The most convincing threats rarely look dangerous. They look exactly like something you'd already trust.
That's not a coincidence, and it's not a failure of anyone's judgement either. It's the entire design principle behind a spoofing attack, and there's real, well-documented psychology explaining exactly why it works, even on people who know better.

The numbers behind it
Phishing and spoofing aren't a fringe problem. CISA reported that phishing emails were associated with more than 90% of successful cyberattacks. Separately, a broad business survey found that 92% of organisations had fallen victim to a phishing attack. These aren't attacks succeeding because of some rare technical flaw, they're succeeding because of how the human brain processes trust.
Why the brain falls for it before it even registers a threat
Spoofing is impersonation: hiding malicious intent behind a familiar name, number, or website. Phishing is usually what follows once that impersonation has worked, the two chain together. What makes the impersonation effective comes down to a small number of well-studied psychological triggers:
None of these are failures of intelligence or training. They're the same mental shortcuts that let people function efficiently day to day, being repurposed against them.
AI has made this measurably harder to catch
The classic advice, watch for typos, awkward phrasing, generic greetings, is losing its usefulness. Attackers can now generate personalised messages at scale that mimic a specific colleague or executive's actual writing style, removing most of the old tells that used to make spoofed messages easier to spot on sight. The visual and linguistic familiarity that makes spoofing effective in the first place is only getting harder to distinguish from the real thing.
What this looked like in a real SharePoint environment
This is exactly the pattern GTconsult's security team walked through in a conversation about a real SharePoint spoofing case: an email crafted to look precisely like official Microsoft communication, professional formatting, familiar branding, even though the sending address itself didn't hold up under a second look. The attack didn't need to be technically sophisticated to be dangerous, it needed to look like something the recipient already trusted.
Worth being upfront about: that conversation is a little dated now, the specific vulnerability discussed has since been patched, and if you're checking your own environment today, don't treat its patch status as current. What hasn't dated at all is the pattern it illustrates, the email in that example wasn't dangerous because it looked dangerous. It was dangerous because it looked exactly like something worth trusting, which is the entire point of this piece.
What actually helps
Since the trigger is psychological rather than technical, the fix has to work the same way:
Frequently asked questions
Why do spoofing attacks work even on careful, experienced people?
Because they target psychological shortcuts, familiarity, authority, and urgency, that operate faster than conscious evaluation. These aren't weaknesses specific to certain people, they're general features of how human judgement works under pressure.
What's the difference between spoofing and phishing?
Spoofing is impersonation, disguising a message, number, or website to look like it comes from a trusted source. Phishing is the exploitation that typically follows, using that impersonation to extract credentials, payments, or access. The two usually work together as a chain.
Has AI made spoofing attacks harder to detect?
Yes. AI tools now let attackers generate personalised messages that mimic a specific person's writing style at scale, removing many of the typos and awkward phrasing that used to make spoofed messages easier to spot.
What's the single most effective defence against spoofing?
Verifying through a separate, already-trusted channel rather than responding within the same message thread. It bypasses the urgency and familiarity triggers the attack is built around entirely.
Want a second opinion on whether your environment would catch this kind of attack?
