
Monday 21 September 2026 · About a 4-minute read
Hello Champions! This week has a twist. We usually tell people to watch out for messages that feel pushy or threatening. This week, every story shows the opposite trick: scams that succeed by being lovely. Here are five to share, each with a small step you can take.
Police and security agencies from Japan, the US, Australia and Germany have warned about criminal groups posing as recruiters for exciting tech jobs. They approach people online, run what feels like a real interview, then ask the candidate to download a file as part of a "coding test". The file quietly takes over their computer. More than thirty thousand computers in around a hundred countries were caught this way in under a year, and the criminals stole over ten million dollars. A separate survey found the trick running in reverse too: fraudsters applying for jobs with fake identities, and nearly every one who got caught already had a company login by the time anyone noticed.
Evidence you can use: if you are talking to hiring managers or HR about being careful with unusual candidates or too-good recruiters, these numbers make the case for you: thirty thousand computers, a hundred countries, one simple trick. A real interview never requires you to download and run a mystery file.
Learn more: The Record's report
Researchers at Aalto University in Finland watched 41 people deal with a fake scam email in a pretend workplace, then interviewed them about how it felt. Three things stood out. Most people who spotted the scam did it on gut feeling, not by working through a checklist. Even people who weren't fooled found the whole thing stressful. And some people who did the right thing by not clicking actually worried they might get in trouble for being too cautious. One person said: "I didn't know I would be this excited not to be scammed."
Try this activity: start a "catch of the week" moment with your team. Once a week, in a team chat or meeting, celebrate anyone who spotted and reported a suspicious message. Keep it light, keep it positive, and make one thing clear: nobody ever gets in trouble here for being careful.
Learn more: The study, free to read
A research team at Surfshark (a company that makes online privacy tools) showed 1,722 people a mix of real comments and computer-generated ones on pretend social media feeds. People spotted only about 4 fake accounts in every 10. Rude, aggressive fakes were caught about half the time, but friendly, agreeable ones fooled people more than 6 times in 10. The fakes that seemed most human were pleasant and unremarkable.
Talking point: share this one over coffee or in your team channel: "You can't tell a fake account by its manners. Charming and agreeable is exactly how the convincing ones behave. What makes you trust an online stranger?" It is a great conversation starter about checking who someone really is before trusting them.
Learn more: The write-up at Help Net Security
The UK's National Cyber Security Centre (the government agency that helps protect the country online) and its US and Dutch partners have exposed a spying campaign that uses a patient approach. The attackers start a chat on WhatsApp or Telegram, pretending to be someone trustworthy. They take weeks building a friendly relationship. Only then do they send a file disguised as something helpful, like antivirus software, that secretly spies on the victim's phone or computer. They even nudge people from work devices onto personal ones, where protection is weaker.
Talking point: worth sharing with your team, and at home: "A scam doesn't always start with a link. Sometimes it starts with a friendship. If an online contact you've never met sends you something to install, that's the moment to stop. Only install apps from the official app stores, no matter who's asking."
Learn more: The NCSC's announcement
Security researchers spotted a fake email circulating that pretends to be a bill from ChatGPT. It claims you owe $23.80 (about £18) and that your account will be suspended in two days unless you update your payment details. The button leads to a convincing copy of the real login page, built to steal your password. The clever part is how ordinary it feels: a small amount, a familiar name, a bit of a deadline. Nothing dramatic at all.
Try this activity: teach your team the address bar check. Next time anyone logs into something after clicking an email, pause and read the web address at the top of the browser first. Try it together on a site you all use, so everyone knows what the real address looks like. The email can lie, the button can lie, but the address bar can't.
Learn more: The write-up at Help Net Security
One person reading an address bar out loud, or celebrating a colleague's good catch, doesn't look like much. But your team copies what you do, and their families copy them. That's how a thirty-second habit ends up protecting people you'll never meet. Have a brilliant week!
Ripples is written for Security Champions and the programme leads who support them.
Subscribe and choose Ripples to receive each edition the morning it publishes.