- › Fraudsters are sending fake 'we noticed a login from a new device' alerts to make people surrender their own passwords.
- › It works because security teams spent years training people to treat account-security warnings as urgent and act on them fast.
- › The person who reacts to the fake alert is doing exactly what we told them a good, security-conscious user does.
- › The fix belongs in the design of the alert: a real alert should never ask you to click a link or type a password.
- › Move verification inside the app the person already trusts, and the fake alert loses the reflex it depends on.
An email lands on a Sunday afternoon. “We noticed a login from a new device,” it says, and the location is a city you have never been to. Your stomach drops. Someone is in your account. You click the link, you enter your password to lock the stranger out, and in the time it takes to do the responsible thing, you have handed your credentials to the person who sent the email.
That scam is making the rounds again, aimed at X users, engineered to turn a moment of genuine vigilance into a theft (The Guardian). It is easy to read that story and land on the usual verdict: people should be more careful, should have checked the sender, should have known better. I want to push back on that verdict, because it misses who taught the person to react that way in the first place.
We did. The security industry did.
The Reflex Was Installed on Purpose
Think about what we have spent the last decade telling people. Watch for unusual account activity. If you get a login alert you do not recognize, act immediately. Do not ignore security warnings. Change your password the moment something looks wrong. Speed is safety.
We ran the campaigns. We sent the posters. We built the training modules that reward the employee who reacts fast to a security warning and gently scold the one who shrugs it off. And it worked. We successfully installed a reflex: an account-security alert means urgency, and urgency means act now.
The attacker did not have to build that reflex. We built it, tested it, and reinforced it on a schedule. The fake alert is just a key cut to fit a lock we spent years installing in people’s heads. When someone clicks that link and types their password, they are doing the exact thing a conscientious, security-aware person was trained to do, at the exact speed we asked for.
That is the uncomfortable part. The victim of this scam is often our best student.
Stop Calling It Human Error
When this goes wrong, the incident writeup almost always reaches for the same phrase. Human error. The user fell for a phish. And once you have named it that way, the fix writes itself: more training, a sterner tone, another simulated phishing test to generate a number for the board.
I have watched this cycle run for years, and it does not work, because it is treating a system problem as a character problem. The person gave a correct response to a convincing forgery of a signal we told them to trust. The failure sits upstream, in a flow that made the forgery easy. You cannot train your way out of that, because the training is part of what makes the forgery land. Turn up the urgency messaging and you make people twitchier, faster to click, more primed for the next fake alert. You are widening the hole and calling the widening “awareness.”
The honest question is not “how do we get people to stop reacting to security alerts?” We spent a decade begging them to react. The question is “why does reacting to a security alert require the person to do something dangerous at all?”
The Design Flaw Hiding Inside the Scam
Sit with the mechanics of the real thing for a second, because the scam only works by imitating it.
A legitimate service notices a new login. It wants to tell you. So it sends an email with a link, and the link goes to a page, and the page asks you to sign in to review the activity. That is the genuine flow at a lot of companies. Now look at what the attacker has to do to impersonate it: send an email with a link that goes to a page that asks you to sign in. The forgery is trivial because the real thing already trained you to accept every step of it. The attacker is imitating a flow that was already shaped like a phish, one the real service taught you to accept.
The security signal and the attack share a delivery method. That is the flaw. We put the alert in the one channel we do not control and cannot authenticate, the inbox, and then we asked the person to authenticate themselves from inside it. Every honest login alert that follows that pattern is a rehearsal for the fake one.
Design the Alert So the Fake One Has Nothing to Copy
Here is where the systems view pays off, because once you see the problem as a design flaw, the fixes move from the person to the flow. None of this is exotic. It is mostly a matter of treating the human’s instinct as a given to design around.
Move verification inside the app the person already trusts. The alert can arrive by email, but resolving it should happen in a place the user opened themselves. “Open the app and check your active sessions in Settings.” No link to click, no password to enter from a message. If the only safe action lives behind the door the person already knows how to open, the emailed link has nothing to offer.
Make the real alerts unspoofable, then say so. Companies that show account activity inside a signed-in dashboard, and tell users plainly that they will never be asked to log in from an alert email, give people a rule simple enough to hold under stress: a message asking you to sign in to check your security is the tell. That rule only works if the company’s own genuine messages never break it. The moment marketing sends one “click here to secure your account” email, the rule dies.
Reward the pause. Inside your own organization, look at what your training actually reinforces. If every drill and every poster prizes the fast reaction, you are coaching the exact behavior this scam needs. Teach and reward the two-second pause where the person navigates to the site themselves instead of following the link. The goal is a workforce whose trained instinct is to verify through a channel they chose, and you build that instinct by rewarding it. The same principle runs under everything in behavioral security: behavior follows what the environment rewards.
Give people a real reporting path and make it safe. The person who half-fell for this and caught themselves is your best early-warning sensor, and they will only tell you if telling you is safe. If reporting a near-miss gets someone a lecture, you have designed a culture where the near-misses stay quiet until one becomes a breach. Make reporting a fake alert a thirty-second, no-blame action, and thank the people who use it.
The Person Was Never the Problem
I keep coming back to the individual in this story, the one who clicked on a Sunday afternoon trying to protect their own account. Everything they did was downstream of what we taught them. They believed a security alert mattered. They acted quickly. They tried to lock out an intruder. We asked for every one of those responses, and then we built a login-alert flow that turned all of them into a trap.
The same pattern shows up everywhere I look in this work. What gets labeled a people problem is almost always a systems problem wearing the person’s name, the way a good employee running a malicious command points at the workflow that set them up. Calling the person on the other end of the fake alert the weak link gets it backwards. They are the part of the system doing exactly what it was designed to do, against a forgery of the one signal we told them to trust.
So the fix is a redesign of the alert, one that finally makes being careful and being safe the same action. Put the safe action inside a door the person already trusts, promise them the real messages will never ask for anything else, and keep that promise. Do that, and the fake “we noticed a login from a new device” has nothing left to imitate.
If you want to know where your own people are being set up to fail by the systems around them, that is the work we do. Start with our free Human Attack Surface Score, or contact Grab The Axe and we will look at it together.
With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.
View Author Page →