Signals Weekly Briefing

SIGNAL: Week 41 - Creatures of Habit

5 October 2026 · 8 min read · Andy
← All Signals briefings

Monday 5 October 2026 | 8-minute read

October has arrived, and with it Cybersecurity Awareness Month, but this week's real story isn't the campaign calendar. It is how consistently the latest research points at one idea: predictability. Attackers recycle the same small set of asks behind endlessly varied stories, risk clusters in a small (and shifting) group of people, and the gap between how confident people feel and what they actually do remains stubbornly wide. If both sides of this contest are creatures of habit, the advantage goes to whoever studies the habits hardest. This week's five items should help.

One person in ten, almost all of the risk, and a different ten next year

Living Security launched its 2026 State of Human Risk Report at HRMCon on 29 September, and the headline finding deserves attention: across de-identified telemetry from more than 100 organisations and nearly five million workforce identities, the riskiest 10 per cent of users accounted for 98 per cent of data loss risk and 96 per cent of malware and endpoint risk. That extreme concentration will not surprise anyone who has run a human risk programme. The more useful finding sits underneath it: in the report's two-year longitudinal analysis, nearly two thirds of the people in the riskiest decile were not in it the year before. Risk concentrates, but it does not sit still. People change roles, gain access, inherit new tools, and their exposure changes with them.

The usual caveat applies. This is a vendor analysing its own platform's telemetry, so the population skews towards organisations already invested in human risk management. Even so, the scale is substantial, and the longitudinal angle is rarer than it should be in this market.

What does this mean for me? If your programme still treats "risky users" as a fixed cohort, this is your prompt to rethink. A one-off risk assessment that labels people and leaves them labelled will be badly stale within a year. Build re-scoring into the cycle, treat movement into and out of the risky decile as a signal worth investigating (role changes and new joiners especially), and resist publishing static "repeat clicker" lists that quietly become a hall of shame for people whose circumstances have simply changed.

Source: Living Security, 2026 State of Human Risk Report launch announcement, 29 September 2026. Read the announcement

2.9 million phishing emails, one overwhelming ask

A research team including the University of Tennessee's Doowon Kim, working with the Anti-Phishing Working Group, has posted the largest content analysis of phishing email I can remember seeing: 2.9 million distinct phishing emails collected over 13 months to June 2026, analysed for theme, call to action and impersonation tactic using an LLM pipeline validated against human annotation. The structure they found is striking. Themes are genuinely diverse, with no single storyline exceeding 21.3 per cent of the corpus, yet one call to action (clicking through to a URL) accounts for 73 per cent of everything. Attackers vary the costume endlessly and barely vary the ask.

The exception is the one to watch. In invoice-themed phishing, the dominant ask has migrated from links towards offline contact, typically a phone number to call, rising from 6.7 per cent of such emails in 2015 to 46.9 per cent in 2025. That is the callback scam going mainstream, moving the victim onto a channel where email filters cannot follow. Worth noting: this is a preprint, not yet peer-reviewed, though the APWG data partnership and validation work are reassuring.

What does this mean for me? This is empirical licence to simplify your training. Chasing every new lure theme is a losing game when the themes number in the dozens but the asks number about five. Teach people to ignore the story and interrogate the ask: what is this message trying to get me to do? And make sure callback phishing is in your simulation and reporting repertoire, because "ring this number about your invoice" now rivals the malicious link in that category, and most reporting buttons were never designed with it in mind.

Source: Park, Lee, Ji and Kim, A Large-Scale Empirical Study of Modern Phishing Email Content, arXiv preprint, 25 September 2026. Read the paper

ENISA's view from Europe: the user as unwitting operator

The EU's cybersecurity agency published its annual Threat Landscape report on 22 September, covering incidents observed across 2025. Phishing still dominates the social engineering category at 77.8 per cent of identified techniques, but the texture has changed. ENISA documents the continued rise of ClickFix, the technique that talks users through pasting malicious commands into their own machines (now adopted by ransomware operators, not just commodity crews), alongside growth in smishing against logistics and public services, device code phishing initiated over trusted platforms like Signal and WhatsApp, and vishing crews impersonating IT support. Threaded through all of it is AI: large language models crafting tailored lures at scale, synthetic identities for remote worker fraud, and fake AI service websites used as bait.

As a regulator's synthesis of reported incidents, this is more authoritative on direction than on precise magnitude, and its EU lens is part of the value for readers tired of US-centric data.

What does this mean for me? The common pattern across ClickFix, device code phishing, and vishing is that the attacker no longer delivers the payload; they persuade the user to perform the technical steps themselves. That breaks the mental model most awareness programmes still teach, where danger arrives as an attachment or a dodgy link. Update your guidance to cover instructions as the threat: anything that walks you through copying commands, approving a sign-in code, or installing "support" software deserves the same reflexive suspicion as an unexpected attachment. Your service desk should also agree on a verification script now, before the IT impersonators call.

Source: ENISA Threat Landscape 2026, European Union Agency for Cybersecurity, 22 September 2026. Read the report

Japan's scam data and the confidence trap

The Global Anti-Scam Alliance released its State of Scams in Japan 2026 report on 29 September, surveying 1,200 Japanese adults. Japan looks comparatively fortunate: 22 per cent encountered a scam in the past year, lower than most Asian markets. But the behavioural detail undercuts any complacency. Fifty-seven per cent of respondents felt confident they could recognise a scam, yet among those who actually encountered one, 53 per cent engaged with the scammer. Impersonation scams led the field at 20 per cent, ahead of shopping and romance scams. The same confidence-versus-behaviour gap has shown up in GASA's other country studies, which makes it look less like a cultural quirk and more like a human constant.

Self-reported surveys have their limits (people underreport embarrassing interactions, so the true engagement figure may be higher), and GASA's country reports are produced with commercial partners. The cross-country consistency is what earns this a place here.

What does this mean for me? Measured confidence is not a control, and it may be the opposite. If your programme's survey data shows rising confidence scores, resist reporting that as risk reduction; pair it with behavioural measures (report rates, simulation outcomes, real incident data) before drawing conclusions. The finding also travels well into personal-life content: scam resilience messaging that starts "you are probably confident you would spot one, and so were the people who engaged" lands harder than another list of red flags.

Source: Global Anti-Scam Alliance, State of Scams in Japan 2026, 29 September 2026. Read the summary

"Don't Make It Easy For Them": a usable theme, for once

Cybersecurity Awareness Month kicked off on 1 October, and this year's theme from the National Cybersecurity Alliance and CISA is "Don't Make It Easy For Them". As campaign slogans go, this one has real behavioural merit: it reframes security from an unwinnable duel with genius adversaries into a matter of not being the easiest target, which is both accurate (see every other item this week) and agency-preserving. The supporting content sticks to the Core 4 behaviours (password managers, multi-factor authentication, recognising and reporting scams, updating software), and the free Champion toolkit includes posters, tip sheets and a sizeable batch of social graphics.

What does this mean for me? Even if your organisation runs its own calendar, the theme is worth borrowing because it answers the fatalism ("attackers will get in anyway, why bother?") that quietly corrodes engagement. Attackers are predictable; raising their cost works. If October is your big engagement window, spend it on the smallest number of behaviours with the clearest payoff rather than a festival of content, and use the free toolkit to save your design budget for the things only your organisation can say.

Source: National Cybersecurity Alliance, Cybersecurity Awareness Month 2026. Visit the campaign hub

 


That is the week: concentrated risk, repetitive asks, misplaced confidence, and a campaign slogan that happens to be true. The craft in this field has never been about predicting the next clever lure. It is about knowing the habits, theirs and ours, a little better than last month. See you next Monday.

The CyBehave Weekly Briefing is researched and written fresh each week. Replies, challenges and ideas for coverage are always welcome.

Get Signals in your inbox

Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.