
Monday 21 September 2026 · About a 9-minute read
The oldest advice in security awareness is to watch out for things that look suspicious. This week's research and advisories point somewhere more uncomfortable: the attacks working best right now are the ones that look warm. A friendly recruiter with a genuine-sounding role. A polite, agreeable commenter. A contact who spends weeks building rapport before asking anything of you. Charm, it turns out, is a delivery mechanism, and this week we have evidence of it from five different directions.
Two pieces landed this week that, read together, should make anyone responsible for human risk look hard at their organisation's hiring pipeline.
First, an international advisory coordinated by Japan's National Police Agency alongside the FBI, the US Defense Department, and agencies in Australia and Germany, covered by The Record on 18 September. It details the North Korean "WaterPlum" campaign (you may know it as "Contagious Interview"), in which actors pose as recruiters for AI and blockchain firms, approach developers and IT professionals through social media and freelance platforms, and ask candidates to download files as part of a coding test or interview task. Between December 2025 and July 2026, the campaign infected more than 30,000 devices across roughly 100 countries, compromised around 7,000 cryptocurrency wallets and stole an estimated $10.5 million. The group now uses AI face-swapping in live video interviews.
Second, identity firm HYPR released its State of HR Identity Fraud Detection report, which Help Net Security covered the same day. The headline claim is striking: among HR leaders who caught a fraudulent hire, 98% said the fake employee had already been issued company credentials by the time they detected it. Meanwhile, 96% of leaders remained confident their organisation would catch candidate fraud. The usual caveats apply, since HYPR sells identity verification and the article gives little methodological detail, but the overconfidence gap it describes rings true against the WaterPlum picture.
The point is the symmetry. Attackers impersonate recruiters to compromise your staff, and impersonate candidates to get inside your payroll. Recruitment, an activity built entirely on strangers extending trust to each other under time pressure, is now an attack surface in its own right.
What does this mean for me? Bring HR and talent acquisition into your human risk programme as a priority audience, not an afterthought. Interviewers need a simple, explicit norm: no legitimate hiring process requires a candidate to run downloaded code outside a sandboxed platform, and no legitimate candidate should object to identity checks before credentials are issued. For the workforce side, remember that many of your employees are also job seekers, often on personal devices where your controls cannot see. A short piece of guidance on recruitment scams, framed as protecting their careers rather than your network, will land better than most phishing modules this quarter.
Sources: The Record, 18 September 2026 · Help Net Security on HYPR's report, 18 September 2026
A peer-reviewed study from Aalto University, presented at SOUPS (the Symposium on Usable Privacy and Security, the field's leading venue for research on how real people experience security) and picked up by the press this week, did something refreshingly simple: it watched. Raphael Weidhaas, Alexandra von Preuschen and Verena Distler placed 41 participants in a simulated workplace and observed, interviewed and surveyed them as a phishing attack played out.
Three findings deserve your attention. Most participants who caught the phish did so through intuition rather than deliberate checklist analysis; the gut fired before the reasoning did. The phish itself was experienced as disruptive and emotionally negative even by people who were never fooled. And, most strikingly, several participants who correctly avoided clicking worried that their caution might itself be read as a mistake, with consequences for their reputation. One participant summed up the emotional stakes of the whole encounter: "I didn't know I would be this excited not to be scammed."
It is a small qualitative study, 41 people in a simulated setting, so treat it as a source of insight rather than statistics. But it is a rare, careful look at the emotional texture of the exact moment our programmes try to influence.
What does this mean for me? If detection is largely intuitive, our job is to train the gut, which argues for frequent, varied, low-stakes exposure over annual instruction. If even successful detection feels bad, the emotional payoff of doing the right thing is currently negative, and behaviour that feels bad does not repeat. And if people fear that hesitating might be held against them, your reporting culture has a problem no amount of content will fix. Make catching a phish feel like scoring a goal: fast positive feedback on reports, public celebration of good catches, and explicit reassurance that caution is never penalised.
Source: Weidhaas, von Preuschen and Distler, SOUPS 2026, open access via USENIX
Surfshark ran an experiment with 1,722 participants worldwide, asking them to distinguish AI-generated comments from human ones in simulated social media feeds, with the bots playing positive, negative and neutral personas. Help Net Security covered the results on 18 September. Overall, people correctly identified only 40% of the bots. But the spread is the story: hostile, negative bots were caught just over half the time, while friendly, positive ones were caught only 38% of the time. Plain-language bots slipped past far more often than emoji-heavy ones, detection declined with age, and serious topics were detected less often than light ones.
Surfshark is a VPN vendor, and this is not peer-reviewed work, so hold the precise numbers loosely. The direction of the effect, though, matches what we know about influence operations: as the researchers put it, manipulative AI accounts tend to be "agreeable, logical, or simply unremarkable". Our mental image of the bot as a clumsy, typo-ridden provocateur is doing us a disservice.
What does this mean for me? Audit your own awareness content for outdated tells. If your materials still teach people to spot bad grammar and aggression, you are training them to catch the bots that fail anyway. The transferable skill is verifying identity and provenance rather than judging tone, and it applies equally to the LinkedIn connection who flatters your CISO and the "colleague" in a Teams chat. This also belongs in your executive and comms teams' media literacy, since coordinated agreeable accounts are exactly how narrative manipulation now works.
Source: Help Net Security, 18 September 2026
On 15 September, the UK's NCSC, the FBI and the Dutch intelligence service AIVD jointly exposed an Iranian campaign deploying spyware dubbed CHOSEN BRICK against dissidents, activists and journalists. The tradecraft is worth every human risk professional's attention regardless of sector. Actors open contact on WhatsApp or Telegram posing as trusted contacts or platform support, invest time building rapport using researched personal details, and only then deliver a file disguised as something mundane: an antivirus installer, a password manager, even an MRI scan. The advisory notes that actors deliberately steer targets from work devices to personal ones, precisely to escape corporate security controls.
This is state espionage rather than commodity crime, and most employees will never be targeted this way. But it is the clearest official description yet of a pattern that is trickling down fast into fraud: the attack that starts as a relationship, not a link.
What does this mean for me? Two practical threads. First, duty of care: if your organisation employs people with public profiles, from executives to researchers to anyone connected to a diaspora community a state might care about, they deserve tailored guidance, and this advisory is a credible, citable basis for it. Second, the personal device pivot is a strong argument for extending your programme beyond the corporate perimeter. Security guidance that helps people protect their own lives, starting with "install only from official app stores, whoever asks", buys goodwill and protects the organisation at the same time.
Source: NCSC advisory, 15 September 2026
Cofense's Phishing Defense Center published analysis this week, covered by Help Net Security on 17 September, of a campaign impersonating ChatGPT billing. The email claims an outstanding balance of $23.80 and warns of account suspension within 48 hours, with a payment-update button that redirects through a Google API to a counterfeit OpenAI login page.
A single campaign is not normally worth your reading time, but this one is a neat specimen of current lure design. The amount is small enough to feel plausible and annoying, not alarming. The brand is one employees now use daily, often on personal accounts invisible to IT. And the redirect abuses legitimate Google infrastructure, so the first hover looks reassuring. The only reliable tell is the final address bar, where the real service lives at auth.openai.com, and the fake does not.
What does this mean for me? AI subscription lures deserve a place in your simulation and comms calendar, because AI tools have joined the small set of brands (banks, parcel firms, Microsoft) with near-universal workforce reach. More broadly, this is a chance to teach the one check that survives every redirect trick: the address bar at login, not the link in the email. It is a small, concrete habit, and small concrete habits are what stick.
Source: Help Net Security, 17 September 2026
Five stories, one thread: the modern attack flatters, befriends and reassures before it ever asks for anything. Our programmes have spent years teaching people to spot hostility and urgency. This week's evidence says the harder, more valuable skill is noticing when warmth arrives on schedule. See you next Monday.
The CyBehave Weekly Briefing is researched and written for leaders in human risk management, security awareness and behaviour change. Forward it to a colleague who would find it useful.
Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.