Prevention
You're Not Gullible. You're Human.
Why phishing still works today, and why it's not your fault.
In May 2000, millions of people around the world received an email with a simple subject line: "ILOVEYOU." Inside was a message that said a love letter was attached. People opened it. Of course they did. Within hours, the attachment — which was not a love letter at all, but a malicious program — had spread to tens of millions of computers, crippling systems at the Pentagon, the CIA, and the British Parliament. It is still considered one of the most damaging cyber incidents in history.
The people who opened that email were not careless or unintelligent. They were curious. They were human. And that is exactly what the attacker was counting on.
More than two decades later, the approach behind that attack — using emotion and trust to trick people into doing something harmful — is still the most common way criminals get into systems, steal money, and cause harm. The technology has changed. The trick has not.
---
## What is social engineering?
Social engineering is the art of manipulating people rather than machines. Instead of breaking through technical defences, attackers exploit something no software patch can fix: normal human behaviour.
Phishing is the most common form. It typically arrives as an email, text message, or social media message that looks like it comes from someone or something you trust — your bank, your employer, a delivery service, even a friend. The goal is to get you to click a link, open a file, hand over a password, or transfer money.
These messages are designed by people who understand psychology. They are not random. They are crafted to push specific buttons — and those buttons exist in all of us.
---
## The buttons they push
Effective phishing attacks almost always trigger one or more of the following:
- **Urgency.** "Your account will be suspended in 24 hours." When we feel time pressure, we stop thinking carefully. - **Fear.** "Suspicious activity has been detected on your account." Fear narrows our focus. We react instead of reason. - **Curiosity.** "You won't believe what someone said about you." We are wired to want to know. - **Authority.** A message that appears to come from your boss, your bank, or a government agency carries weight. We are conditioned to respond to authority figures. - **Trust.** The ILOVEYOU worm spread so fast partly because it sent itself to everyone in the victim's contact list. People received an infected message from someone they actually knew.
None of these are weaknesses. Responding to urgency, authority, and trust are sensible behaviours in everyday life. Attackers have simply learned to weaponise them.
---
## Why it still works, even now
The technology protecting our devices has improved enormously since 2000. Spam filters, antivirus software, multi-factor authentication, and security awareness training are now standard in many organisations. So why is phishing more prevalent than ever?
Because attackers adapted. When technical defences improved, they shifted their focus away from machines and towards people. It is simply easier to trick a person than to break through a well-configured firewall.
Modern phishing attacks are also far more targeted and convincing than the blanket campaigns of the early internet. Criminals research their targets on social media, company websites, and public records. They know your name, your employer, sometimes even your manager's name. They craft messages that feel personal and plausible, not obviously suspicious.
Artificial intelligence is accelerating this further. It is now possible to generate convincing fake emails, voice calls, and even video messages at scale, with little effort. The same emotional triggers, delivered with greater precision.
---
## If it happened to you
Many people who fall for a phishing attack feel embarrassed or ashamed. They wonder how they could have missed the signs. This reaction is understandable, but it is also unfair to yourself.
These attacks are engineered by people who study human psychology and refine their methods constantly. They are not testing your intelligence. They are exploiting the parts of you that are social, trusting, and responsive to emotion — the parts that make you function well as a person.
Being deceived by a well-crafted phishing attack does not say anything meaningful about you. It says something about the sophistication and intent of the person who sent it.
---
## What you can do
You cannot completely protect yourself from social engineering — nobody can. But you can make yourself a harder target.
- **Pause before you act.** Urgency is a red flag, not a reason to hurry. Any legitimate organisation will give you time to verify. - **Verify through a different channel.** If you receive an unexpected request from your bank or your boss, contact them directly using a number or address you already know — not the one in the message. - **Look closely at the sender.** Email addresses and website links can be designed to look almost identical to legitimate ones. A single changed letter can be hard to spot. - **Be cautious with attachments and links.** If you were not expecting a file or a link, treat it with suspicion regardless of who it appears to be from. - **Trust your instincts.** If something feels slightly off, it probably is. That feeling is worth listening to.
---
The ILOVEYOU virus worked because it offered something people wanted: connection. That has not changed. Attackers are still offering connection, safety, urgency, and reward. Understanding that the attack is always aimed at your emotions — not just your device — is one of the most useful things you can carry with you.
You were not foolish. You were targeted.
---
*Need to report what happened? Visit our [Resources](stillonline.org/resources) page for country-specific reporting information, support organisations, and next steps.*
Need help reporting or recovering?
Find where to report cyber crime in your country and where to get support.
Get help