The Anatomy of Manipulation: What 691 Phishing Emails Taught Us About Trust

Ask most people what a phishing email looks like, and they'll describe a threat. Your account has been suspended. Unusual activity detected. Click here or lose access. It's the mental image decades of security training have built: the attacker as digital mugger, jumping out of an alley with a knife made of urgency.
We spent seven years collecting the emails attackers actually send. Then we read all 691 of them, coded each one against known psychological patterns, and asked a simple question: what are people actually up against?
The answer surprised even us. Fear is not the dominant weapon. Trust is.
Seven years, one very unusual dataset
Hook Labs, our research team, pulled together everything our platform had quietly accumulated since 2019: 691 phishing simulation templates modeled on real-world attacks, spanning 1,474 organizations and 135,115 people who received them. We coded every message two ways — once against our own Six Tactics framework (Urgency, Scarcity, Trust, Helpfulness, Authority, Social Proof), and once against a framework from affective neuroscience that sorts persuasion by which primal emotional system it targets: SEEKING (reward and novelty), FEAR (threat), CARE (helping), or PANIC/GRIEF (loss).
Two ground rules, so the data can speak for itself. First, we didn't look at who clicked — this is a study of attacker craft, not victim behavior, so nothing here can be spun into a "these people are gullible" narrative. Second, every stat below describes patterns across our template library in aggregate. No individual organization or person is identifiable in any of it.
Here's what seven years of that library actually contains.
Phishing doesn't scare you. It flatters you.
Coded against the Six Tactics, the pattern that shows up in seven out of ten messages is Trust — the email impersonates someone the recipient already has a relationship with. Urgency and Authority trail a distant second and third, each appearing in roughly a quarter of messages. Social Proof — "everyone else already clicked," a cornerstone of classic persuasion theory — is almost nowhere. It shows up in 0.3% of messages. Attackers apparently never got that memo, or more likely, they tested it and it didn't work as well as simply showing up as your coworker.
The emotional-systems coding sharpens the picture further. Appeals to SEEKING — reward, novelty, curiosity: the gift card, the shared document, the bonus — show up in 37% of messages, roughly double the share built on FEAR (18%).
The phish that gets through doesn't usually look like a threat. It looks like good news, a familiar face, or a routine request from someone you already trust.
Put those two findings together, and a load-bearing assumption of most security training quietly collapses. Fear-first training programs; breach horror stories, warning banners, consequence slides, train people to raise their guard against messages that feel dangerous. But four out of five messages in our library don't feel dangerous at all. They feel like good news. An employee trained to fear scary email has been trained against maybe a fifth of what's actually out there, and left alone with the rest. Worse: a person already on edge from fear-based training is arguably the easiest mark for the next message that offers relief instead of threat.
Meet the boss in a hurry
Nearly half of all messages in the library (47%) stack two or more tactics at once, and the pairings aren't random. The single most common combination — 116 messages, well ahead of anything else — is Authority plus Urgency: someone with standing to make a demand, on a deadline that leaves no time to think it over. Wire this today. Your access expires in 24 hours. Payroll needs your confirmation by 5.
Look closely at who that combination is built to catch. It isn't the careless employee. It's the conscientious one — the person who answers email promptly, respects the chain of command, and doesn't want to be the reason payroll is late. The second-most-common family of pairings, built on Trust and Helpfulness, targets a similar disposition: the person who wants to be useful to a colleague.
That reframes the entire conversation about human error. People don't get phished because they're careless. They get phished because someone weaponized the exact instincts that make them good at their jobs — responsiveness, deference, a desire to help. Treating a click as a discipline problem punishes precisely the traits an organization hired for. The more useful mental model borrows from workplace safety, not performance reviews: the employee who slipped was doing their job, in an environment engineered to be slippery.
There's a policy fix here that costs nothing. If leadership states plainly, in writing, that no legitimate internal request will ever penalize a short delay for verification — and then visibly tolerates being verified themselves — the urgency half of this attack loses its fuel for free.
The danger wears a lanyard
Ask someone to picture a phishing email and they'll probably picture a stranger — a foreign bank, a shady courier notice, a prize they didn't enter to win. Our library says the more dangerous impersonation wears your own company's letterhead. The single most impersonated sender across seven years of data isn't a bank or a tech giant. It's Human Resources — ahead of every consumer brand in the corpus, including the ones you'd expect, like Amazon or Apple. IT and email support aren't far behind. Altogether, 29% of messages impersonate some internal function of the recipient's own company, and three-quarters of all messages fold in the recipient's actual name or email address.
That has two direct implications. For training, "check whether this came from outside the company" is a heuristic the majority-internal impersonation pattern is specifically built to defeat — recognition practice needs to include internal-looking mail, not just external scams. For policy, it means your organization's own communication habits are a security control. Every time HR sends a real mass email with an urgent deadline, a link to an outside portal, and a generic greeting, it teaches employees that pattern is normal — and makes it cheaper to forge. If your legitimate internal email is hard to tell apart from your own phishing simulations, the fix belongs to your communication standards, not to your employees' vigilance.
Attackers keep changing the wrapper, not the message
Over those seven years, the delivery mechanics in our library multiplied fast: credential-harvesting landing pages now sit behind 51% of messages, alongside attachments, QR codes, and multi-step sequences that barely existed in the corpus's earlier years. And yet the underlying tactic mix barely moved. Attackers keep iterating on the vehicle. They conserve the psychology.
That's genuinely good news for how you spend training time. A recognition skill built around tactics — "this is Authority plus Urgency, regardless of what it's wrapped in" — travels across every new delivery method attackers invent next. A skill built around artifacts — hover over the link, check for typos, watch for a weird sender domain — expires the moment the vehicle changes. Teach the psychology and the training survives the next platform shift. Teach the artifact, and you're rebuilding the curriculum every time attackers switch tools.
It also explains something else in the data: nearly half of the templates in our library ship with a teachable moment attached directly to the simulated click — training delivered in the instant a person's mental model of "normal email" just failed, exactly when they're most ready to actually absorb why. That's a deliberate bet on timing, not just content.
A structural footnote: most of this happens at a very small table
One more finding is worth a beat, because it quietly explains why so much published security research doesn't match lived reality. The median organization in our dataset has 28 people. Four in five have fewer than 100. The research literature, meanwhile, is written almost entirely about enterprises with security teams and dashboards to babysit — a reality that describes a small slice of the actual market. In a 28-person company, "security culture" isn't something that filters down through middle management. It's approximately one lunch conversation, and a program that shames a clicker in a company that size isn't delivering private feedback — it's staging a public event.
What this actually means for how we train
If trust and appetite beat fear, and conscientious employees are the real target, two standard practices in this industry are measuring the wrong thing entirely.
Click rate is a diagnostic, not a scoreboard. A program graded purely on click rate quietly optimizes itself toward easier simulations and predictable schedules, because difficulty is a dial anyone running the program can turn. A non-click, meanwhile, can't tell you whether someone recognized the manipulation or just happened to be out of office. The behavior that actually proves recognition is the report — someone who saw the attempt, understood it, and told the team. That's the number worth building a program around.
Scoring individual people is worse than useless — it's actively counterproductive. Collapsing someone's history into a single "risk score" destroys the most useful part of the signal. An employee who never falls for a fake invoice but reliably clicks a boss-in-a-hurry email isn't "62% risky" — they're resilient to one pattern and exposed on another, and those two facts point to two completely different practice sessions. A per-tactic map preserves that nuance; a scalar score erases it, and invites exactly the kind of league-table misuse that turns a training signal into public shame. That's not a hypothetical: a well-known 2020 case where a company ran a reward-themed phishing test around the holidays, then publicly "failed" employees who clicked, made national news within days — a case study in how measurement-as-verdict destroys the trust a reporting culture depends on.
Correction works best in the moment it's needed, not three weeks later. The instant someone clicks is also the instant their mental model of "normal email" has just broken — the exact moment they're most open to learning what actually happened. Feedback delivered right there, specific and blame-free, competes favorably against anything delivered in a scheduled module weeks later.
The throughline
Every finding above points at the same idea from a different angle. The attacker who actually gets through your defenses doesn't look like a threat. They look like your coworker, your HR department, or a boss who needs one small thing before end of day. Training built entirely on fear, graded purely by clicks, and enforced through shame is preparing your people for an attacker who — according to seven years and 691 messages of evidence — barely exists.
The one who does exist is patient, polite, and dressed like someone who already has your trust. Training people to recognize that is a different job than scaring them. It's the job worth doing.
Hook Labs is the research function of Hook Security. This post is adapted from the full report, The Anatomy of Manipulation (August 2026), available on request.
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.