Join our Newsletter — 33% off our NHI Course

Why do phishing and impersonation scams become more effective during periods of widespread fear and remote work?

These scams work better when people are anxious, overloaded, and communicating less in person. Attackers exploit confusion, limited verification channels, and heavier reliance on email, text, and social media. Remote work also expands exposure because businesses open more access paths and users spend more time online, making it harder to separate legitimate requests from fraudulent ones.

Why fear and remote work make impersonation harder to spot

Phishing and impersonation succeed when people cannot easily verify who is asking, and fear makes that problem worse. In a stressful environment, recipients are more likely to act quickly, skip confirmation steps, and treat unusual instructions as urgent exceptions. Remote work adds distance, so attackers can blend into the normal flow of email, chat, and ticket-based requests.

The core failure is not simply “people are careless”, it is that the verification burden shifts onto channels that are easy to spoof and hard to challenge. When teams are dispersed, the usual friction of a walk over to a desk, a quick call to a known contact, or an in-person sanity check disappears, so social proof and urgency become much more persuasive.

That is why impersonation campaigns often reuse familiar operational language, internal terminology, or crisis-themed messaging. The more a message sounds like a routine business process, the less likely a stressed recipient is to question it, especially when the message claims to bypass delays, policy, or normal approval paths.

How remote work expands the attacker’s opportunity window

Remote work does not create phishing by itself, but it broadens the attack surface that impersonation can exploit. Users are distributed across home networks, personal devices, collaboration apps, and asynchronous communication channels, which gives attackers more places to insert a false request and more chances for one message to reach the right person at the wrong moment.

It also changes how trust is established. In-office environments naturally support quick corroboration. Remote environments often rely on written requests, links, attachments, and direct messages, so a fraudulent message can look operationally normal until it is too late. MailChimp breach is a useful example of how social engineering can turn a single compromised employee interaction into broader exposure.

Periods of widespread fear intensify this effect because they compress attention and weaken scepticism. Attackers exploit current events, policy changes, staffing strain, and exception handling to make a false request feel timely and legitimate. In practice, the issue is not only volume, but timing: the best phishing lures arrive when the target is least able to slow down and verify.

What changes when verification becomes the bottleneck

When people are overloaded, the main control failure is usually verification, not awareness. A user may recognise that a message is unusual but still act because the surrounding process makes confirmation slow, awkward, or uncertain. That is why organisations need verification paths that are faster and clearer than the attacker’s pressure campaign.

Current guidance increasingly favours phishing-resistant authentication for high-value access and sensitive workflows. NIST SP 800-63 Digital Identity Guidelines is relevant here because stronger authenticators reduce the value of credentials harvested through impersonation. Where identity proofing and access assurance are weak, a convincing fake message can translate directly into account takeover or fraudulent approval.

Fear also encourages overreliance on urgency signals. Practitioners should assume that “act now” language, unusual payment instructions, and out-of-band password resets will appear more credible during crises than during normal operations. The defensive response is not more messaging, but more verifiable process: explicit callback rules, independent confirmation, and reduced dependence on any single communication channel.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines — Digital Identity Guidelines Phishing effectiveness depends on how identities and authenticators are verified.
Recommendation — Adopt phishing-resistant authenticators for sensitive access and high-risk approval workflows.
CIS Controls v8 6 — Access Control Management Impersonation often leads to unauthorised access or approval abuse.
Recommendation — Tighten account and access workflows so suspicious requests cannot directly change privileges.
NIST CSF 2.0 PR.AC — Access Control Remote impersonation succeeds when access paths and trust checks are too easy to spoof.
DE.CM — Continuous Monitoring Phishing campaigns benefit when abnormal authentication or message patterns are not detected quickly.
RS.CO — Response Communications Rapid impersonation often requires a fast, trusted verification path during incidents or crises.
Recommendation — Enforce stronger access verification for remote request channels and privileged actions. Monitor for anomalous access, login, and message patterns tied to impersonation attempts. Define trusted out-of-band communication paths for urgent request verification.

Practitioner Guidance

What to verify: Treat any request that changes payment, credentials, access, or delivery details as untrusted until it is confirmed through a separate channel already known to the recipient. The strongest control is not content analysis, but a process that forces the user to verify outside the inbox or chat thread.

What changes at scale: The more remote the workforce, the more important it becomes to standardise how legitimate requests are issued and challenged. If every team improvises its own verification habits, attackers only need to learn one weak pattern to succeed repeatedly.

Common mistake: Organisations often focus on training users to “spot phishing” while leaving urgent business processes easy to spoof. That leaves stressed employees responsible for compensating for weak workflow design, which is exactly when impersonation attacks are most effective.

Practitioner takeaway: Fear and distance do not make phishing smarter, they make trust harder to validate, so the best defence is to reduce ambiguity in how legitimate requests are proven, not to assume recipients will pause and think under pressure.