Skip to main content
Episode 4 cover with hosts André Daus and Simon Gajdosik and the episode title 'Why You Click?'

Why You Click

Why smart people still click suspicious links. Simon and André unpack pressure, trust, fear, curiosity, fatigue, routine, and the ten-second pause that can stop one click from becoming a breach.

Key Takeaways

  • Social engineering does not test your intelligence first. It targets the moment around you.
  • Urgency, hierarchy, routine, and old habits can make a suspicious link feel like the fastest way to finish the task.
  • Personalized scams work because they borrow real details from past breaches and make the threat feel specific.
  • Password managers help, but only when domain matching is strict enough to avoid lookalike sites.
  • The practical defense is a habit: pause, verify through a trusted channel, and ask before clicking.

What this episode is about

You know the link looks strange. You click anyway. Why?

In this episode, Simon and André look at the moment before the click. Social engineering does not target intelligence first. It targets pressure, trust, fear, curiosity, fatigue, and routine. The attacker does not need you to be careless all day. They need one bad moment.

They also talk about password managers, passkeys, YubiKeys, homoglyph domains, DNS filtering, disposable browser workspaces, and the habit that matters most: pause before the click.

The moment matters

A suspicious link usually arrives inside a situation. A boss needs a deck changed before a meeting. A customer is waiting. A report is late. A system is asking for attention. Then an email appears with a link, attachment, QR code, or phone number.

That is the opening. You are not deciding in a quiet room with full attention. You are deciding while trying to finish something else.

André separates the pressure into short-term and long-term forces. Short-term pressure is the deadline in front of you. Long-term pressure is what you have learned from school, work, managers, and past consequences. If your environment rewards speed and punishes delay, attackers can use that habit against you.

Personalization raises the pressure

The episode uses a real example: an email that included André’s name, address, email, and an old password. That kind of message feels different from generic spam. It feels aimed.

The password was old and had come from a past breach, but the first reaction was still stress. That is the point. A scam does not need perfect access to create pressure. It only needs enough real detail to make you hesitate.

This is why breach checks matter. If you know where your email or old passwords appeared, you can treat those details as leaked data, not proof that the attacker is inside your current accounts.

Password managers are a signal

Simon brings up an important detail: password managers can warn you when a domain is wrong because they refuse to autofill.

That warning is useful. If the login does not appear where you expect it, stop and ask why. The service may have changed domains, or you may be on the wrong site. Either way, that moment deserves attention.

The setup matters too. Domain matching should be strict enough that credentials do not autofill on lookalike domains. Convenience helps people work, but broad matching can turn convenience into risk.

Passkeys and hardware keys

The episode briefly detours into passkeys and YubiKeys. That detour matters because authentication is changing.

Passkeys are stronger than passwords, but the storage model matters. A synced passkey in a cloud account is different from a credential stored on a hardware security key. Both can be useful. They do not have the same risk profile.

Hardware keys can also be less smooth in practice than they look in theory. Password managers, browsers, operating systems, and devices may all try to handle the same authentication flow. That friction matters because people route around security when it gets in the way.

Lookalike domains are hard

Some links are not obviously wrong. A homoglyph attack can replace a familiar letter with a different character that looks almost identical. The domain may look correct at a glance while pointing somewhere else.

The safer habit is simple: do not use the link when the message is high-risk. Open the official app, use a saved bookmark, or type the domain yourself. If the message is real, the same request should appear through a channel you already trust.

Simon also mentions DNS-level filtering, such as blocking newly created domains, suspicious top-level domains, and known malicious destinations. Tools can reduce exposure, but they do not remove the need for the pause.

Make reporting easy

Security fails when it expects full attention all day. It also fails when reporting a suspicious message takes too many steps.

If reporting is slow, people delete the message or ignore it. If asking for help feels embarrassing, people click alone. A better system makes the safe action easier than the shortcut.

That applies to teams and to families. If someone asks, “Can I open this?”, treat that as success. They paused. They asked. That is exactly the habit you want.

The ten-second pause

The “What’s Your Move” for this episode is a ten-second pause before risky clicks.

Use it for anything involving money, passwords, admin access, customer data, or MFA. Before you click, ask:

  • Did this message create urgency?
  • Does it ask me to use a link, attachment, QR code, or phone number inside the message?
  • Does it involve money, credentials, data, or access?
  • Would I feel awkward verifying it?
  • Can I verify it through a channel I already trust?

You will not catch everything. The point is to interrupt the automatic click often enough that checking becomes normal.

Frequently asked questions

  • Why do people click suspicious links?
    The episode argues that clicking is often about the moment, not intelligence. Pressure, deadlines, hierarchy, trust, fear, curiosity, fatigue, and routine all narrow attention. Attackers shape that moment so the unsafe action feels normal or urgent.
  • What does personalization change in phishing?
    Personalization makes a scam feel real. A message that uses your name, email address, phone number, an old password, or a familiar service can trigger stress before you have time to think. Breach data gives attackers material for that pressure.
  • How can password managers help?
    A password manager can refuse to autofill when the domain is wrong. That warning is useful only if domain matching is strict. If matching is too broad, a lookalike domain may still receive credentials.
  • What is a homoglyph attack?
    A homoglyph attack uses characters that look like familiar letters but are technically different. A domain can look correct at a glance while sending you to another site. This is why typing a known address or opening the official app can be safer than clicking a link.
  • What should I do when I am unsure?
    Ask. Send the message to someone you trust, use a known support channel, or open the service through a saved bookmark or official app. A second opinion is cheaper than recovering from a bad click.