DNYUZ
No Result
View All Result
DNYUZ
No Result
View All Result
DNYUZ
Home News

‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

October 9, 2026
in News
‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

Your first few weeks at work probably look something like this: figuring out who’s who on Slack, which floor has the best snacks, and navigating the hundreds of emails piling up in the inbox. Then one catches your eye. It says “Congratulations!” You click, and a new message appears: “You failed the test,” along with an attached invitation to security training.

Ladies and gentlemen, welcome to the decidedly forgettable experience of falling for a phishing scam—or in this case, the simulation of one. The lesson is to be more careful next time. But what happens when the next message looks like it came from the boss, lands during a busy afternoon, and asks for something that sounds perfectly reasonable?

A new survey from Yubico and Okta highlights why employers need an answer beyond another training session. Of 1,890 technology and security professionals, 82% had received employer security training. Still, 23% said their organizations did not require multifactor authentication (MFA)—a login step beyond a password—across all applications and services. Despite this, 88% described their enterprise as secure. For employers, the question is what stands between a convincing scam and a compromised account when a worker misses the warning signs.

“The gap was not the awareness; it was the adoption,” Poupak Modirassari Enbom, Yubico’s chief market and growth officer, told Fortune.

Talker Research conducted the survey July 2–16 across nine countries, polling professionals in technology and security roles at companies with at least 500 employees. The results, released Oct. 7, reflect that population, rather than workers generally. Yubico, which sells hardware security keys, and Okta, which provides identity management services, announced a partnership alongside the survey.

Knowing the rules does not mean someone will catch every suspicious request, said Lorrie Faith Cranor, director of Carnegie Mellon University’s CyLab, and a co-founder of Wombat Security Technologies, a security awareness training company later acquired by Proofpoint. A scam can work because it addresses a real need like finding a job, resolving an immigration concern, or pleasing the boss.

“But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard,” Cranor told Fortune.

Hey, the boss needs a favor

In a November 2025 Reddit post, one person described buying $800 in Target gift cards on their second day at a new job after receiving an email impersonating their boss. The supposed assignment was to surprise office assistants.

“I’m very new to the company, so I’m still not entirely sure how things go there,” the poster wrote. They said they recognized the scam before sharing the cards’ redemption codes.

Cranor said a person’s risk depends on how often they are targeted, their security habits, their ability to recognize suspicious messages, and whether the lure really interests them. Even someone with good habits can simply be distracted, she added.

Over half (55%) of respondents in the survey also reported being directly targeted by personalized phishing attacks. Another 44% said their organization had experienced at least one successful AI-driven phishing attack in the previous year.

Some familiar warning signs are becoming less useful.

“Sure, there are still some simple phishing messages that you might spot by looking at typos, but a lot of phishing messages are written by AI agents with perfect grammar and spelling and they mimic corporate style and branding,” Cranor said.

The survey put that to the test. Respondents were shown two versions of an HR email asking staff to sign off on an updated handbook, one written by a person and one by AI. Only 36% correctly identified the human-written message, while 54% thought AI wrote it.

Protection for the moment someone slips

The report recommends building stronger authentication into onboarding. Some 52% of respondents said they received username-and-password credentials when starting their roles, though that does not establish whether they also used multifactor authentication. Passkeys use cryptographic credentials tied to a legitimate site, so they won’t authenticate a login on an imitation website. But that protection covers account access—it won’t stop someone from buying gift cards at a scammer’s request.

Cranor said MFA provides substantial protection, but its forms differ. Text-message codes can be vulnerable when an attacker persuades a mobile carrier to transfer a victim’s number to the attacker’s phone. Even an authenticator app can be undermined by deception. A scammer posing as a help-desk employee might ask someone to read out a code, then use it to access the account, she said.

“So it is important to never give anyone these codes,” Cranor said.

And yes, training does still matter. Cranor said it can raise awareness that anyone is a potential victim.

“This is a good start, but to be most effective, it also needs to teach concrete skills and give people practice in using them,” she said. She added that training should also address the threats relevant to different jobs.

Employers should also make checking a request part of the job. If a message appears to come from the boss but something feels off, Cranor said, workers should verify it through another channel before responding.

But employers also need to know whether their training works. Cranor said many efforts to educate employees and the public about scams have not been rigorously evaluated.

“They celebrate the number of people who have been trained or have watched their videos, but they rarely do controlled experiments to see whether the training actually protects people,” she said.

The post ‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional appeared first on Fortune.

Gwynne Shotwell’s $300 million SpaceX pledge to Trump Accounts shows billionaires a tax-smart way to give away their own company’s stock
News

Gwynne Shotwell’s $300 million SpaceX pledge to Trump Accounts shows billionaires a tax-smart way to give away their own company’s stock

by Fortune
October 9, 2026

In a new type of philanthropy, billionaire SpaceX president Gwynne Shotwell has pledged to give more than 2 million American ...

Read more
News

Foreign nationals breach UK base housing key US, NATO intel hub amid $556M expansion

October 9, 2026
News

‘You decided to evade them’: Former HSBC banker ‘clearly in a financial position to pay’ banned from finance for dodging $7,800 in fares

October 9, 2026
News

Sheryl Sandberg says adult children can help a widowed parent with a simple message

October 9, 2026
News

Sweden’s startups will raise $5 billion in 2026. Our secret sauce is 150 years old

October 9, 2026
Disney offered a 13-year-old $2 million to sing in The Lion King—his mom took $100k plus royalties instead. He’s still getting paid 32 years later

Disney offered a 13-year-old $2 million to sing in The Lion King—his mom took $100k plus royalties instead. He’s still getting paid 32 years later

October 9, 2026
Journey drummer Deen Castronovo suffers medical emergency during Oklahoma concert

Journey drummer Deen Castronovo suffers medical emergency during Oklahoma concert

October 9, 2026
Dear Abby: I haven’t had a birthday party since I was a child and want to have one again

Dear Abby: I haven’t had a birthday party since I was a child and want to have one again

October 9, 2026

DNYUZ © 2026

No Result
View All Result

DNYUZ © 2026