Thanks for playing the Fable Security Cybersecurity Awareness Month game! Congratulations, you’re an AI Survivor. Six minutes, five decisions, no time to overthink any of them.
Here’s the part worth sitting with for a second: none of what you just faced was invented for effect. Every situation in this experience is modeled on something that already happened, most of it within the past two years, to real companies with real security teams. We’re not telling you this to scare you. The point isn’t dread, it’s recognition. Once you’ve seen the shape of an attack, it’s a lot harder for the real version to catch you off guard.
Here’s where each one came from.
The Interview: an employee who never showed his face
Earlier this year, the security firm Huntress detailed three separate investigations into suspected North Korean IT worker fraud, one at an Australian healthcare company, two more at financial services firms. In each case, the tells weren’t dramatic, they were small operational details: VPN and proxy usage that didn’t match normal behavior, remote-control hardware tied to past fraud schemes, identity documents with digitally swapped photos, and in one case, a new hire who simply refused to turn on his camera or show the room he was sitting in. None of it looked like a movie hack. It looked like a slightly unusual new employee, until someone added up enough small details to ask questions. (Source)
The connection: what you post is what they use
Security researchers have repeatedly flagged the same pattern: attackers don’t need to hack anything to build a convincing pretext, they just need what you’ve already posted publicly. A shared hobby, a recent trip, a work milestone, it’s often enough to make an unfamiliar contact feel familiar. This isn’t a one-company story, it’s an ongoing trend across the industry. (Source)
The meeting: a familiar face that wasn’t real
Mandiant, Google’s threat intelligence arm, documented a North Korean-linked group luring a cryptocurrency executive into what looked like a routine video call, complete with what appeared to be a deepfaked “CEO” from another company. Partway through, the callers staged a fake technical glitch and talked the victim through “fixing” it, a technique known as ClickFix, that actually installed malware on their device. (Source)
The call: a voice that sounded exactly right
In 2024, a Ferrari executive received WhatsApp messages, then a phone call, from what sounded precisely like CEO Benedetto Vigna, accent included, asking for urgent help with a confidential acquisition. Something about the intonation felt slightly off, so the executive asked the caller to name a book Vigna had recently recommended. The call ended immediately. (Source)
The deadline: a shortcut with real consequences
Earlier this year, a Pennsylvania community bank disclosed to the SEC that an employee, working under deadline pressure, uploaded customer data (names, Social Security numbers, dates of birth) into an AI tool that hadn’t been approved for that use. The bank moved fast enough to stop the data from training the model, but still had to file a formal breach disclosure, and notify both regulators and customers. (Source)
None of the people in these stories were careless. They were experienced professionals at well-run companies, in the first story’s case, companies whose own security teams caught the problem. That’s exactly the point: these tactics don’t rely on you making an obvious mistake. They rely on you being human, moving quickly, and trusting a familiar face or voice. Now that you’ve seen the shape of it once, in six minutes instead of a headline, it’s a lot easier to catch the next time it shows up for real.
If you’re on a security team reading this: this is the exact layer we built Fable to help you strengthen. As Lucas Moody, CISO at Alteryx, put it: “In the age of AI, companies need human-layer defense that’s just as adaptive as the attacks. Anything less is a liability.”
And it’s not just talk, Genesys employees rate Fable training 4.8 out of 5 on average, a number that speaks for itself when the industry standard is training people actively try to click through as fast as possible. Book time with a Fable expert today, and we’ll show you how this can look for your team!
