@0x56
Evil doesn't play a part in this equation. That implies a phishing program is designed to "get you" and not help you. This is no more evil than fire-team training the U.S. Marine Corps go through.
The malicious actors really don't care about your feels, and in order to condition/train individuals properly you need to utilize the same tactics that they are going to use... otherwise your security program is literally checking a box, and nothing to do with actual hardwning your userbase.