Phishing is no longer a specialist skillset - it’s researchable, reproducible, and for criminals, even rentable. For my dissertation project, I built a phishing simulation tool from scratch and ran it with real participants. Even in that controlled, academic setting, people still fell for the lures. That was a sobering lesson… If I could create this as a student, then what does it mean to an attacker with malicious intentions?