The emails of two of my colleagues were hacked recently. You might wonder, what does this have to do with me and I’m about to tell you why you shouldn’t just scroll past this one.
I opened my email and saw an RFP (Request for Proposal) from a colleague who was planning to engage my services to work with one of her clients. As an Independent consultant from time to time we use this as a tool to scope work. There was a “secure” link to click to open up the RFP but, before I clicked it, I checked the sender address to make sure it wasn’t a spoofed lookalike with a swapped letter you have to squint to catch. It was her email…
So I clicked. My malware flagged the content and blocked it. But because I believed it was hers and trusted the sender, I overrode the warning; the next page asked me to type in my email and I did. A second warning came up, and when that happened, I did what my gut was nudging me to do in the first place. To email her to check. After emailing her, she informed me that her account had been hacked earlier that day, and that she had sent a warning to her entire list. Unfortunately, that warning was sitting in my spam folder, unread.
My previous verification training worked exactly as designed, but it protected me from nothing. I was checking whether the address was really hers. It was. The account behind that real address had been hijacked, so every normal check I knew to run came back verified, but I was open for an attack.
The decision wasn’t one choice. It was three.
When I sat to write what I thought would be a simple warning letter about hackers, I began to analyze why I clicked. I realized I hadn’t made a single decision at all. Three different parts of me weighed in, and they didn’t all agree. Follow me on this.
Cognitively, I understand phishing scams. I know to check a sender, and never click links or put in email addresses or passwords. I did, and that check told me to proceed because I knew the sender and had conversations with her recently about working together with one of her clients.
My gut ran a different read. A quiet flag with no evidence behind it, just a sense that I should reach out to her first to ask if the email was from her.
Then the third process operating was how I’m naturally wired to move. My instinct scanned the typical processes, trusted my colleague, confirmed her address, and said go. That same instinct is what lets me act fast and decisively on a hundred legitimate opportunities.
Two of the three lined up. My knowledge and my instinct both pointed at the click, reinforced by a name I trusted. My gut was the lone objector, and it lost the vote.
This is what the three parts of the mind actually are. The cognitive, what you know. The affective, what you feel. The conative, how you instinctively act. Every real decision runs through all three, and we pretend it runs through only the first one. We tell ourselves we chose logically. Most of the time, the other two got there first and logic showed up to justify the call.
Why the two that agreed were wrong
The reason this reaches far past my inbox is what artificial intelligence has done to that trusted name.
A voice can be cloned from a few seconds of audio. A face can be generated for a live video call. A writing style can be lifted from a handful of old emails. The single signal every one of us is built to trust, this came from someone I know, has become the easiest thing in the world to counterfeit. The trusted source is what makes a team fast and human, and it has quietly turned into the hacker’s way in.
My instinct trusted the source of the email, and I verified that source, but the source was the problem.
Roughly 3.4 billion phishing emails go out every day. Phishing shows up in about a third of all confirmed breaches. The median time between opening one and clicking is 21 seconds. Almost nobody analyzes these. People react, the way I did, with instinct and a trusted name doing the driving while the quieter signal gets outvoted.
Now Think About Your Team
Every person who reports to you runs that same three-part machinery every time they make a fast call under pressure. What they know, what they feel, and how they are instinctively wired to act. Most leaders pour everything into the first one, what someone knows. They provide more training to sharpen awareness, create tighter policies, all aimed at the cognitive layer.
Meanwhile, the decision often gets made in the other two, the layers almost no one accounts for. When your people move too fast on the wrong email, or freeze on the right one, you are watching their affective and conative wiring make a call their training never measured.
You can’t lead what you can’t see. Knowing which of the three parts is actually driving your people’s decisions. The question is whether you think it’s just a soft skill or a nice-to-have, or a necessity. This decides whether a well-trained team is actually a protected one.
Next week, I’m going straight at the human layer of these attacks. Why trusted-source verification breaks in an AI world, and where the sharpest leaders are deliberately building good friction back into the decisions their people would rather make on instinct. The team may resist the additional friction, right up until the day it saves them.
For now, think about this question. On your team, which part of the mind is making the decisions that matter most, and would you even know if it changed?
If that question keeps you up at night and you want to talk through what it looks like inside your own organization, reach out to me at support@aliciacouri.com. I’m always up for the conversation.