Doctors, engineers, security professionals: all have clicked. Understanding why is worth more than a hundred "don't click suspicious links" posters.

The mechanics: renting your reflexes

A phishing message is engineered to make you act before you evaluate. The classic ingredients:

Notice that none of these exploit a lack of intelligence. They exploit attention — and attention is a resource everyone runs out of by mid-afternoon. Phishing succeeds not when it beats your reasoning, but when it routes around it entirely.

The vocabulary you'll actually hear

Spear phishing is the targeted version — researched, personal, referencing your real colleagues or projects, dramatically more effective than the mass-mail kind. Whaling targets executives. Smishing and vishing are the SMS and voice-call variants — the fake "bank fraud team" phone call is vishing, and it's devastating precisely because a live human voice applies urgency better than any email. Business email compromise (BEC) is the big-money endgame: attackers inside or impersonating a real business email thread, redirecting genuine invoice payments. It's among the most financially damaging crimes on the internet, and it often contains no malware at all — just a convincing sentence.

Trail note

The single most protective habit isn't inspecting URLs (though it helps): it's switching channels to verify. An email asks you to change payment details? Phone the known number. "IT" calls asking for your password? Hang up and ring the real helpdesk. Attackers control the channel they contacted you on — they rarely control a second one.

What actually helps at scale

Organisationally, the honest lesson is that awareness training alone doesn't get click rates to zero — humans are humans at 4pm on a Tuesday. What works is layering: MFA (a phished password alone stops being enough), email filtering, clearly marked external mail, payment processes that require out-of-band verification, and — crucially — a culture where reporting "I think I clicked something" is praised, not punished. The fastest-contained incidents are the ones someone reported in minutes. Shame delays reports; delay is what attackers need.

Next waypoint — Basecamp

Passwords Are Broken. Here's What MFA Actually Fixes →