
Cybersecurity is usually associated with technology, malware, and hackers. Yet some of the most controversial cases of recent years had nothing to do with technical vulnerabilities — they came down to something far more human: emotions.
In 2021, the British rail company sent an email to around 2,500 employees thanking them for their effort during the pandemic and announcing an extraordinary payment.
When workers clicked for more details, they found there was no bonus at all. It was a phishing simulation.
What made this message especially hard to spot was the context: the workforce had just come through difficult years, with the pandemic's direct impact and personal losses among employees. The scenario was emotionally plausible, making it a highly representative case study of how social engineering works.
Tribune Publishing sent employees an email announcing bonuses of between $5,000 and $10,000.
In reality, the company was going through layoffs, closures, and financial difficulties. The simulation triggered internal and external backlash, leading the organization to issue a statement explaining its purpose.
This case highlights something important: the effectiveness of an awareness campaign is directly tied to the context in which it's run.
Thousands of Australian police officers received an email about a 5% pay rise. It was not a real negotiation, though — it was an internal phishing campaign.
What made it hard to detect was the timing: it coincided with real salary negotiations, making the message indistinguishable from an official communication. The organization decided to review the process and adjust the planning criteria for future campaigns.
UC Santa Cruz ran a phishing exercise simulating a health alert about a supposed Ebola case on campus. Many students and staff believed it was a real emergency.
The fact that so many people took it as real says a lot about how effective high-emotional-load scenarios are. The incident sparked a debate in the cybersecurity community about which situations are appropriate for this kind of test and how to handle follow-up communication with recipients.
In 2018, a phishing exercise related to the Michigan Democratic Party's technology infrastructure was so realistic that it was reported as a genuine attack.
The Democratic National Committee went as far as alerting the FBI, believing it was facing a real intrusion. Following the incident, procedures were changed to require better coordination for future security tests.
The following cases show how cybercriminals use exactly the same mechanisms as awareness exercises: messages that create anticipation, urgency, or perceived benefit. The difference is that here the goal is unauthorized access, stealing funds, or capturing credentials.
Microsoft identified a campaign in which attackers accessed corporate systems to change employees' bank details. The goal was to redirect payroll payments to accounts controlled by the criminals themselves.
The attackers used messages related to HR, benefits, and payroll to build credibility with victims.
For years, numerous phishing campaigns have used supposed salary reviews, benefit updates, or changes to internal policies.
Employees receive seemingly legitimate messages redirecting them to fake portals where they enter their corporate credentials. This tactic works because few topics grab immediate attention like a pay increase.
In 2025, a campaign was detected promising an extraordinary bonus for employees. The victim received a document with a QR code, and scanning it led to a fake Microsoft page designed to capture credentials.
The campaign combined two proven tactics: the promise of a financial benefit and the use of QR codes as a redirection vector.
Some criminal groups don't even need to send emails. They impersonate employees through phone calls to the support desk and get passwords reset or new authentication devices registered.
Once inside, they change payroll data or access critical corporate systems — all without exploiting a single technical vulnerability.
In 2016, groups linked to Russian intelligence used phishing emails targeted at members of the US Democratic Party's inner circle. The messages mimicked legitimate login pages and successfully captured real credentials.
The incident became one of the best-known phishing cases in recent history and proved that a single email can have geopolitical consequences.
What stands out most about these ten cases is that the pattern is nearly identical in every one: a message appealing to something relevant to the recipient — a financial improvement, an urgent alert, an internal communication — that is hard to ignore.
The question worth asking isn't whether these exercises are appropriate, but something more direct: would you have spotted that it was an attack?
Awareness drills exist precisely because the answer, in many cases, is no — not for lack of ability, but because these messages are designed to be convincing. Knowing them is the best way to be prepared.
Tell us about your case. Together we assess whether it makes sense to invest in technology, how, and where to start.