Why careful people still click phishing links

Sarah runs the office at an engineering firm in Tauranga. An email arrives from the firm's accountant, from his usual address, asking her to look over the attached draft accounts before their call on Thursday. There is a call on Thursday. She opens the attachment, a sign-in box appears asking her to confirm her Microsoft account to view the file, she types her password, and the document never loads. She makes a note to ask him to resend it and gets on with the invoicing.

The accountant's mailbox had been taken over the week before. The email came from his real account, it referred to a real meeting, and it asked Sarah to do the thing she does every week. Her password was collected the moment she typed it, and the person who built the sign-in box used it that evening to read everything in her inbox.

Sarah did not click because she was careless. She clicked because she was doing her job, and the email was written to look like her job.

Anyone can be the one who clicks

Our consultants have run cyber security awareness training for years, and what they see is that the person who clicks is not a type. Anyone in a company, in any position, can be the weakest link on a given day, and they tell every room that it is human nature to make a mistake. Being caught does not mean you are a bad person or that you were not concentrating. It means the email was built for the moment it arrived in.

Think about reversing out of your driveway. After doing it hundreds of times, checking behind you becomes part of the routine rather than a separate decision. Work email is much the same. A scam only has to resemble the invoices, files and sign-in prompts you deal with every week.

Our consultants build the same kind of check into the way they handle email, looking at the actual sender address on every message. At first that takes conscious effort. Before long it is simply part of opening an email.

 

Why reading about scams does not fix it

Knowing what a phishing scam looks like is useful, but it does not help if the email in front of you looks completely ordinary. One of the biggest light-bulb moments we see in training is much smaller than people expect.

Our consultants show the room an email where the sender's name reads as someone they know, then open the details to show the address underneath. Many people have never realised those are two separate things, and that the display name can be whatever the sender chose to type. Once you have seen it, you check it, and that check is what the training is building.

This year's Cyber Smart Week, which runs from 5 to 11 October, has the theme "Find a scam before it finds you", and the National Cyber Security Centre describes people as the strongest line of defence a business has. Our rule is simple: were you expecting this, and is the request normal?

Those are the questions to ask when something wants you to sign in, when payment details suddenly change, or when a request arrives outside the usual pattern. If something feels off, verify it another way. Ring the person on a number you already have, send them a separate message, or walk over and ask.

 

What to do this Cyber Smart Week

  • Show your team how to check the actual sender address, not just the name that appears in their inbox.

  • Agree the three moments that always get a pause: a sign-in prompt, a changed bank account, and a request out of the ordinary.

  • Put a second approver on payments, so a convincing message to one person is never enough on its own.

  • Keep personal sign-ups off work email, so anything that is not work stands out immediately.

  • Make "I think I clicked" an easy thing to say, and thank the person who says it.

 

How Think Concepts can help

Passkeys protect your sign-ins and a password manager protects your logins, and we covered both earlier in our Cyber Smart Week series. Training protects judgement, which is the part no software can cover.

Think Concepts runs live cyber security awareness training for whole teams, led by one of our consultants, with regular updates as threats change. Phishing simulations through Phriendly Phishing can sit alongside the sessions, giving staff a chance to practise spotting realistic emails during an ordinary working day.

If your team has not done awareness training before, that is a practical place to start.

Get in touch with the Think Concepts team.

The questions we get asked

Should I just tell everyone not to click links?

No. Your business runs on people opening attachments, approving payments and signing in to things. The aim is for the pause to happen at the right moment and take ten seconds, and for the big decisions to need two people. We recommend a second approver on any payment request, so no single person can be talked into a transfer by an email, a phone call or a video call that looks like the boss.

Does our spam filter handle this?

Filtering stops a great deal, and it is very good at mail from strangers. It is much weaker against an email from a real account that has been taken over, because as far as the filter can see, your accountant sent you a file. Those are the ones that reach the inbox, and those are the ones that need a person to notice. No system stops everything, which is why the training sits alongside the software rather than instead of it.

What does training actually change?

A recent session shows it. One of our consultants was walking a client's team through the difference between spam, junk and phishing, and a new starter put her hand up to say she had received an email that morning, was not sure what to do with it, and thought she might have clicked. They alerted the Think Concepts team from inside the session, they began investigating, and the attack was stopped before it caused the damage it could have. The important part was that she spoke up, and the earlier the better. If you think you have clicked, tell your IT team straight away rather than later in the day.

What should Sarah have done?

Rung the accountant, and then told someone. We see people who click and stay quiet because they are embarrassed. The sooner someone says "I think I clicked", the sooner the IT team can investigate and limit the damage.

Next
Next

Who knows the Xero password when Karen is off sick?