Human Risk

Why smart people click: fifteen years of watching it happen

Phishing is not a knowledge problem. The people who click are usually the ones doing their jobs properly, and that is exactly what the attack is built to exploit.

Why smart people click: fifteen years of watching it happen

Smart people click because attacks are designed for competent people in a hurry, not for careless ones. In fifteen years of running security awareness programmes I have never once found that the person who clicked did not know what phishing was. They knew. They clicked anyway, and usually for a reason that made sense at the time.

Human Element in Breaches 62% of breaches, per Verizon’s 2026 DBIR
Avg Reporting Rate About 13% of simulated phishing gets reported, per Proofpoint
AI Phishing Click Rate 54% for AI generated emails vs 12% for a generic control group, per a peer reviewed study
No Blame Guidance UK NCSC recommends a no blame reporting culture over punitive policies

That gap between what people know and what people do is the entire problem, and almost every awareness programme is built to solve the wrong half of it.

The people who click are usually your good employees

Look at who actually falls for a well-built simulation. It is rarely the person coasting. It is the one who replies fastest, who does not want to hold up a colleague, who saw a message from a senior name and did the responsive thing. Attackers do not target stupidity. They target conscientiousness, urgency and hierarchy, because those are reliable across every organisation on earth.

This is why the annual training video changes nothing. It adds knowledge to people who already had it. It does not touch the conditions under which the mistake gets made.

What actually changes behaviour

Three things, in my experience, in this order of impact.

Coaching at the moment of the mistake. A person who clicks and gets a short, calm explanation within seconds remembers it. The same person told about it in a quarterly module does not. The window where a mistake becomes learning is measured in seconds, not weeks.

Making reporting the easy path. Most people who are suspicious of a message do nothing, because doing something is effort and being wrong is embarrassing. Put a report button where they already are, thank everyone who uses it including the ones who were wrong, and reporting climbs. Reporting matters more than click rate, because reports are how you find the attack that got through to everyone else.

Removing the shame. Programmes that publish click rates by team produce quieter employees, not safer ones. If clicking is humiliating, people hide it, and the hour you lose to hiding is the hour the attacker needs.

What AI changed, and what it did not

The obvious change is quality. The tells we taught people to look for, broken grammar, odd phrasing, generic greetings, are gone. A model writes better English than most native speakers and it can write it in the register of your industry. Advice built on spotting mistakes has expired.

The less obvious change is personalisation at scale. It used to be that a targeted attack on a specific executive took real effort, so only high value targets got one. That cost has collapsed. Everyone can now receive the kind of message that used to be reserved for the finance director.

What has not changed at all is the psychology. Urgency, authority, fear of looking unhelpful. Those levers are the same ones that worked in 2010, because they are human, not technical. Which means the defence that works is still behavioural, and it is now the only defence that scales, because the surface-level tells are gone.

If you are responsible for this at your company

Stop measuring your programme by click rate alone. Measure reporting rate, and measure how fast a report reaches someone who can act. Run simulations that look like the messages your people actually receive rather than the templates that come with the tool. Coach in the moment, never in a quarterly. And treat the people who click as the signal that your process has a gap, not as the gap.

The uncomfortable truth is that a sufficiently good attack will get a click from almost anyone, including you and including me. The programmes that work are the ones designed for that being true.

Takeaways

  • Replace click rate as your top phishing metric with reporting rate and time to report, and set a target for both.
  • Add a one click report button inside the email client itself, and send a thank you response to everyone who uses it, even when the message was legitimate.
  • Give people a short, plain language explanation within seconds of a simulated click instead of saving the lesson for a quarterly training module.
  • Pull your next simulation templates from real messages your own staff received recently rather than the vendor’s default template library.
  • Stop publishing click rates by name or team, and audit your program for any policy that penalizes people for clicking.

Questions people actually ask

Why do smart, careful employees still fall for phishing scams?

Attacks target conscientiousness and urgency, not intelligence. Well built phishing exploits reliable human traits: wanting to respond quickly, deferring to authority, and avoiding the appearance of being unhelpful. Knowing what phishing looks like does not remove the pressure to act fast under those conditions, which is why engaged, competent staff are often the ones who click, not the careless ones.

Does AI make phishing emails harder to detect?

Yes. Large language models remove the grammar mistakes, odd phrasing and generic greetings that used to flag phishing attempts, and they can write in the specific tone of an industry. A peer reviewed study comparing AI generated spear phishing to human crafted attempts found AI automated messages reached click through rates matching experienced human attackers, far above generic phishing sent to a control group.

What should companies measure instead of phishing click rates?

Track reporting rate, meaning how many suspicious messages get flagged, and response speed, meaning how fast a report reaches someone who can act on it. A low click rate can hide a culture where people quietly ignore suspicious messages instead of reporting them, while a rising reporting rate surfaces the attack that got through before it spreads across the rest of the company.

Does punishing employees for clicking phishing links improve security?

No, it tends to backfire. Punitive approaches push employees to hide mistakes rather than report them, which slows down detection of real attacks already inside the network. Guidance from the UK National Cyber Security Centre recommends a no blame culture, since staff who fear reprimand report suspicious emails less often, which removes an organization’s earliest warning system for attacks in progress.

How much of a role does human error play in data breaches?

A majority. Verizon’s 2026 Data Breach Investigations Report found the human element was involved in 62 percent of breaches, through routes like phishing, social engineering and credential misuse. That is one reason security programs built only around technical controls, without addressing how and when people make decisions under pressure, still leave the most common attack path largely unaddressed.

Sources

  1. 2026 Data Breach Investigations Report (DBIR)Verizon
  2. Phishing attacks: defending your organisationNational Cyber Security Centre (UK)
  3. How Good Are Users at Reporting Phishing Simulations?Proofpoint
  4. Evaluating Large Language Models’ Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human SubjectsarXiv

What happens next

As AI generated phishing keeps closing the quality gap with human written attacks, expect more organizations and researchers to shift benchmarking away from click rate toward reporting speed and psychological safety metrics. Standards bodies and regulators are likely to lean harder on no blame reporting culture as a baseline expectation rather than a nice to have. Watch for vendors to publish more granular reporting rate benchmarks as click rate alone becomes a less reliable signal of programme health.

Share this
Come find me

The daily thinking
lives on the feeds.

Long form here. The working notes, the arguments and the things that did not fit go out most days.

← All writing