Admitting that to yourself is a huge step forward in being able to detect it. Believing yourself immune increases your chances of being spearfished.
I bet there are some that are immune. But yes, 99% of employees can be phished.
Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale.
Assuming humans won't do stupid things 100% of the time is never an effective security control.
It’s not a solution to the problem, but it certainly helps.
My gut feeling is for engineers, the phising training that most companies use is wholly ineffective at doing anything, and in particular it is especially ineffective against targeted attacks. But i have yet to see any research one way or another.
I suspect less technical users might benefit from such training a bit more (but still not that much)
I also worry that the emails might not represent real attack emails, and we end up training users to identify the test emails but not real attack emails.
(Not that i got any better solution)
All of them.
In short, I do not know my ebay password, but I could have fallen for this phishing attack.
Nobody is perfect.
Everyone is vulnerable given time/effort.