I spent 9 hours on a Saturday in March fixing one phishing email that got past our filter
Found out the attacker spoofed our CFO's name but used a domain with a Cyrillic 'a' that looked identical, and our own help desk had already clicked it twice before flagging it. Now I want to know, does anyone else think user training is mostly a waste when the lookalike domains are this good, or is there a tool under $500 that actually catches this?