Security teams should treat crisis themed phishing as a blend of social engineering and urgency exploitation. The best defense is layered awareness training, strong email filtering, and a habit of verifying links before opening them. Users need clear reporting paths for suspicious messages, because speed matters when campaigns mimic trusted public sources or health authorities.
How crisis-themed phishing works and why urgency is the real payload
Public health crises give attackers a believable pretext for urgency, fear, and curiosity. That matters because phishing succeeds when the message feels timely enough to bypass routine skepticism. Security teams should focus on breaking that emotional shortcut: make verification easy, make reporting fast, and make risky clicks less likely to reach a mailbox in the first place.
The core failure mode is not just deceptive content, but timing and trust abuse. Messages that appear to come from health agencies, employers, insurers, or relief organisations can feel legitimate enough to override normal caution. Teams should therefore treat crisis-themed lures as a content problem and a process problem, combining filtering, user education, and clear escalation paths.
What effective reduction looks like in practice
Strong email filtering should block obvious spoofs, suspicious attachments, and known malicious URLs, but filtering alone will not stop every campaign. Users still need a habit of checking sender details, hovering over links, and confirming unexpected requests through a trusted channel before acting. The goal is to reduce both initial exposure and the chance that one mistaken click becomes an incident.
Training works best when it is specific to the lure pattern, not generic. Crisis-themed phishing should be used in awareness exercises so people learn to question messages that exploit health anxiety, donation appeals, policy updates, or emergency guidance. Clear reporting paths matter because early reports let security teams hunt, block, and warn other users before the campaign spreads.
How to keep the response fast without overloading users
The most useful operational change is to make the safe action the easiest action. If staff can report a suspicious email with one click, and if security can rapidly remove the message from other inboxes, the organisation shortens the attacker’s window. That is especially important when campaigns borrow public-health language, because hesitation and confusion are exactly what the attacker wants.
Teams should also tune their response to the type of message. Some lures are broad and noisy, while others are targeted and well-crafted. When a crisis theme is tied to a specific region, employer, or benefit program, the risk is higher because the message is more contextual and more credible. In those cases, the response should include user notification, mailbox search, and blocklist updates, not just a training reminder.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Crisis-themed lures are a phishing technique that exploits trust and urgency. |
| Recommendation — Map crisis-themed email lures to T1566 and tune detections for social-engineering pretexts. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | Filtering and link defense directly reduce phishing delivery and click-through risk. |
| CIS-14 — Security Awareness and Skills Training | User training is central when attackers exploit fear and urgency during a crisis. | |
| Recommendation — Harden email and browser protections to block malicious links and attachments. Run targeted phishing training that uses current crisis-themed lure patterns. | ||
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training Policy and Procedures Are Established and Maintained | Awareness programs are needed to counter social engineering during crisis-driven campaigns. |
| DE.CM-09 — Monitoring for Unauthorized Personnel, Connections, Devices, and Software | Fast reporting and monitoring help detect and contain malicious email campaigns. | |
| Recommendation — Maintain phishing awareness procedures that include crisis-themed examples. Monitor user reports and email activity to spot and contain phishing campaigns early. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Reporting and monitoring depend on timely detection of suspicious user activity and messages. |
| Recommendation — Log and review suspicious-message reports to accelerate phishing response. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Phishing often aims to steal credentials, making authentication resilience relevant. |
| Recommendation — Use phishing-resistant authentication to reduce the impact of stolen credentials. | ||
Practitioner Guidance
What to prioritise: Focus first on reducing the credibility of the lure and the speed of user reporting. That combination does more than awareness alone, because it cuts both the attacker’s reach and the dwell time of a successful message.
What to verify: Test whether suspicious emails can be reported in a single step, whether security can quarantine similar messages quickly, and whether users know which trusted channel to use when a message claims to be from a health authority or relief program.
Common mistake: Treating crisis phishing as a one-time awareness topic. These campaigns evolve with current events, so teams need recurring message examples and short refreshers whenever a public health issue is in the news.
Practitioner takeaway: The best defense is not telling users to be suspicious of everything, but making it easy to pause, verify, and report before urgency turns into compromise.
Related resources from NHI Mgmt Group
- How should security teams reduce the risk of ClickFix phishing when attackers use AI tool installation instructions as the lure?
- How should security teams reduce the risk of HTTPS phishing when attackers use trusted certificates to create believable fake sites?
- How should security teams reduce the risk of email phishing when attackers use display-name spoofing and mobile clients hide full headers?
- How should security teams reduce phishing risk when attackers can personalize lures at machine speed?