Field Notes – What bank warnings about spear phishing actually miss

What institutional phishing guidance gets right, what it sidesteps, and why the gap between the two is where modern attackers live.

Banca Migros published a warning to employees this month. Read it: check sender addresses carefully, even with known contacts; question unusual or urgent requests; clarify via a second, independent communication channel; stick to approval processes no matter how urgent the request seems.

Solid advice.
Recognizable to anyone who has spent time in security awareness, the kind of thing that belongs in an onboarding deck and gets forgotten by Friday afternoon.

The problem is not the advice. The problem is what the advice implicitly assumes about the threat — and what that assumption has quietly stopped being true.

The threat the checklist was designed for

Spear phishing, as Banca Migros describes it, is a targeting problem. Attackers research their marks, know names and roles and internal processes, and craft messages that appear to come from trusted sources with plausible urgency. The solution, as classically framed, is procedural: slow down, verify, follow process.

This framing made complete sense for a long time. The attacker’s advantage was asymmetric information — they knew more about your organization than you knew about them. The defender’s response was friction: add a step, add a channel, add an approval gate. Each additional step increased the cost of a successful manipulation and gave the target a moment to pause.

The checklist evolved to address the attacker’s core technique, which was impersonation through text. A fake email. A spoofed sender. A forged PDF.

What the checklist was not designed for is what the attacker has become.

What the attacker has become

The modern spear phishing operator is not primarily running text-based impersonation, and text impersonation is now the entry-level technique, the thing you use on low-value targets when you do not have the time or the information to do it properly.

For anything meaningful (read it: a wire transfer, a credential handoff, access to a privileged system) the attacker now arrives with context; not just a name and a title, but a plausible pretext assembled from publicly available information: LinkedIn activity, press releases, job postings, conference schedules, org-chart inference from email signatures, GitHub commit metadata, Slack workspace configurations visible through OAuth app integrations. The kind of reconnaissance that used to take a dedicated team days now takes an AI-assisted workflow hours, sometimes less.

This matters because the second channel check, the one Banca Migros recommends as the procedural safeguard, assumes that the attacker’s presence is limited to the communication channel being questioned. Call the person back on a known number. Send a separate email. Confirm through an internal system.

What happens when the attacker already knows what the legitimate counterpart said in their last three messages, knows the project name, knows the tone, knows that the CFO is traveling this week because they posted it on LinkedIn and checked in at the airport? The second channel does not fail because the target is careless. It fails because the attacker has enough context to pass the verification the target is attempting.

Context weaponization is the technique the checklist cannot address. Not because the checklist is wrong, but because it was designed before context became cheap.

The compliance problem hiding inside the training problem

There is a second issue, quieter and more structural, embedded in the Banca Migros guidance: “stick to internal approval processes, no matter how urgent the request seems.“

This is correct. It is also the instruction that gets bypassed most reliably in real incidents, not because employees are reckless, but because approval processes carry implicit social costs. Questioning a request from a senior figure inside the organization is not procedurally complicated. It is… socially uncomfortable! It activates deference hierarchies that employees have spent their careers navigating correctly.

The attacker who impersonates an executive is not primarily exploiting a gap in the approval process. They are exploiting the social architecture around it, the part that says questioning someone senior, in front of others, on a time-sensitive matter, is career risk.

No checklist addresses that: awareness training that explains the threat intellectually but does not build the behavioral muscle to act in the moment of real social pressure is training that produces informed employees who still comply.

I keep coming back to the same observation: the gap between knowing and doing is wider than most training programs acknowledge. And that gap is exactly where spear phishing operators live.

What the warning is really saying

To be fair to Banca Migros, what they published is the correct first-order response for an organization communicating a threat to a non-specialist audience. The advice is not wrong. It is genuinely useful for the majority of employees who will encounter unsophisticated attempts.

The harder question is what organizations are building underneath the checklist. Whether the three steps are a floor or a ceiling. Whether simulations are testing employees against fake CEO emails with slightly wrong sender domains, the obvious version of the attack, or whether they are testing against the scenario where the context is right, the pretext is plausible, and the social pressure is real.

Most organizations are testing the former: the attacker has moved to the latter.

That is not an argument against publishing the checklist. It is an argument for understanding what the checklist does not cover, and building toward it, because the version of spear phishing that gets past your awareness training is the one that was designed to look exactly like legitimate communication.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top