Report: Employees Are Overconfident in Their Ability to Spot Scams

KnowBe4 Team | Aug 12, 2026

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.

“Findings suggest employee confidence is rooted in their ability to spot traditional fraud tactics,” the report says. “A large majority (78% of respondents) said they were confident they could identify a fraudulent payment request at work. But they're still looking for the traditional phishing tactics - such a typos or fake email addresses - they were trained to recognize years ago. 70% rank typos, fonts, or  grammatical errors as their No. 1 warning sign.”

While typos and grammatical errors are still red flags, employees need to be aware that many phishing emails now have perfect spelling and grammar. Users should be on the lookout for other signs of social engineering as well.

“Every other cue trails well behind: 25% cite an unfamiliar sender, 22% [cite] unusual urgency, and 16% [cite] a suspicious invoice,” the researchers write. “Even unusual urgency - the pressure tactic common to executive-impersonation and payment-diversion scams - ranks near the bottom. The reliance on old signals is sharpest among the youngest workers: Gen Z ranks grammar mistakes as a top warning sign more than any other generation (82%), compared with 50% of Baby Boomers.”

Employees are also lagging in awareness of established social engineering techniques. Most (81%) respondents said they would trust a payment request that appeared in an existing email thread, even though attackers have been hijacking existing email threads for years to launch business email compromise (BEC) attacks.

Security awareness training can give your organization an essential layer of defense by teaching your employees to thwart evolving social engineering tactics. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce human risk. Trustmi has the story.

Secure Your Human and AI Workforce

Transform your attack surface into your strongest defense with our AI-driven platform. Request a personalized demo to see how to mitigate social engineering, manage agent risk, and automate your phishing response.

Get a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.