I'm going to prove a point and you're going to help me.
If you're a member of the information security and/or cybersecurity profession, and you have clicked on a phish in the last, say, five years, share this post. If you have not, star this post.
Someone's trying to say that you can punish people out of clicking on scam links and I say that not only can you NOT prevent phishing by punishing people, but the most skilled #infosec and #cybersecurity people in the world can and do get phished as well.
As the security backlash has grown against Microsoft's Recall feature, it at least seemed the screenshots it silently takes every 5 seconds are stored such that a hacker would need administrator privileges to access them.
Turns out even that safeguard is easily bypassed.
https://www.wired.com/story/microsoft-windows-recall-privilege-escalation/