Security Starts with Awareness

Explore the latest in social engineering, generative AI threats, and cybersecurity strategies to protect what matters most: your people.
Blog post
ClickFix turns employees into the attacker
ClickFix is a social engineering technique that tricks people into manually typing and running a malicious command themselves, using a fake CAPTCHA or verification prompt. Because the victim executes the command by hand, no email filter, attachment scanner or exploit-based defense ever sees it coming (Microsoft, August 2025). ESET tracked a 517% surge in ClickFix attacks over six months, making it the second most common attack vector behind phishing itself (ESET research, June 2025). Someone visits a normal-looking site and hits a page asking them to verify they're human. It looks like the Cloudflare or Google reCAPTCHA check they've passed a hundred times before. A button labeled "Verify" or "How to fix" copies a command to their clipboard, then tells them to open Windows Run, paste, and press enter. They do it because every step feels like routine troubleshooting, not an attack. Nothing gets downloaded. Nothing gets clicked as an attachment. The malware installs because the person typed the command that installed it.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Blog post
ClickFix turns employees into the attacker
ClickFix is a social engineering technique that tricks people into manually typing and running a malicious command themselves, using a fake CAPTCHA or verification prompt. Because the victim executes the command by hand, no email filter, attachment scanner or exploit-based defense ever sees it coming (Microsoft, August 2025). ESET tracked a 517% surge in ClickFix attacks over six months, making it the second most common attack vector behind phishing itself (ESET research, June 2025). Someone visits a normal-looking site and hits a page asking them to verify they're human. It looks like the Cloudflare or Google reCAPTCHA check they've passed a hundred times before. A button labeled "Verify" or "How to fix" copies a command to their clipboard, then tells them to open Windows Run, paste, and press enter. They do it because every step feels like routine troubleshooting, not an attack. Nothing gets downloaded. Nothing gets clicked as an attachment. The malware installs because the person typed the command that installed it.
Blog post
Fake job offers are the new phishing email
Attackers are using real-looking job offers, tailored to a candidate's actual skills, to install remote access malware with a single click. There's no password request and no suspicious link to spot, because the message does exactly what a real recruiter message does (Cyderes, September 10, 2026). Employees who'd never open a random invoice attachment open a coding test, because a recruitment message arrives in a context they've already decided to trust. A software engineer gets a message about a role that matches their actual skills. The company looks real, the pay range is reasonable, and the next step is a short coding assessment, a normal part of any hiring process. They download the file and open it. Nothing about the message asked for a password. Nothing pointed to a mismatched domain. The message did exactly what a real recruiter message does, and that file is what installs the malware.
Blog post
Device code phishing hit 340 organizations
More than 340 Microsoft 365 organizations across five countries were targeted in a device code phishing campaign that started in February 2026 (The Hacker News, March 25, 2026). The technique doesn't steal a password or break multifactor authentication. It gets an employee to approve a login session for someone else, inside Microsoft's own sign-in page. That makes it a human risk problem, not a technical failure, and it slips past training built to catch fake links and lookalike login screens.
How to calculate security awareness ROI
Human risk remains the most exploited access vector in data breaches, and the global average cost of a breach hit $4.88 million in 2024. For security teams at mid-size and large enterprises, the question is no longer whether to invest in awareness training, but how to prove that investment reduces risk in a measurable, sustained way. This guide covers the metrics that matter, the compliance frameworks that require it, the calculation formulas, and the mistakes that distort the results.
Blog post
Why MFA Doesn't Stop This Vishing Attack
A vishing operation Google tracks as UNC6671 called employees at private equity and financial services firms on their personal phones, posed as IT helpdesk staff, and walked them through spoofed login portals. Adversary-in-the-middle infrastructure captured credentials and MFA codes in real time. Google identified 72 spoofed websites built for the campaign and traced more than $10 million in bitcoin to wallets linked to the group between January and May 2026 alone. The attackers didn't defeat MFA outright. A phone call put them in the room for the exact moment a legitimate employee entered a valid code into what looked like the right place, and they captured it as it was used.
Blog post
The Ransomware Readiness Gap Most Plans Don't Test For
Ransomware is malware that encrypts an organization's systems until a ransom is paid, and most readiness programs are built around that moment: backup integrity, recovery time, incident response runbooks. But the technical encryption is usually the last step of the attack, not the first one. Mandiant's M-Trends 2026 report found that the time between an attacker gaining initial access and deploying ransomware has collapsed to as little as 22 seconds in some cases, largely because attackers increasingly get in by calling the IT helpdesk and asking to be let in. A well-documented case shows exactly how far a single phone call can go: one ten-minute call cost a major company more than $100 million. Most ransomware readiness plans have never tested for that call.
Blog post
It Used to Take Real Skill to Write a Phishing Email with a 54% Click Rate. Now It Takes None
A peer-reviewed study by Harvard Kennedy School researchers found that a fully AI-automated spear phishing email reaches a 54% click-through rate, matching an email written by a skilled human expert — with no research time and no writing skill required from whoever sends it. Most phishing defense has quietly relied on a limiting factor that was never written down: writing a genuinely convincing, well-researched attack took real skill, which meant only a small number of attackers could produce one. Generative AI removes that limiting factor entirely. The threat did not get psychologically smarter. It got available to anyone.
Blog post
DORA Covers Five Areas of Risk. Most Compliance Reviews Only Check One or Two.
DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), is the EU law that requires financial entities and their critical technology providers to manage digital risk to a common standard. It has applied since 17 January 2025 across roughly 20 types of financial entities, from banks and insurers to payment institutions and crypto-asset service providers. It covers five areas: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing, plus direct oversight of the technology providers the sector depends on most.
Blog post
MFA stopped account takeover. It didn't stop a $60 million wire transfer
MFA adoption sharply cut how often BEC attacks hit accounts without it in place, real, measurable progress. But the money kept moving anyway, and BEC losses rose again in 2025. We think that gap exists because BEC never really depended on breaking into an account. It depended on a person believing the message came from someone they trust, and no authentication protocol was built to test that.
Blog post
Cybersecurity Training Was Built for a Different Threat. So Were Simulations. We Just Changed Both.
Zepo Intelligence launches two new capabilities this week. Learning Studio generates hyper-personalized cybersecurity training in minutes — so training evolves as fast as threats do. Multiattack Simulations chains phishing and vishing into a single coordinated campaign that pivots on how each employee actually responds. Together, they close the gap between how attacks land and how organizations prepare.
Blog post
Prompt Injection Is the New Social Engineering. Most AI Security Programs Aren't Built for It
Prompt injection has ranked as the top risk in OWASP's assessment of large language model applications for two consecutive editions. It isn't a code flaw a patch will close. It exploits the same psychological mechanics that made phishing and pretexting work for decades, translated into how a language model reads untrusted content.
Fake AI Tools Are the Fastest-Growing Attack Vector of 2026. Your Policy Sent Employees Looking
Employees looking for an AI tool their company hasn't provided don't go looking for trouble. They search for the popular option and click the first result. Attackers know this, and fake AI tools built to look like the real thing are now one of the fastest-growing attack vectors of 2026. This post argues that an AI policy without a clear, easy path to request new tools doesn't prevent shadow AI — it sends employees searching, and searching is exactly where the attack starts.
Blog post
Your EU AI Act Classification Is Complete. Shadow AI Isn't on the List.
The EU AI Act requires organizations to classify every AI system they run by risk level. That requirement assumes a complete list of systems exists. Gartner's own research says it usually does not: 69% of security leaders already suspect employees are using generative AI tools nobody approved, and Gartner expects more than 40% of enterprises to face a security or compliance incident tied to unauthorized shadow AI by 2030. This post argues that the real compliance gap is not legal — it is behavioral, and it is measurable before it becomes an incident.
Blog post
Your ISO 37001 due diligence file could be perfectly accurate, and still completely out of date
Most organizations treat third-party due diligence as a single gate: pass it once, and the relationship stays cleared. That approach assumes the vendor approved on day one is the same vendor a year later. ISO 37001 due diligence exposes what happens when that assumption breaks: ownership changes, a new intermediary enters the deal, the vendor expands into a market nobody reviewed, and nothing in most compliance programs notices. This is not a documentation failure or a reviewer's judgment call. It is a monitoring gap, and it is measurable before it becomes an incident.
Blog post
The compliance program that produces records but not decisions
Most compliance programs do exactly what they were designed to do: produce a record. Modules completed, policies acknowledged, certificates issued. What they do not produce is the decision that matters, when an employee faces a real vendor and a real relationship. 93% of employees say they would report misconduct; only 50% do when they actually witness it (Ethisphere, 2024 Ethical Culture Report). That gap is not a training failure. It is a design problem, and it takes a different architecture to close.
Blog post
The AI risks your compliance team has not modelled yet
Most security and risk leaders built their model of AI risk in 2023: hallucinations, data leaks, unsanctioned tools. That model is now incomplete. Three risks have moved from theoretical to operational: bias amplified at scale, inference from accumulated context, and an accountability gap with no audit trail. Today, 39.7% of workplace AI interactions involve sensitive data (Cyberhaven, 2026 AI Security Report). None of these three look like an AI problem when they surface, which is exactly why they go unmanaged.
Blog post
Your employees know AI hallucinates. They still don't verify.
Most AI literacy programs are awareness programs with a new label. They teach employees what the risks are. They don't change what employees do when those risks materialize under real work pressure. The gap between knowing AI can produce unreliable outputs and building the habit of verifying before acting is a behavior gap, not a knowledge gap. Closing it requires what works for any behavioral security program: repeated exposure, realistic scenarios, and reinforcement at the point of decision.
Blog post
Your employees pass the phishing test. 87.5% still fall for the attack.
Adding a single channel to a phishing attack multiplies the failure rate by six. That is what most security awareness programs are not measuring — and it is the gap where coordinated attacks succeed. This post argues that single-vector simulation produces readiness data that does not map to how attacks actually land, and examines what a testing methodology built for this reality looks like.
Blog post
Your Face Is Now a Weapon. Here's What That Actually Means
Deepfake fraud attempts have grown 2,137% over three years. Voice clones now require as little as 3 seconds of audio. Deepfake-related losses in North America exceeded $200 million in Q1 2025 alone. The threat has moved inside organizations, attackers are impersonating employees in live Zoom calls, generating phishing emails with a 54% click-through rate, and bypassing identity verification in real time. Generic awareness training isn't closing the gap. Real behavior change requires the risk to feel personal, not abstract.
Blog post
How attackers steal passwords through social engineering
Most compromised credentials aren't broken through brute force. They're obtained by convincing the person who holds them. Helpdesk vishing, MFA fatigue, and AI-personalized phishing are the active vectors — and the defence that works has to operate at the human layer.
Blog post
Calendar invite phishing: how a Google Calendar attack bypassed every perimeter control
On March 17, an attacker sent a Google Calendar invite for a $399.77 charge that wasn't real. There was no link to click, no attachment to detonate, and DKIM passed. The only piece of the attack that mattered was a phone number. Here's why every perimeter control failed, and where the defense actually lives.
Blog post
AI social engineering in 2026: why phishing simulations built on last year's templates are the wrong defense
Targeted social engineering used to require hours of manual reconnaissance. AI removed that ceiling. Personalized, multi-channel attacks now take seconds to build — and most simulation programs still test only email.
Blog post
The architecture gap: why your security gateway and your training program have never shared a single data point
Your security gateway logs every threat targeting your employees. Your training platform runs on a quarterly calendar. These two systems were built for different buyers, measured by different metrics, and were never designed to exchange data — and that gap is where incidents happen.
News
Zepo Intelligence: the first cybersecurity ecosystem to connect threat detection with human risk management
Zepo Intelligence is now the first cybersecurity ecosystem for human risk — a platform where real-time threat detection and security training share a single data model. Every blocked attack immediately informs training. Every behavioral signal refines how protection is applied.
Blog post
What every regulation now requires from your cybersecurity training program — and why completion rates fail all of them
Modern cybersecurity regulations have shifted from "completion" to "competence," leaving organizations legally vulnerable when they prioritize annual check-boxes over actual behavioral change. Discover the five documentation gaps that fail regulatory scrutiny and how to build a training program that is truly defensible after an incident.
Blog post
One call to a vendor. 15,661 records exposed. The Ericsson breach shows where security awareness ends.
A single vishing call to a third-party vendor gave attackers access to Ericsson customer data for five days — and Ericsson wasn't notified for seven months. The gap most security awareness programs don't cover is vendor employees. Here's how to start bridging it.
Blog post
Deepfakes don't exploit technology gaps. They exploit obedience.
The industry narrative around deepfake attacks focuses on how convincing the technology has become. That framing misses the point. Deepfakes succeed because they activate the same behavioral patterns organizations have spent years reinforcing: defer to authority, act on urgency, don't question leadership. Security leaders report near-universal confidence in their defenses, yet only 8.4% of organizations scored above 80% in simulated detection exercises. Detection tools are a losing arms race. The defensible skill is verification: building a culture where people pause and confirm regardless of how real something looks or sounds.
Blog post
The leak of 47 political leaders: A case study in context-driven risk
A recent breach has exposed the personal data of 47 high-profile Spanish politicians, including regional presidents and high-ranking officials.
News
Zepo Intelligence Selected for the 2026 CrowdStrike, AWS & NVIDIA Cybersecurity Startup Accelerator
Zepo Intelligence, an agentic social intelligence platform for workspace security, has been selected to participate in the 2026 Cybersecurity Startup Accelerator with CrowdStrike, Amazon Web Services (AWS) and NVIDIA through its Inception program, to help fuel the next generation of AI-driven cloud security innovation.
FraudGPT: what security leaders need to know in 2026
AI tools like FraudGPT have made convincing phishing attacks accessible to anyone with a subscription. Here's how the threat has evolved since 2023 and why the defense is behavioral, not technical.
News
Zepo Intelligence Raises $15M Seed Round to Protect Workspaces from AI-Driven Social Engineering
Zepo Intelligence, the company redefining human-centric security, announced today the closing of a $15 million Seed investment round. The round includes three European VCs with strong focus in cybersecurity, Kibo Ventures, eCAPITAL and TIN Capital, and will allow Zepo to expand its team and scale its proprietary technology globally as AI-driven social engineering rapidly escalates into one of the most persistent and costly challenges for security leaders in modern organizations.
News
Tangos, technology, and trust: a recap of our week in Buenos Aires
From exclusive roundtables at Happening Costanera to the bustling floor of IT Forum Financiero, our team spent an incredible week connecting with the heartbeat of LATAM’s financial sector.
News
The Art of Connection
In the relentless pursuit of goals and deadlines, sometimes the most productive thing you can do is pause, reconnect, and look at the world through new eyes.

How Zepo helps companies

When everything connects, results follow

Paula Pereira

Digital Information Security Manager

“I would recommend Zepo to colleagues at other companies because I believe it has met all our needs. It has allowed us to run three types of campaigns that other tools we have tried simply cannot do. And beyond the product itself, the support from the whole team has helped us get far more out of it.”

+9K

Employees Protected

–10%

Click Rate on Attacks

+18%

Training Completion Rate

Ramon Fernandez Blanco

Cybersecurity & Digital Product Manager

“Since implementing Zepo, employee awareness has increased significantly. Employees now actively discuss cybersecurity and phishing campaigns, and suspicious emails are quickly reported instead of ignored.”

+600

Employees Protected

–15%

Credentials Submitted

+26%

Training Completion Rate

Jonathan Nelson

Director of Risk Intelligence

“Zepo’s vision for a real-time, hyper-personalised, multi-platform cybersecurity solution is truly unique and stands head and shoulders above the competition.”

+100

Employees Protected

Get Smarter Before Attackers Strike.