Ripples · Champions Weekly Briefing

Week 38: Trust Falls

14 September 2026 · 5 min read · Andy
← All Ripples editions

Monday 14 September 2026 · About a 4-minute read

Hello champions! This week's stories all circle one idea: scammers have worked out that the easiest way past our defences is to dress up as the defences themselves. Fake IT calls, fake security fixes, fake upgrades. Here are five things worth knowing, each with something small you can do about it this week.

1. That phone call about your "sign-in upgrade" might be a thief

Microsoft (the company behind Windows and Office) has warned about criminals ringing and messaging people at work, pretending to be the IT helpdesk. The story is clever: your company is moving to passkeys (a newer way to sign in that uses your fingerprint, face, or a PIN instead of a password), and you must update your sign-in right now or be locked out. They then send you to a fake sign-in page, sometimes even with your company's name in the web address, and steal your login details the moment you type them in. The "upgrade" is just the costume. What they want is your account.

Talking point: Share this line with your team this week: "IT will never ring you out of the blue and ask you to sign in somewhere or change how you log in on the spot. If someone does, hang up and check through a channel you already trust."

Learn more: Microsoft's write-up of the scam

2. Never paste text someone else gives you into your browser

Researchers at Cisco (a large technology company) found scammers offering people a "secret trick" for getting better rates when swapping digital currency. All you had to do was copy a special line of text and paste it into the address bar at the top of your web browser. That text was actually computer code, and once pasted, it quietly changed account details on screen so that money went to the thieves instead. The same move is turning up in fake error messages and fake "fixes" too.

Try this activity: At your next team huddle, take two minutes to agree a simple rule: if any website, pop-up or message tells you to copy and paste something into your browser or your computer to fix a problem or unlock a reward, stop and check with IT first. Ask if anyone has already seen one. You may be surprised.

Learn more: Cisco's research on the copy-paste scam

3. The oldest trick is still the biggest risk (and AI is now second)

SANS, one of the world's largest security training organisations, asked more than 1,700 people who run security awareness programmes worldwide what worries them most. Top of the list, still, is plain human trickery: scam emails, scam texts and scam calls that talk people into doing something unwise. The climber is new, though. Risky use of AI tools at work, like pasting confidential information into chatbots or trusting AI answers without checking them, has jumped to second place.

Evidence you can use: "In a survey of more than 1,700 security professionals worldwide, tricks aimed at people were the number one risk, and risky use of AI tools has climbed to number two." Handy the next time someone asks why champions bother.

Learn more: The SANS 2026 report

4. Champion programmes change workplaces, slowly and surely

Layer 8, a UK company that helps organisations run champion programmes, has studied more than 100 organisations with networks just like yours, the first global study of its kind. Two findings stand out. Most workplace habits improve once a programme has been running for about three years, so steady beats spectacular. And only about 7 organisations in every 100 track whether their programme is actually reducing risk; yet in the ones that do, roughly 3 in 4 find their champions stay enthusiastic longer. Counting something keeps people going.

Try this activity: Pick one simple number to track this month: teammates you have chatted to about security, questions you have been asked, or people who came to something you ran. Write it down and compare it next month. Programme leads, ask each of your champions to do the same.

Learn more: The Layer 8 Champions Impact Report

5. A fresh, free guide to risks from inside an organisation

CISA, the American government agency that helps protect businesses from cyberattacks (a bit like the UK's National Cyber Security Centre), has refreshed its free guide on risks that come from inside organisations. That sounds sinister, but most of it is everyday stuff: honest mistakes, people being manipulated by outsiders, and former staff keeping access to systems long after they have left. The update covers working from home and how AI is now used to deceive people, and its advice is warm rather than suspicious: look out for colleagues and get the basics right when someone moves on.

Talking point: Try this at your next team chat: "When someone last left our team, did their access to our systems and shared logins leave with them?" If nobody knows, that is a useful discovery, and worth a friendly nudge to your manager or IT.

Learn more: CISA's updated guide

That's your lot for this week. None of these actions takes more than a few minutes, but every conversation you start makes the next scam a little less likely to land on someone unprepared. Drop one pebble this week and let it spread.

See you next Monday!

Get Ripples in your inbox

Subscribe and choose Ripples to receive each edition the morning it publishes.