THE SHORT ANSWER

Scams can work because people make decisions with limited time, attention and information. A deceptive request may combine urgency, authority, fear, scarcity, reward, familiarity or social proof. These pressures can narrow attention before the claim is independently checked.

Pressure can interrupt ordinary checking

Signal and useful pause
SignalWhat it tries to changeUseful response
UrgencyYour available timeCreate a pause and use a known channel
AuthorityYour willingness to questionVerify role and request separately
FearYour attention to consequencesName the threat, then check the source
Reward or scarcityYour tolerance for uncertaintyVerify before paying or sharing data

Familiar names, branding, language and context can make a request feel routine. None is proof of identity by itself.

Evidence & context: United States Federal Trade Commission

Design and context matter

People are more vulnerable when distracted, tired, isolated, rushed or handling an unfamiliar process. Attackers can also possess real personal or business details. Blaming the person who was deceived hides the conditions an organization can improve.

Restore time, channel and choice

  • Time: stop the deadline from controlling the decision.
  • Channel: leave the incoming message and initiate contact through a known route.
  • Choice: involve another person when the consequence is high.

A genuine colleague or provider should tolerate proportionate verification for a consequential request.

Notice what the message is trying to make you feel

Before judging the claim, name the pressure: rushed, afraid, excited, obliged or embarrassed. Then ask questions that reveal assumptions and verify the request outside the conversation that delivered it.

Sources & further reading

  1. How To Avoid a Government Impersonation Scam

    United States Federal Trade Commission. Official consumer guidance on urgency, payment demands, caller-ID limits and contacting an organization through a known channel. Agency examples and reporting routes are United States-specific.

  2. Phishing Guidance: Stopping the Attack Cycle at Phase One

    Cybersecurity and Infrastructure Security Agency. Current defensive guidance on phishing resistance, MFA and organisational controls. Specific authentication choices depend on service support and risk.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗