(1/10) Phishing: Why Smart People Fall for It
Digital Safety Series: Ep. 1
You've probably seen a "your package couldn't be delivered" text at some point. Maybe you almost clicked it. Maybe you did. Phishing isn't built for careless people. It's built for busy, smart, distracted people. That's you. That's me. That's basically everyone with a phone.
It isn't some complicated technical break-in that only happens to people who "don't know better." It's actually the opposite of technical. It's psychological.
So Why Do Smart People Actually Fall For It?
There's a real myth that phishing only catches people who are careless or not tech-savvy. The data says otherwise. Doctors, tech executives, finance controllers, highly trained, highly intelligent people fall for this constantly. Why? Because phishing was never designed to beat your IQ. It's designed to beat your biology.
Psychologist Daniel Kahneman, who won a Nobel Prize for his work on human judgment, spent decades showing that your brain runs on two different modes:
System 1: fast, automatic, intuitive. It runs on autopilot, scanning for familiar patterns so you can decide in a split second without burning energy.
System 2: slow, deliberate, analytical. It's the part that actually double-checks a URL, questions a request, catches the thing that feels "off." It takes real effort to switch on.
When you're calm and unhurried, System 2 is right there, ready to spot a lookalike link. The problem is, scammers have gotten very good at making sure you never get to use it.
They do that by pulling three specific levers.
The urgency lever (amygdala hijack): "Your account will be frozen in 30 minutes." "Your card is about to be blocked." Your brain reads that as a threat, and a threat triggers what's called an amygdala hijack - a real physical stress response, cortisol and adrenaline flooding your system. When that happens, System 2 goes quiet. Your brain isn't being lazy, it's prioritizing speed over accuracy, because that's what a threat response is built to do. You're not choosing to skip the check. Your biology is skipping it for you.
The familiarity lever (cognitive ease): We're wired to trust what feels familiar, and scammers know it. That's why they research their targets - the right formatting, the right tone, the right internal jargon, mentioning your actual boss or a project you're actually working on. When something requires zero effort to process because it already "looks right," System 1 waves it through without ever calling in System 2 to check. The scam isn't fighting your judgment. It's making sure your judgment never gets involved.
The authority lever (conditioned obedience): This one hits hardest at work. If an email looks like it's from your CEO, a senior vendor, or a tax official, most people's instinct is to respond fast and respect the hierarchy - not to question whether the sender is really who they say they are. The desire to be efficient and professional overrides the instinct to verify.
Stack those three together - urgency, familiarity, authority, and you've got a message that never gives your analytical brain a chance to show up. That's the actual answer to "why smart people fall for it." It was never about intelligence. It's about which system got to make the decision.
It's Not a Hack. It's a Trap Dressed Up as Something Official
The word "phishing" comes from the same place as fishing. You cast a hook, bait it with something convincing, and wait for someone to bite. Except instead of fish, attackers are after your data - your full name, your date of birth, your Aadhaar or PAN number, your net-banking login, your card details. Enough pieces, and they can walk straight into your bank account or if you work for a company, straight into its network.
We used to say "just check for bad grammar and you'll spot the fake." Not anymore. Attackers are using AI to write these messages now. The grammar is flawless. The formatting is perfect. The urgency feels real, because it's engineered to feel real.
It's also not just email anymore. There's smishing - phishing through text messages. There's vishing - phishing through phone calls, usually someone claiming to be your bank. There's quishing - phishing through QR codes that quietly send your money out instead of bringing money in. The attack surface is everywhere your phone touches. Different channel, same three levers.
When a Global Cricket Body Lost ₹20 Crore to One Email
If you think this only happens to careless individuals, look at the International Cricket Council (ICC) - the body that governs cricket worldwide and drives a massive part of the sport's ecosystem in India.
In 2022, the ICC lost close to $2.5 million (roughly ₹20 crore) to what's been widely reported as a business email compromise, or BEC, attack. In a BEC scam, criminals don't hack their way in through code. They study an organization's email patterns, then send a message that looks like it's coming from someone trusted, a vendor, an executive, a finance contact and convince an employee to authorize a payment or wire transfer. Notice which levers that pulls: familiarity, because the message mirrors something the employee already trusts, and authority, because it appears to come from someone whose request you don't stop to question. The ICC reported the incident to law enforcement in the US, and the exact mechanics of how the fraudsters got in were never fully made public. But the outcome was blunt: real money, sent by real people who believed they were dealing with a real, trusted party, gone.
This is the high-stakes version of spear phishing, not a wide net thrown at millions of random people. A targeted, researched message aimed at one person or one role, built to look exactly like something they'd already trust.
The Everyday Version: Real Scams Hitting Indian Phones Right Now
You don't have to run a global cricket body to be a target. This same playbook runs at massive scale on ordinary phones across India, every single day.
Smishing - the fake delivery text.
Over the past couple of years, India Post has had to repeatedly warn people, through the government's own fact-checking body, that a viral text message is fake. It reads something like: "Your package couldn't be delivered due to incomplete address information. Update your details within 12-48 hours or it will be returned." There's a link. The link leads to a cloned website that looks almost identical to the real one. Some versions ask for a small "redelivery fee" of ₹25 to ₹100 and quietly harvest your card details the moment you enter them. Others plant something worse on your device the moment you tap the link. India Post has said, plainly and repeatedly: they never send messages like this. If you get one, that's your answer already.
Vishing - the call that already knows your card number.
This is the one that catches people off guard, because the caller sounds like they know you. They'll state your actual card details back to you, or reference a real recent transaction, to win your trust fast. Then comes the pressure: your card is about to be blocked, unless you "verify" by reading out an OTP right now. The moment you do, the money's not being verified, it's being moved. No real bank will ever call you and ask you to read out an OTP. That single fact is the whole scam, once you know it.
Quishing - the QR code that takes instead of gives.
This one is especially sharp because it plays on a mistaken assumption. In India's UPI-driven world, a QR code shows up claiming to be a "cashback," a "refund," or a "lottery win." People scan it expecting money to land in their account. But a QR code is built to send money, not receive it. The second you scan it and enter your UPI PIN, you've authorized an outgoing payment, straight to the scammer. There is no such thing as "scan this QR code to receive money." If a code implies otherwise, that's the tell.
Why None of This Is About Being Careless
Look at the pattern across all three. The ICC case. The fake delivery text. The "your card will be blocked" call. None of them hacked anything. Each one just pulled the same three levers - urgency, familiarity, authority, and let biology do the rest.
That's the real skill scammers have built: manufacturing a feeling, not writing better code.
Your Practical Checklist - Use This Every Time
Pause on urgency: Any message demanding instant action, "24 hours or your account is suspended," "12 hours or your package is returned" is a signal to stop, not to comply. Real organizations, banks included, don't threaten instant account closure over a text message.
Check the actual domain, not the logo: Scammers can copy a logo, a font, an entire page design in minutes. What they can't do is legally own a company's real domain. If a message claims to be from your bank or India Post but the link doesn't match their official domain exactly, that's your answer. Look at the URL bar, not the pretty design around it.
Go direct, every time: Never act through the link or number inside an unsolicited message. If you're worried about a delivery or an account, close the message, open a fresh browser tab, and type in the official website yourself. Or open the company's app directly. You're bypassing their fake doorway entirely, and this one habit alone blocks most of these attacks.
Hang up, then call back yourself: If someone calls claiming to be your bank, a government office, or any company asking you to "verify" details or read an OTP, hang up. Find the real number from your bank statement, your card, or the official app, and call that number yourself. You're the one initiating the verification now, not them.
Report it: India has a dedicated portal for this: cybercrime.gov.in, and a national helpline at 1930. Reporting a scam doesn't just protect you, it helps shut the operation down before it reaches someone else who might not pause in time.
The goal here is to build one habit: trust after you've checked, not trust by default. That's it. That's the whole shift. You're smart enough to spot the patterns. You just have to remember to actually look.
Reference materials:
ICC ₹20 crore business email compromise (2022)
ESPNcricinfo report as covered by The Daily Star: https://www.thedailystar.net/sports/cricket/news/icc-loses-25m-phishing-scam-3226706
The Federal: https://thefederal.com/sports/icc-lost-close-to-2-5-million-in-phishing-scam-in-2022-report
Business Standard (via TBS News, same wire pickup): https://www.tbsnews.net/sports/icc-falls-prey-online-scam-loses-close-25-million-usd-571586
India Post smishing scam
Press Information Bureau (PIB) Fact Check, via Business Standard: https://www.business-standard.com/finance/personal-finance/that-india-post-parcel-message-on-your-phone-it-s-a-scam-says-pib-125101300283_1.html
PIB Fact Check follow-up, via Business Standard: https://www.business-standard.com/finance/personal-finance/another-delivery-scam-surfaces-pib-flags-fake-india-post-sms-125102000484_1.html
Business Standard (case detail, ₹23.26 lakh Hyderabad victim): https://www.business-standard.com/india-news/new-india-post-scam-targets-citizens-what-is-it-and-how-to-be-safe-124091700490_1.html
Daniel Kahneman - System 1 / System 2
APA Monitor on Psychology, official summary of Kahneman's work: https://www.apa.org/monitor/2012/02/conclusions
The Decision Lab (academic reference guide): https://thedecisionlab.com/reference-guide/philosophy/system-1-and-system-2-thinking
A note on the rest: "amygdala hijack" and "cognitive ease" are established psychological terms (the former coined by Daniel Goleman, the latter from Kahneman's own book)
