When company news becomes a phishing target

Company social media posts can give scammers what they need for convincing phishing attacks. Here's how to stay safe.

19th August 2026

Picture of Kate Nordbruch
Kate Nordbruch
Operations Director
Andrew

Having an online presence and announcing company news is an important part of building relationships with your customers and celebrating success in the modern business world. But it’s worth thinking about how the small details you share on your company socials could leave you vulnerable to phishing scams and attacks. 

A scam we’ve seen recently targets new employees at businesses, with scammers gambling on the fact that they will be less familiar with company procedures and may not have been enrolled in cyber security training yet. Information is gathered from ‘welcome to the team’ posts on company social media or ‘new role’ announcements on LinkedIn.

From this, it’s then very easy to guess that employee’s new email address and target them. The scammer will then set the display name of a generic email account to match the name of a senior person in the company – easily obtained from a quick visit to your website or Companies House. 

Posing as the senior employee, the scammer then emails a request – ‘I need you to purchase some gift cards for a client. Send me the codes and I’ll reimburse you. Can’t call now as heading into a meeting.’

The new employee, eager to impress in their new role, may be tempted to action the request immediately, but just a few seconds of caution can prevent them from being duped. 

  1. Always question requests that imply urgency – scammers rely on you reacting before thinking.
  2. Check the email address matches the display name and is a known and expected email address.
  3. Verify requests for payment or confidential information in-person or by a phone call to a number you already hold on file.  

Now, none of this is to say you shouldn’t share news on social media. You should absolutely continue celebrating and sharing, but it is important to be mindful that this information could be used for scammers to create convincing phishing emails. That’s why regular cyber security training for your staff is so important from day 1. 

If you don’t currently have ongoing cyber security training for your staff, talk to us at Wight Computers. It is a core part of all our support packages because we know it works to keep your company data safer and more secure.

An annual, one-off session just doesn’t cut it anymore. Through regular training videos and simulated phishing emails, staff enrolled on our training are practising spotting these red flags all the time, building the likelihood they spot and avoid a genuine phish.  

Our customer (referred to above) did the training, and they spotted and reported the attempted phish. Training and maintaining a vigilant attitude works – simple as that.

Any questions?

If you have any questions in relation to this blog post, contact us. We would be more than happy to help!

Subscribe to our newsletter

Here at Wight Computers Ltd we take your privacy very seriously, and will only use your personal information to communicate with you and provide the products and services you have requested from us.

You can unsubscribe or change your preferences at any time by clicking the link in the footer of our emails.

For more information, please read our Privacy Policy.

To use reCAPTCHA V3, you need to add the API Key and complete the setup process in Dashboard > Elementor > Settings > Integrations > reCAPTCHA V3.
Share this blog

More Articles