Treat the message as a social engineering attempt first, not a routine marketing email. During crisis periods, attackers exploit urgency, scarcity, and anxiety to bypass judgment. Organisations should reinforce user reporting, block suspicious links, and remind staff to verify offers through trusted channels before clicking. Rapid awareness messaging matters because emotionally charged lures can increase click-through rates and expose credentials or malware delivery paths.
Why crisis phishing works on the first pass
Fear and scarcity change how people process messages. In a public crisis, attackers borrow the same signals that real alerts use, urgent deadlines, limited supplies, policy updates, refund notices, or relief offers, so the message feels plausible before the recipient evaluates the sender. That is why the response must assume social engineering first and treat the lure as a trust test, not a normal communication.
The core failure is not technical novelty, it is attention capture. When people are under pressure, they are more likely to click quickly, skip verification, and accept a link that appears to offer safety, access, or advantage. Organisations that understand this can design responses around verification friction and reporting speed rather than relying on users to “be careful”.
Controls that strengthen this layer include reporting habits, link scrutiny, and trusted-channel verification. The best organisations make the safe path obvious and fast, so employees can confirm a request without replying to the phishing message itself. That matters because crisis-themed lures often imitate genuine operational communications closely enough that content alone is not a reliable filter.
How to stop the click from becoming a compromise
The immediate objective is to reduce the odds that one emotionally charged message becomes credential theft, malware delivery, or business disruption. A single click may expose passwords, session tokens, or internal portals, so the response should prioritise containment at the mailbox, browser, and user-reporting layers. When the message looks like a crisis update, the question is not whether it is persuasive, but whether it has been verified through an independent channel.
Blocking suspicious links is useful, but it is not enough on its own. Organisations should pair filtering with rapid awareness messaging that tells staff what the current lure looks like, what trusted source to use, and what not to do. This is especially important during fast-moving events, because the attacker benefit comes from compressing the time available for reflection.
Verification discipline also helps preserve operational trust. If employees are trained to check offers, relief notices, policy changes, or urgent instructions through known internal contacts or official websites, the organisation lowers the chance that a false scarcity message turns into a broader incident. For crisis conditions, the safest default is to slow the action, not the decision.
What a crisis-aware response should emphasise
Organisations should tune their phishing response to the situation rather than using a generic awareness script. A crisis campaign may use humanitarian themes, emergency funding, travel disruption, health notices, or supply shortages, and each of those can be credible enough to bypass routine suspicion. The response needs to reinforce the behaviour that breaks the attack chain, namely reporting, independent verification, and refusal to act directly from the message.
Messaging should be short, current, and operationally usable. Staff need to know which channel to use for reports, which domain or help desk to trust, and what to do if they already clicked. The more immediate the real-world event, the more important it is to update defenders and users quickly so the false narrative does not outrun the organisation’s guidance.
Good practice is to assume some percentage of users will still engage, even when warned. That means the organisation should also watch for downstream signals such as unusual credential entry, repeated login prompts, or access to unknown domains. The response is strongest when awareness, technical filtering, and incident handling are coordinated rather than treated as separate tasks.
Risk and Threat Considerations
Fear and scarcity lures are effective because they exploit urgency bias, which reduces the time people spend checking sender authenticity and destination URLs. During a public crisis, that can increase both click-through and the chance that a user will disclose credentials or open a malware path.
Failure mechanism: The attacker frames the message as time-sensitive or consequence-heavy, then relies on emotional pressure to bypass normal verification. If the organisation has weak reporting habits or no trusted alternate channel, the click can become a credential harvest, session compromise, or malicious payload delivery.
Impact: The immediate loss may be account access or endpoint compromise, but the larger effect is that a crisis can amplify the speed and scale of phishing across the organisation. Staff may also lose confidence in legitimate emergency communications if the response is slow or inconsistent.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Identity and Access Management | Phishing aims to steal or misuse credentials and access, so access control is directly implicated. |
| DE.CM-01 — Network and System Monitoring | Suspicious links and login activity should be detected quickly after crisis-themed phishing. | |
| Recommendation — Enforce phishing-resistant access controls and block credential use that bypasses verified identity. Monitor for suspicious messages, clicks, and anomalous sign-in activity tied to phishing. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | The subject is email-based social engineering using malicious links, which browser and email protections directly address. |
| Recommendation — Harden email and browser filtering to block malicious links and spoofed crisis lures. | ||
| MITRE ATT&CK | T1566 — Phishing | The question is specifically about phishing campaigns exploiting fear and scarcity. |
| Recommendation — Map observed lures to phishing techniques and tune detections for urgent crisis pretexts. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Verification and response depend on logging suspicious authentication and user-reporting events. |
| Recommendation — Log suspicious login attempts and reportable user interactions so phishing impact can be investigated. | ||
Practitioner Guidance
What to prioritise: Make the reporting path faster than the phishing path. If users must debate whether a crisis message is real, the control has already lost some of its value.
What to verify: Confirm that staff know one trusted place to validate urgent offers, notices, or instructions, and that security or service desk teams can answer quickly enough to support that habit. If verification takes too long, users will default to the message itself.
Common mistake: Treating crisis phishing as a pure awareness problem. The real control is a combination of user behaviour, link blocking, and a verification workflow that is simple enough to use under stress.
Practitioner takeaway: In a public crisis, the organisation should optimise for fast doubt, fast reporting, and fast independent verification, because emotionally charged phishing succeeds when it converts urgency into action before scrutiny can happen.
Related resources from NHI Mgmt Group
- How should security teams reduce phishing risk when attackers use a public health crisis to drive clicks?
- What breaks when phishing campaigns use public identity data to personalise lures?
- How should organisations collect real-time data in a compliant way during a public health crisis?
- What happens when phishing campaigns use localized lures and country-specific tax authority branding against global organisations?