AI deepfake CFO calls surge 300%Microsoft 365 mailboxes hijacked via token theftSupplier invoice fraud drains six figuresHelp desk social engineering restarts ransomware waveQR phishing moves attacks to personal phones68% of breaches still involve a personRegulators ask for training evidence, not policyExecutive impersonation by SMS climbs againAI deepfake CFO calls surge 300%Microsoft 365 mailboxes hijacked via token theftSupplier invoice fraud drains six figuresHelp desk social engineering restarts ransomware waveQR phishing moves attacks to personal phones68% of breaches still involve a personRegulators ask for training evidence, not policyExecutive impersonation by SMS climbs again

Human risk findings

What is actually going wrong for organizations right now — and the training or simulation control that answers it inside Rampart.

DeepfakeJuly 14, 2026· Industry threat reporting

Deepfake voice and video calls are now a mainstream finance fraud

Attackers join a scheduled video call with a cloned executive face and voice, then push a same-day wire. Finance teams approve because the request arrives inside a familiar workflow.

What to do in Rampart: Run a payment-authorization simulation and train an out-of-band callback rule for any payment change.

Cloud & emailJune 28, 2026· Cloud security advisories

Adversary-in-the-middle kits defeat MFA on Microsoft 365

Phishing kits proxy the real login page, capture the session token and keep mailbox access after MFA. The first sign is usually an inbox rule that hides replies.

What to do in Rampart: Simulate a credential-harvest landing page and teach staff to report, not re-authenticate.

PhishingJune 9, 2026· Fraud prevention casework

One compromised supplier mailbox becomes your payment problem

Attackers watch a genuine invoice thread for weeks, then send updated bank details from the real supplier domain. Nothing about the email is technically malicious.

What to do in Rampart: Assign vendor-fraud training to finance and procurement groups on a quarterly cycle.

RansomwareMay 22, 2026· Incident response retrospectives

Ransomware crews are calling the service desk instead of exploiting software

Operators phone the help desk posing as staff locked out of MFA, get a reset, and walk in with valid credentials. Identity verification, not patching, is the failing control.

What to do in Rampart: Train IT and help desk staff separately with a stricter caller-verification script.

PhishingMay 4, 2026· Email security telemetry

Quishing shifts the click to devices your controls never see

A PDF or poster carries a QR code, the victim scans with a personal phone, and the fake login never touches corporate filtering or endpoint tooling.

What to do in Rampart: Include QR-based lures in your simulation mix, not just link and attachment lures.

ResearchApril 18, 2026· Annual breach research

The human element remains the single largest breach factor

Year after year, breach research puts phishing, stolen credentials and errors ahead of exploited vulnerabilities. Awareness maturity now shows up in cyber insurance questionnaires.

What to do in Rampart: Evidence completion, reporting rate and risk trend — not just training hours.

RegulationMarch 30, 2026· Assessor guidance

Auditors now expect per-person awareness evidence

HIPAA, PCI DSS 4.0, SOC 2 and ISO 27001 assessments increasingly ask who completed what, when, and what happened after a failed simulation.

What to do in Rampart: Keep an immutable audit log and exportable per-employee completion records.

PhishingMarch 11, 2026· Threat intelligence roundups

Gift-card and payroll-change texts still work on new starters

New employees are targeted within days of a public LinkedIn announcement, usually before they finish onboarding training.

What to do in Rampart: Trigger onboarding awareness training on day one, not at the next quarterly cycle.

Turn a headline into a control

Every finding above maps to a course you can assign or a simulation you can launch this week.