Why smart people click: The psychology behind every phishing attack

In January 2024, a finance employee at the Hong Kong office of engineering firm Arup joined a video call with his CFO and several colleagues to discuss a confidential transaction. Everyone looked familiar. The CFO spoke. The colleagues nodded. The employee transferred $25 million.

There was no CFO on that call. There were no colleagues. Every person he saw and heard was a deepfake generated using publicly available footage and AI voice cloning tools. By the time the fraud was discovered, the money was gone.

The employee was not careless or poorly trained. He looked at his colleagues and saw his colleagues. That is the point. Phishing in 2026 is no longer about a badly worded email asking you to verify your account. It is about an AI-generated version of someone you trust, telling you what you need to hear when your guard is down.

The exploit has always been human

Before AI, attackers had already mastered the psychology. Effective phishing targets cognitive shortcuts your brain relies on every day. These are features of human cognition, not weaknesses unique to the naive or untrained.

• Authority bias. We tend to comply with perceived figures of power without pausing to verify legitimacy. Your brain assigns trust categories, so you do not scrutinize an email from your CEO the way you scrutinize one from an unknown address. Attackers exploit that system.

• Urgency. Under time pressure, the brain shifts from System 2 thinking (slow, deliberate and analytical) to System 1 (fast, automatic and instinct-driven). Daniel Kahneman’s work explains why urgency is so reliably exploited: the faster mode is built for rapid response, not careful verification. The suspended account. The failed payment. The wire transfer that must clear in forty minutes. Feeling pressure from the sense of urgency makes you human.

• Social proof. When others appear to accept something as legitimate, the brain treats that as evidence. The Arup deepfake worked not only because the CFO looked convincing, but because the colleagues did, too. A room full of people nodding normalizes the situation.

In 2023, Scattered Spider used these levers to breach MGM Resorts International without touching code. They called the IT help desk, impersonated an employee using LinkedIn information, and talked their way into internal systems. The attack cost MGM an estimated $100 million. No malware. No exploit. Just a phone call.

What AI changed

Everything above existed before large language models. AI has industrialized it and removed the friction that once limited its reach.

Spear phishing—the targeted variant that uses your name, role, colleagues, and context to carry out an attack—was labour-intensive. A convincing attack required research and time, limiting the scale at which attackers could operate. That constraint is gone.

Tools like WormGPT and FraudGPT, malicious-use AI models available on dark web marketplaces for a few hundred dollars a month, can generate thousands of personalized, grammatically flawless phishing emails in minutes. They can use a target’s LinkedIn profile, manager, projects, and communication style to produce a message that reads as if it came from someone who knows them. Misspellings and awkward phrasing are no longer reliable signals. AI-written phishing can look legitimate because it is modeled on legitimate communication.

Researchers at SlashNext reported a 1,265% increase in phishing emails in the twelve months following the public release of ChatGPT. That is a structural shift.

AI also exploits cognitive load. When someone is juggling decisions and context-switching, their capacity for careful evaluation shrinks. Attackers time communications for stretched moments: end of quarter, end of day, or back-to-back meetings. A message that raises flags on a slow morning may be acted on at 4:45pm on a Friday.

The voice at the other end

Voice cloning has taken the same trajectory. Attackers can clone a person’s voice from as little as three seconds of audio captured from a LinkedIn video, podcast or company town hall, then use it in real-time calls or recorded messages.

In 2024, the FBI warned about AI voice cloning in vishing campaigns targeting senior executives and government officials: a familiar caller creates urgency around a financial transaction or credential request, followed by a spoofed text or email.

This works through multi-channel reinforcement. When the same message arrives through more than one channel we trust independently, repetition feels like verification. A call from the CFO followed by an email confirming the request feels like evidence. Attackers engineer that feeling.

Why training alone no longer holds up

Security awareness training has long focused on phishing signals: misspellings, suspicious sender domains, and unexpected attachments.

Those signals are being eliminated. When the email looks legitimate, the voice is familiar, and the face on the video call is trusted, there may be no obvious tell. Attacks are engineered to satisfy the cognitive shortcuts training tried to sharpen.

A 2024 IBM study found that AI-generated phishing emails achieved click rates comparable to those crafted by human social engineers and, in some scenarios, significantly higher because they lacked the small inconsistencies trained users had learned to flag.

Awareness training is valuable, but it cannot be the last line of defense. Workflows should prevent a single moment of human judgment from authorizing a catastrophic action through out-of-band verification, multi-person approval, and callback procedures using independently stored numbers.

The Arup employee who transferred $25 million did what his training told him to do. He verified the meeting invitation. He recognized the faces. He heard familiar voices. The problem was that his environment gave him no mechanism to verify what his senses were telling him.

The threat in 2026 is not carelessness. It is trust used against us at scale. The question is whether systems can survive the moments when being careful is no longer enough.

What the new red flags actually look like

The old tells are largely gone, but AI-generated attacks have introduced different signals:

• Urgency combined with an unusual channel switch. Legitimate internal processes rarely require a move from email to WhatsApp, or from a scheduled meeting to an unplanned call, mid-transaction. Channel switching breaks the audit trail and normal procedure.

• Resistance to verification. A real CFO will not object to a callback using the company directory, and a real IT administrator will not say the situation is too urgent for confirmation. Any contact that discourages verification should not be trusted. Attackers rely on motivated reasoning—our tendency to excuse people we trust.

• Contextual precision that feels slightly off. AI spear phishing may get names, roles and company context right while missing details a real colleague would know intuitively, such as a project name, internal code, or platform. One researcher described it as “a very convincing stranger who has done a lot of research.” The research is visible. The familiarity is not.

• Requests that bypass normal processes under the cover of confidentiality. Scattered Spider’s MGM breach succeeded partly because impersonating IT support gave attackers a reason to bypass verification. Genuine escalations do not usually require secrecy from your security team. Confidentiality that isolates you from people who could verify the request is a social-engineering signal.

What verification actually looks like in practice

Process changes work only if they are specific enough to execute under pressure. Mature security postures embed controls like these:

• Preapproved callback numbers, stored independently. Maintain verified numbers for finance, IT, HR and executive assistants. When a sensitive request arrives through any channel, including video, hang up and call back using the preapproved number, not one supplied by the caller.

• Dual-approval with physical separation for financial transfers. Transactions above a defined threshold should require two people to confirm independently, not in the same email thread or call. In the 2016 FACC case, an Austrian aerospace firm lost $47 million to CEO impersonation because there was no second checkpoint. Removing that single point of authorization is more effective than relying on one individual.

• A shared code word for high-value verification. Some organizations use a verbal or written code word known only to internal teams. It is low-tech, requires knowledge an attacker is unlikely to have, and side-steps the pressure of the moment.

• A culture where verification is never a career risk. People who believe questioning a senior's request translates into distrust or incompetence will not question that request. Research on organizational deference shows employees under-challenge upward when stakes are highest. Leadership must make clear that verification is expected behavior, not an inconvenience. This is a management message, not only a security message.

The Arup case, and the many like it that do not make the news, will keep happening until the conditions that allow them are changed. AI will not slow down. The attacks will not become less convincing. The window to fix the process is between now and the time the next call comes in.