Cloud Levante
BlogCybersecurity

10 phishing and security cases — real and simulated — that sparked real controversy

Jun 25, 20268 min read
10 phishing and security cases — real and simulated — that sparked real controversy

Cybersecurity is usually associated with technology, malware, and hackers. Yet some of the most controversial cases of recent years had nothing to do with technical vulnerabilities — they came down to something far more human: emotions.

Drills · Internal exercises
Case 01
West Midlands Trains and the fake COVID bonus
Drill

In 2021, the British rail company sent an email to around 2,500 employees thanking them for their effort during the pandemic and announcing an extraordinary payment.

When workers clicked for more details, they found there was no bonus at all. It was a phishing simulation.

What made this message especially hard to spot was the context: the workforce had just come through difficult years, with the pandemic's direct impact and personal losses among employees. The scenario was emotionally plausible, making it a highly representative case study of how social engineering works.

Case 02
Tribune Publishing and the $10,000 bonuses
Drill

Tribune Publishing sent employees an email announcing bonuses of between $5,000 and $10,000.

In reality, the company was going through layoffs, closures, and financial difficulties. The simulation triggered internal and external backlash, leading the organization to issue a statement explaining its purpose.

This case highlights something important: the effectiveness of an awareness campaign is directly tied to the context in which it's run.

Case 03
Queensland police and the fake pay rise
Drill

Thousands of Australian police officers received an email about a 5% pay rise. It was not a real negotiation, though — it was an internal phishing campaign.

What made it hard to detect was the timing: it coincided with real salary negotiations, making the message indistinguishable from an official communication. The organization decided to review the process and adjust the planning criteria for future campaigns.

Case 04
The fake Ebola alert at a university
Drill

UC Santa Cruz ran a phishing exercise simulating a health alert about a supposed Ebola case on campus. Many students and staff believed it was a real emergency.

The fact that so many people took it as real says a lot about how effective high-emotional-load scenarios are. The incident sparked a debate in the cybersecurity community about which situations are appropriate for this kind of test and how to handle follow-up communication with recipients.

Case 05
The drill that ended up at the FBI
Drill

In 2018, a phishing exercise related to the Michigan Democratic Party's technology infrastructure was so realistic that it was reported as a genuine attack.

The Democratic National Committee went as far as alerting the FBI, believing it was facing a real intrusion. Following the incident, procedures were changed to require better coordination for future security tests.

When the attacks were real

The following cases show how cybercriminals use exactly the same mechanisms as awareness exercises: messages that create anticipation, urgency, or perceived benefit. The difference is that here the goal is unauthorized access, stealing funds, or capturing credentials.

Real attacks · Cybercriminals
Case 06
The "Payroll Pirates" and payroll theft
Real attack

Microsoft identified a campaign in which attackers accessed corporate systems to change employees' bank details. The goal was to redirect payroll payments to accounts controlled by the criminals themselves.

The attackers used messages related to HR, benefits, and payroll to build credibility with victims.

Case 07
Fake pay rises to steal credentials
Real attack

For years, numerous phishing campaigns have used supposed salary reviews, benefit updates, or changes to internal policies.

Employees receive seemingly legitimate messages redirecting them to fake portals where they enter their corporate credentials. This tactic works because few topics grab immediate attention like a pay increase.

Case 08
The "Enhanced Bonus" attack
Real attack

In 2025, a campaign was detected promising an extraordinary bonus for employees. The victim received a document with a QR code, and scanning it led to a fake Microsoft page designed to capture credentials.

The campaign combined two proven tactics: the promise of a financial benefit and the use of QR codes as a redirection vector.

Case 09
Tech support as the entry point
Real attack

Some criminal groups don't even need to send emails. They impersonate employees through phone calls to the support desk and get passwords reset or new authentication devices registered.

Once inside, they change payroll data or access critical corporate systems — all without exploiting a single technical vulnerability.

Case 10
The phishing that helped trigger the DNC case
Real attack

In 2016, groups linked to Russian intelligence used phishing emails targeted at members of the US Democratic Party's inner circle. The messages mimicked legitimate login pages and successfully captured real credentials.

The incident became one of the best-known phishing cases in recent history and proved that a single email can have geopolitical consequences.

What stands out most about these ten cases is that the pattern is nearly identical in every one: a message appealing to something relevant to the recipient — a financial improvement, an urgent alert, an internal communication — that is hard to ignore.

The question worth asking isn't whether these exercises are appropriate, but something more direct: would you have spotted that it was an attack?

Awareness drills exist precisely because the answer, in many cases, is no — not for lack of ability, but because these messages are designed to be convincing. Knowing them is the best way to be prepared.

Contact

Let's talk.
We'll build the rest together.

Tell us about your case. Together we assess whether it makes sense to invest in technology, how, and where to start.

Office
Plaza San Cristóbal, 14 (ULab), 03002 Alicante, Spain

You can manage your data or opt out at any time here.