August 16, 2026 ยท by David Gilbert ยท 4 min read ยท Cyber Security

Why I Still Get Caught Out Sometimes (Yes, Really)

It's a slightly uncomfortable thing to admit publicly, but I think it's a more useful post than another generic warning list: a genuinely convincing scam attempt nearly got past me recently, despite this literally being part of what I advise other people on for a living. Here's what happened, and why I think being honest about this matters more than pretending it can't happen to someone like me.

What Actually Happened

A message arrived that appeared to be from a service I genuinely use, referencing a real, plausible account issue, with a tone and layout that matched what I'd actually expect from that company. I was busy, slightly distracted, and a good two clicks into responding before something โ€” I genuinely can't pinpoint exactly what โ€” made me pause and check independently rather than just continuing through the flow the message was steering me toward.

The Specific Thing That Made Me Pause

If I'm honest, it wasn't a confident, expert-level "I spotted the tell" moment. It was a vague, nagging feeling that something was slightly off in the timing โ€” I didn't recall the underlying account issue it referenced being genuinely outstanding. That small, easy-to-ignore hesitation was the entire difference between catching it and not catching it, and that's exactly the uncomfortable, important part of this story.

Why Even Careful, Knowledgeable People Are Genuinely Not Immune

Modern scams are specifically designed to exploit exactly the moments when anyone, regardless of expertise, is busy, slightly distracted, or processing several things simultaneously โ€” which describes most of us, most days, including people who professionally know better and advise others on exactly this topic. Expertise reduces how often you fall for something. It doesn't reduce it to zero, and pretending otherwise, even quietly to myself, would be exactly the kind of overconfidence that actually increases real risk over time.

What I Actually Did Right, Despite the Near Miss

I didn't act purely on instinct or rush to definitively decide either way in the moment. I went and verified independently โ€” checking the actual account directly, completely separately from anything in the suspicious message โ€” before doing anything the message itself was asking for. That single habit, verify independently before acting, is what actually saved me, not any special, expert ability to spot a fake by inspection alone.

Why I'm Telling This Story Publicly

A lot of cyber security advice implicitly suggests that getting caught out reflects carelessness or low awareness on the part of the person who fell for it. I think that framing is actually counterproductive, and arguably a little unfair โ€” it discourages honest reporting and makes people feel foolish for something that's actually a structural, systemic risk, not a personal failing unique to less careful or less informed people.

What I'd Want Anyone Reading This to Take Away

The goal isn't becoming someone who can perfectly spot every scam by inspection alone, because that's an unrealistic standard nobody, including security professionals, genuinely meets consistently. The realistic, achievable goal is building habits โ€” independent verification, healthy hesitation before acting on urgency โ€” robust enough to catch you even on your most distracted, busiest day, which is exactly the day a real scam is actually most likely to succeed against anyone.

The Honest Bottom Line

If someone who does this for a living can come this close, anyone can, on the right day, at the right level of distraction. That's not a reason to despair. It's the actual argument for building independent-verification habits so solid they don't depend on your alertness that particular day โ€” because your alertness, mine included, will occasionally not be at its best, on exactly the day it matters most.