Research released by KnowBe4 showed that during the fourth quarter of 2020, phishing emails were on the rise as scammers targeted proactive employees adjusting to working from home.
“Hackers are playing into employees’ desires to remain security minded. We are still seeing some subjects around COVID-19, but it seems users are getting more savvy to those types of ploys. Curiosity is piqued with security-related notifications and HR-related messages that could potentially affect their daily work,” the report said.
In Q4 2020, KnowBe4 examined tens of thousands of email subject lines from simulated phishing tests. The organisation also reviewed “in-the-wild” email subject lines that show actual emails users received and reported to their IT departments as suspicious. The results are below.
Top 10 general email subjects:

- Password Check Required Immediately
- Touch base on meeting next week
- Vacation Policy Update
- COVID-19 Remote Work Policy Update
- Important: Dress Code Changes
- Scheduled Server Maintenance – No Internet Access
- De-activation of [[email]] in process
- Please review the leave law requirements
- You have been added to a team in Microsoft Teams
- Company Policy Notification: COVID-19 – Test & Trace Guidelines
KnowBe4 CEO Stu Sjouwerman said it’s no surprise that phishing attacks related to working from home are increasing, given that many countries around the world have seen their employees working from home offices for nearly a year now.
“Just because employees may be more used to their home office environment doesn’t mean that they can let their guard down. The bad guys deploy manipulative attacks intended to strike certain emotions to cause end-users to skip critical thinking and go straight for that detrimental click,” he explained.
About the author