It's wrong to focus on email, since that is simply the channel that has the largest online reach. Just like crooks used the telephone to run scams before the Internet, they can and do just as easily slide over to some other non-email messaging systems to find their marks online. As you say, this is fundamentally a human problem, brought about by how poorly certain technologies are implemented and used. For example, use of unique/disposable email addresses for individual contacts would go a long way toward identifying and eliminating phishing attempts from the start. I've done this for years, and not only does it make me difficult to phish, it allowed me to recognize when TD Ameritrade's systems were compromised and customer information was used to send stock scam spams. 2f0801daa520563f04e2234a512d5275b067e542023763beaf208bc2ac81b14d