Signals Weekly Briefing

SIGNAL: Week 38 - Trust Falls

14 September 2026 · 8 min read · Andy
← All Signals briefings

Monday 14 September 2026 · About an 8-minute read

A thread runs through this week's stories: trust. Attackers have started borrowing the wardrobe of security itself, dressing their scams up as passkey upgrades, IT helpdesk calls and vulnerability fixes, because nothing lowers our guard quite like the belief that we are being protected. Meanwhile, three very different publications remind us that building justified trust inside an organisation (through champions, culture work and decent insider risk practice) is slow, patient, measurable work. Both halves of that equation are worth your attention this week.

When the "security upgrade" calls you

Microsoft's threat intelligence team has published detailed research on a campaign that should give every awareness lead pause. Attackers are phoning, texting and even messaging employees over Teams while posing as the IT helpdesk, claiming that the organisation is moving to passkeys and that the employee must update their sign-in "immediately to avoid disruption". The victim is walked to a convincing fake sign-in page, often on a domain that embeds the company's own name (think company-name.secure-passkey.com), where the attacker captures credentials and session tokens through adversary-in-the-middle or device-code techniques. Here is the sting: enrolling a passkey is rarely the actual goal. The passkey story is simply the pretext. Once inside, the attackers register their own authentication method for persistence and quietly work through Microsoft 365 looking for data worth taking.

What does this mean for me?

If your organisation is rolling out passkeys, or any change to how people sign in, your communications plan is now part of your attack surface, because attackers will copy it. Tell people precisely how the migration will happen, and just as precisely how it will not ("no one from IT will ever ring you and ask you to sign in somewhere on the spot"). Give your service desk a two-way verification script, so staff can authenticate the helpdesk and vice versa. And fold voice and Teams-based lures into your awareness content, because this campaign barely used email at all. The broader lesson is one behavioural scientists would recognise instantly: a well-publicised change creates a window in which change-themed requests feel plausible. Own the narrative before someone else does.

Source: Microsoft Security Blog threat research, published 9 September 2026. Passkey-themed social engineering leads to identity and cloud compromise

Copy, paste, compromised

Cisco Talos has traced a campaign, running since last October, that shows the "ClickFix" trick evolving in an interesting direction. Instead of the familiar fake CAPTCHA telling users to run a command to prove they are human, this operation targets cryptocurrency traders with a "leaked vulnerability report" describing non-existent flaws in swap services, and promises payouts up to 38 per cent higher to anyone who exploits them. The exploit? Paste a line of JavaScript into Chrome's address bar, or into a Tampermonkey browser extension. The pasted code then silently swaps deposit addresses and doctored the amounts on screen. The confirmed haul is modest so far (around 0.159 BTC, roughly ten thousand dollars, and Talos is straightforward about that), but the campaign has survived two disruption attempts and was still active in August.

What does this mean for me?

Two things stand out. First, the lure is greed and flattery rather than fear: you have been trusted with insider knowledge, and there is money in it for you. Most awareness content still assumes urgency and threat, so check whether yours covers the seductive version. Second, paste-based attacks deserve a behavioural rule as simple and repeatable as "check the sender": if you did not write it, it does not go in your address bar, your terminal or your Run box. Very few simulation programmes exercise this pathway at all, and this campaign is best read as a rehearsal for the same mechanism aimed at your finance team rather than at crypto hobbyists.

Source: Cisco Talos threat research, published 8 September 2026. ClickFix moves into the browser: cryptocurrency theft with Google-hosted C2

Social engineering keeps the crown, AI takes silver

The SANS Institute's 2026 Security Awareness and Culture Report is out, now in its eleventh year and drawing on more than 1,700 practitioners worldwide, with no vendor telemetry. Social engineering remains the most-cited human risk, but the movement is at number two: AI, up from fourth place two years ago. The report breaks that down into unauthorised generative AI use, employees "vibe coding" their way to production software, and AI agents acting without review. Three quarters of awareness teams now use AI in their own programmes. The benchmarking data is arguably the most useful part: SANS finds that meaningful behaviour change takes around three dedicated staff sustained over three to five years, and embedding lasting culture takes four or more over five to ten. There are updated salary benchmarks too, if you fancy an awkward conversation with your manager.

What does this mean for me?

This is budget-season ammunition. If you are a team of one, the honest reading is that compliance-level outcomes are your ceiling, and the report gives you independent, practitioner-sourced numbers to argue for either more headcount or more modest promises. It also confirms that AI risk now lives firmly inside the human risk portfolio: if your programme has nothing yet on shadow AI use or oversight of agent-driven work, this is the year to fix that. Usual caveat: this is a self-reported survey of practitioners, so it measures the profession's perceptions as much as the risk itself. That doesn't make it less useful for benchmarking; it just tells you where your peers are, not where the attackers are.

Source: SANS Institute practitioner survey report, released late August 2026, free with registration. SANS 2026 Security Awareness and Culture Report

Champions programmes work slowly, and almost nobody measures them

Layer 8, the UK security culture consultancy, has published its Champions Impact Report 2026, billed as the first global study dedicated to security champions programmes and built on responses and interviews from more than 100 organisations across the UK, Europe and the US. The headline findings deserve a wince and a nod in equal measure. Only 7 per cent of organisations measure their champions programme's direct impact on risk reduction, with most tracking attendance and other easy-to-count proxies, and 48 per cent still run their measurement on spreadsheets. Yet among organisations that do measure, 74 per cent report higher champion engagement over the long term, and the study finds secure behaviour adoption grows most strongly once a programme passes the three-year mark.

What does this mean for me?

If your champions network is essentially a mailing list with a logo, this report is your case for giving it a proper job. Pick a small set of behaviours tied to named organisational risks, count something about them (even roughly), and set executive expectations in years rather than quarters. The engagement finding is the quiet gem here: measurement isn't just proof for the board; it seems to be motivational fuel for the champions themselves, presumably because people stay committed to things that visibly matter. One honest note: Layer 8 sells champions programme services, so read the framing with that in mind, though the measurement gap it describes will feel painfully familiar to most of us regardless.

Source: Layer 8 practitioner research report, free to read. Layer 8 Champions Impact Report 2026

CISA rewrites its insider threat playbook for the hybrid era

CISA, the US government's cyber defence agency, has updated its Insider Threat Mitigation Guide for the first time since 2020. The refresh, announced on 9 September, adds guidance for hybrid and remote work, coverage of AI being used to manipulate and deceive employees, updated behavioural indicators that may signal growing risk, and strengthened material on the moments organisations most often fumble: visitor screening and employee departures. New case studies run through the whole framework, from defining the threat to managing it.

What does this mean for me?

Even if you are nowhere near the US, this is a free, credible framework to check your own arrangements against, and its instincts are refreshingly human. The guide treats insider risk as a people problem before a surveillance problem: notice when colleagues are struggling, involve HR and wellbeing functions early, and get the unglamorous mechanics of leavers' access right. A practical starting point is to map your own leaver process against the guide's separation guidance this quarter; in my experience, that is where the gap between policy and practice is widest, and it needs no new budget to close.

Source: US government guidance, updated 9 September 2026. CISA Insider Threat Mitigation Guide, with useful coverage from Infosecurity Magazine


 

That is the week. If one theme deserves your Monday morning, make it the first story: the more visibly we improve security, the more our improvements become costume material, and the best defence is telling people exactly what to expect from us before someone else does it less honestly. See you next week.

The CyBehave Weekly Briefing is researched and written for human risk, awareness and security culture professionals. Forward it to a colleague who would find it useful.

Get Signals in your inbox

Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.