August is the month everyone comes back. The office fills up again, the calendar reloads, and somewhere around the second morning you sit down to an inbox holding three weeks of things you didn't see happen. Most people don't read that inbox. They process it, at speed, in a state of mild guilt, looking for the handful of items that still matter. An attacker doesn't need you to believe the email. They just need you to file it.
That's the thread running through this month's five. None of them are trying to scare you into acting. They're trying to look like one more item in a queue you're already clearing, and each one leans on a different reason you'd wave it through: routine, access you're about to need, curiosity, flattery, and something owed to you. The callout on each template names the lever, so your team learns to spot the pull rather than the branding.
Download these phishing templates for your in-person security awareness training materials! And check out this list of best phishing simulation tools 2026
There is a particular kind of phish that dresses up as the thing meant to stop it.
The Hook: An email security digest, subject 12 messages quarantined while you were away, lists a handful of held senders with dates and a "Review and Release" button. Some of the names look like real suppliers. It arrives in the exact week you're expecting a backlog of held mail, and the whole point of a quarantine digest is that you skim it and act. There is no urgency in it at all, which is precisely why it gets through.
Real-World Risk: The "Review and Release" link opens a spoofed quarantine portal that asks you to sign in to Microsoft 365 before it can show your held items. The credentials go straight to the attacker, and mailbox access in the first week back is unusually valuable: it's full of half-finished threads, delegated approvals, and people apologising for slow replies. That's ideal cover for a follow-up message that nobody questions.
Learning Moment: Quarantine lives inside your security portal, and your IT team can tell everyone exactly where that is. Teach people to review held mail from that portal or from within their mail client, never from a link in the digest itself. It's worth saying out loud to your team that a phish can absolutely impersonate the tool that catches phishing, because most people have never considered it.
Access you're about to need is more persuasive than access you already have.
The Hook: A note from Facilities says your building access has been suspended after 21 days without an entry scan, and invites you to reactivate before your first day back. It's dull, it's procedurally plausible, and it lands with a small practical worry attached: standing outside your own office looking foolish. The deadline isn't threatening. It's just the day you already planned to return.
Real-World Risk: The "Reactivate Badge" link leads to a spoofed facilities or identity portal that harvests SSO credentials. The more interesting harvest is the rest of the form. Employee ID, office location, floor, sometimes a manager's name, all of it volunteered because a badge reactivation would reasonably ask. That's a ready-made pretext for a phone call to the service desk, or for someone standing at your door with a plausible story about a broken pass.
Learning Moment: Physical access problems get solved by people, not by links. Reception, Facilities, or the service desk on a number your team already knows. Point out that a request asking for both a login and your employee details is doing two jobs at once, and the second one usually gets no scrutiny at all.
Nobody has their guard up for a photo.
The Hook: A shared album notification, sender either the People Team or a named colleague, announces that the summer social photos are up and mentions you appear in fourteen of them. The pull is curiosity with a thread of self-consciousness running through it, the small need to know how you came out. It's also the rare work email people genuinely want to open, and it forwards itself around a team without anyone pausing on the link.
Real-World Risk: "View Album" opens a convincing Google Photos or SharePoint sharing screen that asks you to sign in to confirm you're on the invite list. That extra step feels like a privacy control, which is why it works. Credentials are harvested on entry, and because photo sharing is normal social traffic, the click happens outside the mental category most people reserve for suspicious email.
Learning Moment: A genuine shared album opens for someone already signed in, so being asked to authenticate to view photos is the signal, not the reassurance. Tell your team to open the sharing platform directly and look for the album there, and to check with whoever supposedly shared it. Worth pairing with a reminder that social and low-stakes emails deserve the same pause as financial ones, because attackers know exactly where the guard drops.
Flattery is the trigger people are least prepared to notice, because it doesn't feel like pressure.
The Hook: An email from Internal Mobility says your profile has been matched to an open role and invites you to review the details before applications close on Friday. Nothing is demanded. You've simply been noticed. In the first weeks back, when a lot of people are quietly reconsidering their year, that lands harder than any warning could, and the soft deadline supplies just enough movement.
Real-World Risk: "View Matched Role" leads to a cloned Workday or internal careers portal. Beyond the credential harvest, this one is unusually likely to succeed on the second attempt: someone who wants the role will retry a failed login rather than abandon it. Because these platforms usually sit behind the same SSO as everything else, one determined re-entry can open payroll, personal data, and internal systems that have nothing to do with a job posting.
Learning Moment: Internal roles are visible from inside the careers portal you already have access to, so the check is simply to go and look for the posting yourself. Make the broader point explicitly with your team: phishing that compliments you is still phishing, and the emails that feel good are harder to question than the ones that feel bad.
Money you're owed pulls just as hard as money you're about to lose, and it doesn't put anyone on edge.
The Hook: A recognition platform notification tells you 4,200 unredeemed points expire on 31 August and links you to the rewards catalogue. It's cheerful, it's specific, and the deadline is genuinely close. Recognition platforms send exactly this email in exactly this tone, and most people have only the vaguest idea of their balance, which means the number is unverifiable and therefore accepted.
Real-World Risk: "Redeem Points" opens a spoofed rewards portal behind a company SSO prompt. Credentials are harvested, and the redemption flow gives an attacker a natural excuse to ask for more: a delivery address, a personal email for the voucher, sometimes a phone number "to confirm the reward". That combination supports the follow-up, whether that's a smishing message or a service desk call with enough personal detail to sound legitimate.
Learning Moment: Reach the rewards platform the way you normally would, through your bookmark or the company portal, and check the balance there. The habit worth teaching is that a pleasant email gets the same treatment as an alarming one. If your team can only remember one rule, make it this: the emotion an email produces tells you nothing about whether it's real.
None of this month's templates need you to panic. They need you to be busy, and in August almost everyone is. The return wave produces a very specific state of mind: fast, forgiving, keen to get the pile down to something manageable by Friday. That state is the vulnerability, not any individual email in it.
Which makes the useful habit a small one. Not scrutinising every message, because nobody catching up on three weeks is going to do that. Just reaching the real thing directly when an email asks you to sign in, whether it's a quarantine portal, a badge form, a photo album, a job posting, or a rewards balance. Clearing your inbox is not the same as reading it, and the difference is where attackers do their work.
Explore our phishing simulation library and pick the variations that match the tools your team actually uses.
Explore our phishing simulation library and pick the variations that best match the tools your team actually uses.
Want to explore more? Browse our blog for additional templates, and stay ahead of cyber threats with our curated training resources.
Ready to level up? Register for a free trial of Wizer Boost to access our full library of phishing templates and exercises!
Learn how to set up your first simulation in minutes.