Skip to main content
Phishing Scams

Phishing Scams: Why Your Best Defense Isn't Awareness

Stop blaming users for clicking. The real fix for phishing is phishing-resistant MFA and a culture that rewards reporting, not perfect detection.

Stop telling people to spot phishing emails. That's the advice everyone gives, and it's mostly useless. The FBI's IC3 received 193,407 phishing complaints in 2024 alone — the most-reported crime category. People clicked. They will keep clicking. The better strategy: assume the click will happen and make it harmless.

The awareness trap

Awareness training treats phishing as a knowledge problem. It isn't. Attackers now use generative AI to write flawless messages (CISA). Verizon's 2026 DBIR found threat actors use AI to work faster at every attack stage. You cannot train 500 employees to out-analyze a machine that never sleeps.

Verizon's 2024 DBIR found 68% of breaches involve a non-malicious human element. That's the number that should end the awareness-first era. The human is not the weakest link; the system that lets one click compromise everything is.

Make the click boring

Phishing-resistant MFA — FIDO/WebAuthn security keys or passkeys — is the only widely available authentication that stops phishing (CISA). Traditional MFA (SMS codes, push notifications) can be bypassed by phishing, push bombing, SS7 flaws, or SIM swapping (CISA). If your MFA can be relayed, it's not a phishing defense; it's a speed bump.

Microsoft says MFA blocks over 99.9% of account compromise attacks. But that stat hides a caveat: it doesn't specify which MFA. SMS MFA still lets a SIM-swap victim get owned. So the real goal is phishing-resistant MFA on email, banking, and cloud accounts first (CISA).

Here's a concrete example: an attacker calls a carrier, claims your phone was stolen, and gets your number moved to their SIM. Now every SMS code goes to them. If your bank uses SMS MFA, they're in. If it uses a FIDO2 key, they're stuck. That's the difference between a breach and a shrug.

What about reporting?

The strongest counter-argument: if you stop pushing awareness, people won't report suspicious messages. Fair. But awareness and reporting are different. You don't need users to diagnose; you need them to forward. CISA's Recognize, Resist, Delete framework — spot, report, delete without clicking — works only if reporting is frictionless and blame-free.

Create a one-click report button. Never punish someone who reports a mistake. Punishment drives silence; silence drives dwell time. Verizon's 2026 DBIR found mobile devices are a new favorite target, with people more likely to fall for fake texts or calls than email. Your reporting channel must cover SMS and voice, not just email.

Technology first, people second

If you run a small business, CISA's four essentials are: teach phishing avoidance, require strong passwords, require MFA (phishing-resistant where available), and update software. Notice the order: teach first, but MFA second. I'd flip it. Deploy phishing-resistant MFA before you run another training slide.

Passwords still matter. Use a manager to generate unique ones — at least 16 characters, random, unique (CISA). NIST requires 15 characters for single-factor and 8 with MFA. But no password length survives a real-time phishing proxy. Only FIDO/WebAuthn does.

What I'd actually do

Buy hardware security keys for every employee who touches email or financial systems. Enable passkeys on personal accounts. Turn off SMS MFA everywhere it's optional. Set up a one-click report button and celebrate every report, even false alarms. Then, and only then, run a short quarterly training that focuses on reporting, not detection.

Measure success by click rate? No. Measure by report rate and time-to-revoke. If someone clicks, your MFA should stop it, and your team should know within minutes. That's a security program, not a guessing game.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • CISA (Recognize and Report Phishing) - https://www.cisa.gov/secure-our-world/recognize-and-report-phishing
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/

Share this article:

Comments (0)

No comments yet. Be the first to comment!