
Monday 10 August 2026 | A 4-minute read
Hello Champions. Five things caught our eye this week, and every one of them gives you something concrete to run with. Grab a coffee and have a skim.
A new university study asked a question we love: if people know so much about phishing, why do they still get caught? Researchers surveyed 553 staff and students, and everyone scored well on knowledge. The difference between the people who got caught and the people who didn't came down to habits. The safest people were the ones who actually did the safe things, like reporting odd emails and using strong logins, not the ones who simply knew the theory.
Try this activity: at your next team catch-up, skip the "spot the scam" quiz and ask one question instead: "Does everyone know how to report a dodgy email, and have you ever done it?" Walk through it together once. Practising it beats knowing about it.
Learn more: the study in JCERP
A huge test involving 14 million people found that when a convincing fake scam email lands, about 5 people in 100 click it. Here's the surprising part: only about 10 in 100 report it. Everyone else spots something odd and just deletes it or moves on.
That deleted email is valuable. One report can warn the security team that the whole company is being targeted, so the person who reports is protecting hundreds of colleagues, not just themselves.
Evidence you can use: out of every 100 people who receive a convincing scam email, only about 10 report it. If you're making the case for a reporting push, or just want a line for your next team update, that number does the talking. And when someone does report, thank them out loud.
Learn more: coverage of the Fortra research
At Black Hat, one of the big security conferences, a clear theme emerged this week: scammers now mix channels. A con might start with a text message, move to WhatsApp, and end with a phone call from a voice that sounds exactly like your boss. AI makes the voices and messages very convincing.
The good news is that one simple habit beats all of it: if a request is unusual or urgent, check it through a different route you already trust. Hang up and call the person back on the number you have for them, or ask them face to face.
Talking point: share this phrase with your team: "unusual request? Check it another way." Remind them it applies to texts and calls, not just email.
Learn more: lessons from Black Hat
This one sounds like science fiction but it's happening now. Criminals are using AI-generated video and audio to pass job interviews, get hired into remote roles, and log in on day one as an employee. Investigators in the US found one group that used stolen identities to get jobs at more than 100 companies.
If you're ever in a video call that feels a bit off, there's a charming low-tech check: ask the person to wave a hand in front of their face. Live fake video still struggles with that.
Talking point: if anyone in your team is involved in hiring, especially for remote roles, mention this story to them. It's a great conversation starter, and being aware is most of the battle.
Learn more: the story at The Next Web
A thoughtful piece this week argued that security culture isn't built by policies or campaigns. It's built by trust, and trust is built by keeping your word. That's brilliant news for you, because as a Champion your superpower isn't technical knowledge. It's being the approachable, reliable person your colleagues can ask without feeling silly.
Try this activity: this week, when someone asks you a security question, thank them for asking before anything else. The easier it feels to ask you, the safer your team becomes.
Learn more: the essay in Security Management
One thought to leave you with: the safest teams aren't the ones that never make mistakes. They're the ones where people speak up quickly. Every report, every question and every thank-you is a small stone in the water. See you next Monday.
Subscribe and choose Ripples to receive each edition the morning it publishes.