Skip to content

Scams that target your workforce

These scams go after employees, help desks, finance teams, and hiring pipelines rather than consumers. Each type below explains how the attack works, the red flags, and the controls that stop it, and links to real cases, each graded by source.

Business payment fraud (BEC)

Impersonating executives, suppliers, or employees to redirect business payments, now including deepfake video and voice.

Workforce and access social engineering

Attacks that manipulate employees and help desks into handing over access: password resets, MFA fatigue, fake IT support, insider bribery, and fake hires.

Delivery techniques to defend against

  • Adversary-in-the-middle phishing: Phishing pages that relay the real login in real time, capturing the session cookie and defeating one-time codes and push MFA.
  • OAuth consent phishing: Tricking a user into granting a malicious or look-alike app access to their account, which keeps working after a password reset.
  • ClickFix (fake fix-it prompts): Fake error or CAPTCHA pages that tell the victim to paste a command into their own computer, which installs malware.
  • Voice phishing (vishing): Phone calls, sometimes with cloned voices, that impersonate banks, IT, officials, or family to get money, codes, or access.
  • Spear phishing: Phishing written for one person or team, using details from social media, breaches, or earlier emails.

Controls, step by step

Rollout guides for the controls that break these attacks.

Real cases