Four months of pandemic phishing have produced a great deal of commentary about criminals exploiting a crisis and almost no useful advice. The commentary is true and not very interesting. What is interesting is the mechanism, because it exposes a structural weakness in how most organisations defend against social engineering. The technique has not changed at all since January. What changed is the supply of pretexts. A phishing lure works when it arrives in the same week the recipient is genuinely expecting a message about that subject, and since February the news has been manufacturing those weeks at a rate no awareness programme can track.
The wave pattern, in order
Run back through the year and the sequence is almost perfectly aligned with announcements. February and early March brought health authority advisories and case maps. Late March brought "our office is closed, here is the new process" and a surge of credential pages imitating remote access portals. April brought government support schemes, deferrals and relief applications, aimed squarely at finance teams who were genuinely filling in unfamiliar forms. April and May brought payroll and human resources lures: salary adjustment letters, furlough notices, contract amendments, all of which employees were actually receiving. June brought return-to-office logistics, testing appointments and permits. This month it is travel resumption and treatment news. Each wave was plausible because the real version was in the recipient's inbox the same week. That is the whole trick. Training material that teaches people to be suspicious of unexpected messages fails when the message is entirely expected.
Three attacks that matter, and only one looks like phishing
Strip out the noise and most of the actual loss in this period came from three things. Credential harvesting against the identity provider. Not a clumsy imitation of a bank, but a pixel-accurate copy of your own sign-in page, frequently a live proxy of the real one, so the victim authenticates successfully, sees their actual mailbox, and notices nothing. Where the proxy also relays the second factor in real time, the attacker obtains a working session. Payment and mandate fraud. A supplier's bank details change, explained by a sentence everybody currently accepts without thinking: our finance team is working remotely and our usual account is not accessible. Four months of genuine disruption has made the single most useful fraud excuse in history completely unremarkable. Consent and authorisation abuse. Rather than stealing a password, the attacker asks the user to approve an application's access to their mail and files, or repeatedly triggers approval prompts until a tired person accepts one. Neither of these is defeated by a stronger password, and neither looks like the phishing in the training deck.
Why the awareness numbers are misleading
Most organisations measure their programme by simulation click rate, and a falling click rate is being reported as improved resilience this year. It mostly is not. Simulations teach recognition of simulations. They are sent by the same tool, from the same sort of domain, with the same tells, and a workforce learns the pattern rather than the principle. A novel pretext arriving in a real week of genuine confusion performs very differently, and the gap between simulated and real performance widens precisely when events are moving fast. Two better measures exist. The first is the report rate: what proportion of people who received a real malicious message told somebody. The second is time to containment: how long between the first report and the message being removed from every other mailbox. Both measure the system rather than the individual, and both can be improved by spending money, which click rate cannot. The consequence for strategy is the important part. If the pretext catalogue refreshes weekly, recognition cannot be the primary control. Process has to be.
Define the irreversible actions and protect those
The defence that survives a pretext nobody has seen before is a short, explicit list of actions that cannot be completed on the strength of a message, whatever the message says or who appears to have sent it. Keep the list to about six: releasing a payment above a threshold, changing supplier or employee bank details, entering credentials anywhere other than the normal single sign-on flow, re-enrolling or resetting a multi-factor device, creating mail forwarding to an external address, and granting an application access to company data. For each one, the rule is the same and it is not "be careful". Verify out of band, on a number already held in the master record, never a number in the message, and record who verified and when. Where possible, remove the ability to do it alone: two people for bank detail changes, an approver who is not the requester for payments, administrators unable to reset their own second factor. Six controlled actions and a callback rule will outperform a year of awareness content, because they do not depend on anyone recognising anything.
Name the sensitive actions
Cover payment, account details, authentication reset and data-access changes.
Verify independently
Use an established contact route, with an independent approver where required.
Report and contain
Give staff a reporting path and measure response and containment with clear definitions.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for Social Engineering Defense Program
- Write the irreversible-actions list and the out-of-band verification rule, and have an executive sign it. Short, specific and mandatory beats comprehensive and advisory.
- Verify only against numbers already in the master record. The contact details in the request are part of the attack; this single discipline stops most mandate fraud.
- Measure report rate and time to containment, not click rate. Publish both monthly, and treat a rising report rate as success even when it means more false alarms.
- Give people a one-click report button, respond to every report, and tell the reporter what happened. Feedback is what sustains reporting; silence kills it within a quarter.
- Disable end-user application consent and alert on new mail forwarding rules. Two configuration changes that close the two attacks awareness training does not cover.
- Turn off legacy authentication and strengthen the second factor for administrators and finance. Prompt-based approval is the weakest common form; hardware keys or codes for the accounts that matter.
- Tag external mail and publish your own mail authentication records. Cheap, unexciting, and it removes an entire class of impersonation.
- Run simulations quarterly, never punitively, and vary the channel. If the programme creates fear of being blamed, people stop reporting, and reporting is the control you actually need.
The Regional Angle
Four things are specific to this market, and the first sits outside every control you have bought. A very large share of commercial communication here happens on messaging apps. Purchase orders arrive as photographs, approvals are given as voice notes, invoices are forwarded in chats, and bank details are exchanged in the same thread. None of that passes a mail gateway, none of it is authenticated, none of it is logged, and none of it is retained in a way you could investigate. Add the regional norm of frequently changing mobile numbers, where a new SIM is unremarkable, and "this is my new number, please send the payment to the updated account" becomes an entirely credible message. Decide which transactions may originate on a messaging app, state that payment instructions never may, and put that in writing to suppliers and customers as well as staff. Second, the workforce here is unusually exposed to recruitment fraud this year. Redundancies are linked to residency, and a person whose visa depends on employment will engage with a job offer they would otherwise ignore. Criminals are harvesting passport copies, identity documents and fees from people at their most vulnerable, often while impersonating well-known regional employers. That is both a duty-of-care issue for your own staff and a brand problem: check periodically whether your company name is being used in fake recruitment advertisements, tell candidates you never charge fees, and give departing employees a short written warning about it in the exit pack. Third, look at the shared mailboxes. Trade licence renewals, establishment card notices, immigration fee demands and municipality correspondence typically land in a generic address monitored by an administrator or a public relations officer, with a password several people know and no second factor. It is the highest-value, least-protected mailbox in the company, and it receives exactly the kind of official-looking payment demand that is hardest to challenge. Put multi-factor authentication on shared mailboxes, convert them to delegated access under named accounts, and route all government fee payments through the same verification rule as any other payment. Fourth, acknowledge the social cost of verification. In hierarchical and family-owned organisations, a junior accountant who telephones to check whether the chairman really sent an instruction is risking a rebuke, and that is why the control fails in practice. The fix is not training; it is a written, signed policy that requires the callback regardless of seniority, so that the employee is following a rule rather than expressing doubt. Give people the sentence to say and the authority to say it.
The objection worth taking seriously
The strongest objection is that this discussion, like most of the industry's, ends up making the user the control. Four months into a pandemic, with people working from bedrooms alongside children, worrying about their jobs and processing genuine messages about testing, relief and salary changes, the expectation that they will reliably distinguish a real payroll notice from a fake one is not a security strategy. It is an alibi, and the punitive simulation programmes some organisations have run this year have done real damage to the reporting culture they depend on. The second objection runs the other way, and deserves an answer. Process controls have a cost. Out-of-band verification on every bank detail change slows the supplier onboarding that the business is chasing, two-person approval consumes scarce finance capacity, and there is a fair argument that the pandemic phishing wave has been more loudly reported than it has been costly, with the actual losses still concentrated in the same unglamorous causes as 2019. That is why the list is six items rather than sixty. Bound the friction deliberately: a small number of irreversible actions, protected absolutely, and everything else left to run at commercial speed. That configuration is affordable, it does not depend on anyone recognising a lure they have never seen, and it keeps working when the next crisis rewrites the pretext catalogue in a fortnight.
Common Questions
Does multi-factor authentication stop this?
It stops password reuse and simple credential theft, which is most of the volume. It does not stop real-time proxy pages, consent abuse or approval fatigue, which is where the sophisticated attacks now sit.
Should we increase simulation frequency?
Quarterly, varied, and never used as a disciplinary instrument. Beyond that the returns fall quickly, and the programme starts to suppress reporting.
How do we protect people who do not use email much?
With process rather than training. Operational and site staff are reached on messaging apps and by phone, so the verification rule has to cover those channels explicitly.
What should we expect over the next twelve months?
Expect the pretext to follow the news: vaccine and treatment announcements, travel resumption, return-to-office logistics and redundancy administration will each generate their own wave. Expect more attacks aimed at authorisation rather than passwords, because that is where multi-factor adoption has pushed the attackers. Expect banks and regulators to start mandating callback verification for mandate changes. And expect at least one large regional loss this year to be traced to an instruction that arrived on a messaging app and was never verified.
Social Engineering Defense Program — we define the irreversible actions, build the verification rule that protects them, and measure reporting and containment instead of click rates.
