Sentinel Vault
← All field notes
Human & Social Impact · May 24, 2026

Why People Fall for Scams They Already Recognized

Why People Fall for Scams They Already Recognized

After enough years interviewing fraud victims, you start to notice that the most common sentence in the interview is not the one you would expect.

It is rarely "I didn't see it." It is rarely "I had no idea." It is some version of "I had a feeling it was a scam." Or "I knew better than this." Or "Something told me to stop."

The recognition fired. The skepticism activated. The internal alarm went off. And the money still left the account.

That single fact, repeated across hundreds of interviews, ought to reorganize how we think about security awareness training. Most of the industry is still measuring whether users can recognize a scam. The real question is what happens in the thirty seconds after they do.

The case examples in this post are drawn from Fleeced Nation, my novel about a Los Angeles fraud unit. The characters are fictional. The patterns are not.

What Awareness Training Measures, and What It Misses

The security awareness training industry has built a sophisticated reporting layer over the last decade. We can measure click rates, report rates, time-to-report, time-to-lure. We can profile which emotional manipulations work best on which users. We can deliver personalized coaching based on those profiles.

All of that is real progress. None of it is wrong.

But all of it lives inside one of three distinct failure landscapes. The other two are largely invisible to the analytics models we have built. Training programs that only address the first landscape will improve the metric, leave the failure rate roughly where it is, and confuse senior leadership about why.

The three failure landscapes are the emotional trigger, the cognitive bias, and the behavioral state. They are different problems with different solutions, and we are mostly trying to solve one of them.

Layer One: The Emotional Trigger

Consider Evelyn Park. A seventy-one-year-old widow in Walnut, California. Korean-American, lives alone on a quiet street. The call comes in on a Tuesday morning. A voice on the other end says her grandson has been arrested. There is a bail amount. There is a courier who can pick up cash and deliver it to the courthouse. There is a clock running. There is a man on the line who sounds like he is trying to help her.

By Wednesday afternoon, she has handed ninety-five thousand dollars in cash to a stranger at her front door.

This is the emotional trigger layer. Fear, urgency, the threat to a loved one. The fraud script is engineered to hit a single emotional pressure point so hard that deliberation cannot get a word in. It is fast, loud, and designed to bypass the part of the brain that would otherwise ask questions.

This is the layer awareness training reaches well. Phishing simulations can measure how often a user reacts to urgency cues. Personalized profiling can identify which emotional buttons land hardest on which employees. Repetition and feedback can build slower reflexes against the pattern.

If your training program is doing this work well, you are protecting the Evelyn Park scenario. That is real progress and worth measuring. The mistake is believing it is the whole job.

Layer Two: The Cognitive Bias

Consider Aunt Judith. Sixty-eight years old, lives in North Platte, Nebraska, husband bedridden, the household running on her quarter-million-dollar retirement account. The scam starts as a PayPal overpayment. She is told a buyer has accidentally sent too much money and she needs to wire the difference back.

She wires it.

It does not feel right afterward. She knows she should not have done it. But the next call explains that there was a clearing problem and another wire is needed to release the original. She wires that one too. By the third wire, the entire account is gone.

This is not three separate failures. It is one failure compounded by a cognitive bias that has been documented for fifty years. Once a person has committed resources to a course of action, the psychological pressure to protect that investment overrides clean evaluation of the next step. The economists call it the sunk cost fallacy. The fraud operators call it the second pull.

What matters here is that no amount of emotional susceptibility profiling would have caught this. The first wire was the trigger. The second and third wires were architecture. Aunt Judith did not have a vulnerability to PayPal-overpayment scripts. She had the same vulnerability every human carries to sunk cost reasoning, layered on top of a script designed to weaponize it.

The full list of cognitive biases the fraud industry exploits is long and known. Authority bias, social proof, sunk cost, scarcity, anchoring. They are not personality traits. They are how the human mind processes uncertainty under pressure. A susceptibility profile cannot fix them because they are not user-specific. They are species-specific.

Layer Three: The Behavioral State

Consider Miguel Alvarez. A self-employed HVAC contractor in the San Gabriel Valley. He runs four crews, manages payroll, schedules jobs, fields supplier calls, all from a phone in his truck between visits. On a Thursday afternoon, an email arrives that looks like it came from a long-time supplier. There is an invoice. There is an updated bank account number for the wire. There is the same language the supplier always uses.

He approves the wire from his truck on the way to the next call.

Sixty-five thousand dollars goes to the attacker. The real supplier was never compromised. The email account spoofing was good enough to pass the half-second scrutiny a tired contractor can afford between two appointments.

Miguel was not careless. He was on autopilot. He was processing the email the way he had processed eighty similar emails that week, because his attention was a finite resource being spent on actual work. Cognitive load is the invisible attack surface that awareness training cannot see. A susceptibility profile drawn from a 90-second phishing simulation cannot detect that a user is exhausted on a Thursday afternoon or that their attention budget for the day is already depleted.

Now consider a different victim, the unnamed woman from Santa Clarita who lost one-point-eight million dollars to a pig-butchering scam. The relationship started months earlier on a dating app. It moved to text messages. There were photos. There were daily check-ins. There were small disclosures about his job in international finance, and small jokes about her cat. By the time the investment opportunity came up, she was not being scammed by a stranger. She was being asked for a favor by someone she had come to trust.

Incremental commitment over months is not detectable by any training tool. The grooming relationship looks nothing like the threats awareness programs have been built to recognize. There is no phishing email to flag. There is no urgency to override. There is a sustained relationship that gradually shifts what counts as a normal request.

This is the third landscape. State and context. When, not who. The user is the same person they were at nine in the morning. The conditions are different.

The Override Moment

This brings us back to where we started. The most common sentence in a fraud interview.

The Evelyn Park scenario, the Aunt Judith scenario, the Miguel Alvarez scenario, the Santa Clarita scenario. Different mechanics. One shared feature. In almost every interview, at some point, the victim describes a moment of internal warning that they recognized and overrode.

Evelyn told the detective she thought it was strange the courier wanted cash. She did it anyway. Judith told her son she had a bad feeling after the first wire. She sent the second one. Miguel said he almost called the supplier to confirm. He decided he was being paranoid and approved the wire. The Santa Clarita woman told her sister she had wondered for weeks if the relationship was real. She kept investing.

Most fraud failures are not recognition failures. They are override failures.

The training worked. The pattern was identified. The internal alarm went off. And something else, something the awareness training industry has barely begun to study, won the argument inside the victim's head in the next thirty seconds.

This is the layer of the failure landscape no current awareness program is designed to address. Not because anyone is failing at their job. Because the medium of awareness training, simulated phishing emails and short coaching videos and quarterly assessments, was built to teach recognition. It was not built to teach what to do once you recognize something.

What Awareness Training Actually Reaches

A candid accounting helps here.

Personalized, profile-driven awareness training does real work against the in-the-moment emotional hijack of a user who is paying attention and has the cognitive bandwidth to evaluate. That is a non-trivial slice of the problem. It is worth doing well.

It does not reach the override moment. It does not reach the architectural cognitive biases that fire regardless of profile. It does not reach the state-based bypass that happens when the user is tired or distracted. It does not reach the relationship-based grooming that happens over months. And it does not reach the population of vulnerability factors that have nothing to do with susceptibility profile at all: grief, cognitive decline, debt desperation, isolation, the early stages of dementia.

This is not a critique of any particular vendor or platform. It is a structural ceiling on the medium. Awareness training is one tool in the human risk reduction stack. It is not the whole stack. Treating it as the whole stack is what produces the program performance that looks great in the dashboard and identical in the loss numbers.

What Has to Change

Four moves, in order of how much leverage they carry.

Train for the override moment, not just the recognition. Every awareness curriculum I have seen teaches users how to spot a scam. Almost none teach users what to do in the thirty seconds after they have spotted one and the internal alarm has fired. That window is where the fraud is won or lost. Specific, rehearsed actions matter here. Call a designated person before sending any wire over a threshold. Sleep on any request that arrives with urgency. Read the email aloud to a colleague. These are not awareness skills. They are response skills, and they have to be drilled.

Design environments that break autopilot. Cognitive load is an attack surface. The answer is not better training for the contractor in his truck. It is a bank-level cooling-off period on wires over a threshold for that contractor's business account. It is a two-person verification step on payment-account changes. It is a mandatory delay between approval and execution on high-value transfers. These design choices are unglamorous and they save people from themselves on the days they cannot defend themselves.

Acknowledge what training will not reach, and build protective infrastructure for it. Some vulnerability factors are not user errors and they will not be trained away. A widow grieving her husband, an older user with early cognitive decline, an employee in financial desperation, an isolated person who has been groomed for six months by a fraud operator pretending to love them. These people need protective infrastructure that does not depend on their own judgment in the moment. Account-level transaction monitoring with family notification. Bank protocols for unusual cash withdrawals. Mandatory cooling-off periods. Trusted contact designations. The training industry cannot reach these populations on its own. It can help build the case for the infrastructure that surrounds them.

Train the network, not only the target. Most successful fraud interventions in actual cases come from someone other than the victim. The daughter who calls to check in. The colleague who asks "wait, did finance actually request this?" The teller who pauses on the third cash withdrawal in a week. The neighbor who notices the unfamiliar courier at the door. The awareness training industry has spent twenty years training the target. The leverage is in training the network around the target.

The dashboard is not the strategy. The dashboard is the diagnostic. The strategy is recognizing that recognition is one layer of a four-layer problem, and that the layers we are not measuring are the ones doing most of the damage.

Frequently asked
Why do people fall for scams they already suspected?
Recognition and action are two different things. Across hundreds of victim interviews, the most common statement is not "I had no idea," it is "I had a feeling it was a scam" or "I knew better." The skepticism fired and the money still left. Most security awareness training measures whether people can recognize a scam, but the decisive question is what happens in the thirty seconds after they do.
What are the three failure landscapes behind falling for a scam?
The emotional trigger, the cognitive bias, and the behavioral state. The emotional trigger is a fear or urgency script, like a fake grandchild-in-jail call, engineered to hit one pressure point so hard that deliberation cannot get a word in. The cognitive bias and behavioral state are the other two, they are different problems needing different solutions, and they are largely invisible to the click-rate analytics most programs rely on.
Why does awareness training improve the metrics but not the failure rate?
Because most programs only reach the first failure landscape, the emotional trigger, which is what click-rate analytics can measure. The cognitive-bias and behavioral-state failures happen after recognition and are invisible to those models, so a program can drive click rates down while the real failure rate stays roughly where it was, which confuses leadership about why losses continue.
What should training measure instead of recognition?
What happens in the thirty seconds after recognition. Since victims often recognize the scam and act anyway, the useful target is the decision and behavior that follow the internal alarm, not just whether the alarm fires. That means building slower reflexes and interruption points into the moment of action, not only teaching people to spot the lure.
About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.