• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Move over, DINKs. SPLITs are the new financial power couple: They have two incomes, no kids yet, and no joint bank account

2

Whole Foods CEO says grocery will turn Amazon from the 'everything store' into the 'everyday store'

3

Texas businessman gets 13 years in federal prison as feds seize his Lamborghinis, Ferraris, Firebird, and dozens more cars to pay back fraud victims

1

Move over, DINKs. SPLITs are the new financial power couple: They have two incomes, no kids yet, and no joint bank account

2

Whole Foods CEO says grocery will turn Amazon from the 'everything store' into the 'everyday store'

3

Texas businessman gets 13 years in federal prison as feds seize his Lamborghinis, Ferraris, Firebird, and dozens more cars to pay back fraud victims
CybersecuritySecurity

‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

By
Tatiana Sataua
Tatiana Sataua
News Fellow
Down Arrow Button Icon
By
Tatiana Sataua
Tatiana Sataua
News Fellow
Down Arrow Button Icon
October 9, 2026, 3:00 AM ET
A researcher browses an internet site with a job offer for a United Nations agency that has been flagged as a scam in Nairobi on June 30, 2022. A report by Code for Africa revealed that in 2020 when job losses soared during the Covid-19 pandemic 33 scam recruitment Facebook accounts, groups and pages with more than 184,000 followers targeted people in Kenya, requiring them to send about 350 Kenyan shillings ($3) before placements that never materialised. Syndicates behind these scams rely on the desperation of job seekers who fail to double-check the authenticity of job postings and send money without hesitation to secure employment, said Kenyan cyber security expert Anthony Muiyuro.
Security training can help workers recognize phishing attempts, but experts say employers also need stronger login protections for when a convincing scam slips through.TONY KARUMBA/AFP via Getty Images
Google source logo
Add Fortune on Google for similar content.

Your first few weeks at work probably look something like this: figuring out who’s who on Slack, which floor has the best snacks, and navigating the hundreds of emails piling up in the inbox. Then one catches your eye. It says “Congratulations!” You click, and a new message appears: “You failed the test,” along with an attached invitation to security training.

Recommended Video

Ladies and gentlemen, welcome to the decidedly forgettable experience of falling for a phishing scam—or in this case, the simulation of one. The lesson is to be more careful next time. But what happens when the next message looks like it came from the boss, lands during a busy afternoon, and asks for something that sounds perfectly reasonable? 

A new survey from Yubico and Okta highlights why employers need an answer beyond another training session. Of 1,890 technology and security professionals, 82% had received employer security training. Still, 23% said their organizations did not require multifactor authentication (MFA)—a login step beyond a password—across all applications and services. Despite this, 88% described their enterprise as secure. For employers, the question is what stands between a convincing scam and a compromised account when a worker misses the warning signs.

“The gap was not the awareness; it was the adoption,” Poupak Modirassari Enbom, Yubico’s chief market and growth officer, told Fortune.

Talker Research conducted the survey July 2–16 across nine countries, polling professionals in technology and security roles at companies with at least 500 employees. The results, released Oct. 7, reflect that population, rather than workers generally. Yubico, which sells hardware security keys, and Okta, which provides identity management services, announced a partnership alongside the survey.

Knowing the rules does not mean someone will catch every suspicious request, said Lorrie Faith Cranor, director of Carnegie Mellon University’s CyLab, and a co-founder of Wombat Security Technologies, a security awareness training company later acquired by Proofpoint. A scam can work because it addresses a real need like finding a job, resolving an immigration concern, or pleasing the boss.

“But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard,” Cranor told Fortune.

Hey, the boss needs a favor

In a November 2025 Reddit post, one person described buying $800 in Target gift cards on their second day at a new job after receiving an email impersonating their boss. The supposed assignment was to surprise office assistants.

“I’m very new to the company, so I’m still not entirely sure how things go there,” the poster wrote. They said they recognized the scam before sharing the cards’ redemption codes.

Cranor said a person’s risk depends on how often they are targeted, their security habits, their ability to recognize suspicious messages, and whether the lure really interests them. Even someone with good habits can simply be distracted, she added.

Over half (55%) of respondents in the survey also reported being directly targeted by personalized phishing attacks. Another 44% said their organization had experienced at least one successful AI-driven phishing attack in the previous year.

Some familiar warning signs are becoming less useful.

“Sure, there are still some simple phishing messages that you might spot by looking at typos, but a lot of phishing messages are written by AI agents with perfect grammar and spelling and they mimic corporate style and branding,” Cranor said.

The survey put that to the test. Respondents were shown two versions of an HR email asking staff to sign off on an updated handbook, one written by a person and one by AI. Only 36% correctly identified the human-written message, while 54% thought AI wrote it.

Protection for the moment someone slips

The report recommends building stronger authentication into onboarding. Some 52% of respondents said they received username-and-password credentials when starting their roles, though that does not establish whether they also used multifactor authentication. Passkeys use cryptographic credentials tied to a legitimate site, so they won’t authenticate a login on an imitation website. But that protection covers account access—it won’t stop someone from buying gift cards at a scammer’s request.

Cranor said MFA provides substantial protection, but its forms differ. Text-message codes can be vulnerable when an attacker persuades a mobile carrier to transfer a victim’s number to the attacker’s phone. Even an authenticator app can be undermined by deception. A scammer posing as a help-desk employee might ask someone to read out a code, then use it to access the account, she said.

“So it is important to never give anyone these codes,” Cranor said.

And yes, training does still matter. Cranor said it can raise awareness that anyone is a potential victim. 

“This is a good start, but to be most effective, it also needs to teach concrete skills and give people practice in using them,” she said. She added that training should also address the threats relevant to different jobs. 

Employers should also make checking a request part of the job. If a message appears to come from the boss but something feels off, Cranor said, workers should verify it through another channel before responding.

But employers also need to know whether their training works. Cranor said many efforts to educate employees and the public about scams have not been rigorously evaluated.

“They celebrate the number of people who have been trained or have watched their videos, but they rarely do controlled experiments to see whether the training actually protects people,” she said.

Fortune Daily breaks the traditional barrier between audience and newsroom. The show transforms Fortune’s trusted reporting into actionable, conversational, and entertaining insights for an emerging class of business leaders. Watch here.
About the Author
By Tatiana SatauaNews Fellow

Tatiana Sataua is a News Fellow at Fortune covering business, technology, AI, and consumer culture.

See full bioRight Arrow Button Icon
Google source logo
Add Fortune on Google for similar content.

Latest in Cybersecurity


Most Popular

Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

    Latest in Cybersecurity


    Most Popular

    © 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
    FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.