Join our Newsletter — 33% off our NHI Course

Why do wartime cyber campaigns increase identity and trust risk?

Because conflict narratives lower user suspicion and create urgency. Attackers exploit that context to make phishing, recruitment and impersonation messages look timely or legitimate. Identity teams should assume that sender reputation, message context and channel choice all become attack vectors when kinetic events are in play.

How wartime narratives turn trust into a delivery channel

Wartime campaigns work because they compress attention and change how people judge legitimacy. Messages that reference conflict, humanitarian issues, sanctions, troop movements or emergency support can feel time-sensitive and credible, which reduces the normal friction that stops a user from engaging, clicking or replying. That shift in perception is the core trust problem, not just the content itself.

In practice, the attacker is borrowing the emotional authority of real events. A message does not need to be technically sophisticated if the context already makes the target less likely to question it. That is why conflict-linked lures often outperform generic spam: they exploit the moment when people expect urgent communication and are least willing to slow down.

Identity teams should treat this as a context-driven trust failure. The sender may be impersonated, but the larger issue is that the message appears to come from a plausible role, channel or mission, which weakens the recipient’s ability to distinguish authentic contact from hostile reach.

Which identity controls are most exposed

Wartime cyber campaigns usually aim at the parts of identity security that depend on trust cues. Email reputation, account naming, reply chains, chat presence, external collaboration and contractor workflows all become easier to abuse when recipients assume conflict-related messages are normal. That means phishing, impersonation and recruitment attempts can bypass both technical filters and human suspicion.

The risk rises when organisations allow fast-moving exceptions, broad guest access or loosely governed external communication paths. If an attacker can impersonate a partner, recruiter, aid organisation or internal business contact, the control failure is rarely one single missing check. It is usually a combination of weak identity verification, weak channel verification and over-trust in urgent context.

One practical anchor is to review how your environment handles third-party and external identities, because conflict narratives often arrive through those edges first. NHIMG’s Third-Party, B2B and Contractor Access Guide is a useful reference point for sponsorship, time-bounding and review discipline around external access.

For broader identity lifecycle hygiene, it also helps to understand where stale, shared or over-permissioned accounts create openings that a social lure can exploit after the first click. The NHI Lifecycle Management Guide and IAM and IGA Basics both support that review.

Why message context matters more than the headline

Wartime campaigns succeed when they combine believable context with a low-cost action: open a file, confirm a detail, join a call, donate, log in or grant access. The message often looks ordinary in isolation, but the surrounding narrative gives it momentum. In identity terms, context becomes part of the authentication problem because recipients are informally using story, tone and channel as proof.

That is why sender reputation alone is not enough. A legitimate-looking mailbox, messaging account or compromised partner identity can still be used to create trust. The stronger control is to separate message plausibility from identity proof by requiring independent verification for sensitive requests, especially when the content references crisis, military activity or humanitarian urgency.

Where organisations have mature identity posture monitoring, they are better placed to spot the knock-on effects of that trust abuse. Identity Security Posture Management (ISPM) Guide is relevant because wartime lures often exploit the same weaknesses that posture tools surface, such as dormant accounts, standing privilege and configuration drift.

Risk and Threat Considerations

Wartime campaigns increase exposure because people are primed to act quickly and verify less. That creates a favourable environment for impersonation, credential theft and social engineering across email, chat and collaboration tools.

Failure mechanism: Attackers exploit urgency and emotional salience to bypass normal scrutiny, then use spoofed or compromised identities to make malicious requests look aligned with a real-world event.

Impact: The likely outcomes are account compromise, fraudulent access approval, lateral trust abuse and faster spread of the campaign through internal or partner relationships.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication and Access Control Conflict lures abuse identity trust and access decisions.
Recommendation — Require independent verification before approving identity-sensitive requests.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Phishing and impersonation often aim to steal or reuse authenticators.
IA-2 — Identification and Authentication (Organizational Users) Sender and request legitimacy depend on strong user authentication.
Recommendation — Rotate and protect authenticators exposed to wartime phishing. Enforce strong authentication for workforce accounts handling sensitive requests.
OWASP Non-Human Identity Top 10 NHI-10 — Human Use of NHI Conflict-themed messages can exploit human trust around accounts and channels.
Recommendation — Prevent humans from approving access through unverified identity cues.
CIS Controls v8 CIS-5 — Account Management Impersonation succeeds more easily when accounts and access paths are weakly governed.
Recommendation — Continuously review and remove unnecessary account access paths.

Practitioner Guidance

What to verify: Treat conflict-linked requests as untrusted until the identity of the sender and the legitimacy of the channel are verified through an out-of-band step that does not reuse the same email thread or messaging space.

Decision rule: If the request involves credentials, access, payment, urgent contact lists or external collaboration, escalate it to a higher-verification path even when the message appears operationally plausible.

What practitioners underestimate: The attack is often not the initial lure but the trust chain it creates afterward, where one convincing message can open the door to additional impersonation, reply-chain abuse or delegated access.

Practitioner takeaway: In wartime conditions, the key control is not simply blocking suspicious content, it is preserving independent verification when narrative pressure makes normal trust signals unreliable.