06/24/2026
Most people feel relatively confident about spotting a phishing email 🎣
And a few years ago, that confidence was often justified.
You could usually rely on obvious clues. Poor spelling, strange wording, emails that didn’t sound quite right.
But that’s changed 😱
It’s becoming apparent that there’s a clear gap between how confident people feel and what happens when they’re tested with realistic phishing messages.
The interesting part is why people are getting it wrong: Phishing emails don’t look like phishing emails anymore.
With AI helping to write and refine messages, they read like normal business communication.
The tone feels right, the language flows properly, the usual red flags aren’t as obvious as they once were.
And it makes the decision much harder.
Instead of spotting something that looks wrong, you’re being asked to question something that looks completely normal.
And that’s where things slip through.
How do you prepare your business for this?
Traditional security training often focuses on what to look for, but real-world situations don’t always follow a checklist.
When someone is busy, dealing with a full inbox, and trying to keep things moving, even a well-trained person can make a quick decision that they wouldn’t make with more time.
What seems to work better is building habits as well as awareness.
🔎 Taking a moment before acting
🔎 Checking where a link really goes
🔎 Going directly to an account instead of following an email prompt
These are small actions, but they hold up even when the message looks convincing.
💭 When an email looks completely legitimate, what would make you pause before you act?