September is when work starts up again properly. The new term begins, Q4 planning kicks off, budgets reopen, and a lot of the things people rely on get renewed or replaced along the way: certificates, cards, passes, dates in the diary. Alongside all of that comes the ordinary traffic of a busy office, voicemails, polls, and notifications that nobody reads closely because they look like more of the same. After a few weeks of "here's your new one" and "you have a new message", most of it gets processed on autopilot. An attacker in September doesn't need to invent a reason for you to log in. The calendar has already supplied one.
That's what ties this month's five together. Each one makes its request sound like ordinary admin, and each leans on a different reason you might go along with it without checking: curiosity, access you'd rather not lose, something new being issued to you, an event you're looking forward to, and a small social decision that feels like a bit of fun. The callout on each template names the lever, so your team learns to spot the pull rather than the branding.
Download these phishing templates for your in-person security awareness training materials! And check out this list of best phishing simulation tools 2026
Voicemail has become rare enough that a missed one feels like it probably matters.
The Hook: A phone-system notification, sender Voicemail Service, subject New voicemail (0:47), transcript ready, says a message came in from a number you don't recognise while you were in a meeting. It shows the first line of a transcript that cuts off just as it gets interesting, and offers a "Listen to Message" button. Nothing is demanded. The pull is curiosity, and because Teams, Zoom Phone and RingCentral all send this kind of email, it reads as plumbing rather than a request.
Real-World Risk: "Listen to Message" opens a spoofed Microsoft 365 or Google Workspace sign-in "to play your secure voicemail". The audio never existed; the login page is the whole attack. The credentials go to the attacker, and a mailbox as Q4 approaches is full of budget threads and supplier conversations that are worth hijacking.
Learning Moment: Real voicemail lives inside the phone app you already use, so the check is to open Teams or the phone client directly and look there. A sign-in prompt on its own doesn't prove anything either way, since genuine services ask for one too; what matters is whether you reached the page from the email or from somewhere you trust. It's worth saying to your team that curiosity gets far less suspicion than fear, and this template is built entirely on curiosity.
Access you're about to lose is more persuasive than access you've never had.
The Hook: An email from the IT Service Desk says your remote access certificate expires on 30 September and you need to renew it to keep using VPN and Wi-Fi from your laptop. It's procedural, it refers to something most people vaguely know exists but have never touched, and the deadline is close without being aggressive. The "Get Certificate" button promises two minutes of admin now to avoid a locked-out Monday later.
Real-World Risk: The button leads to a cloned Okta or Microsoft Entra sign-in that asks you to authenticate before your certificate can be issued. There is no certificate. The credentials are harvested on entry, and in the better versions the MFA prompt is relayed in real time so the attacker walks away with a live session. Certificate language is useful to attackers because almost nobody knows what a genuine renewal is supposed to look like, so nothing about the page feels wrong.
Learning Moment: Check renewal instructions with your service desk through your usual support channel before following anything in the email. Organizations handle certificates differently, so the rule isn't "this never comes by email"; it's "confirm it with the people who'd actually be sending it". Make the wider point too: an email about a system you don't understand deserves more scrutiny, not less, because "I don't really know how this works" is the state attackers are counting on.
Being issued something new feels like a perk, and perks rarely get questioned
The Hook: A note from Finance says corporate cards are moving to virtual cards for Q4 and your new card is ready to activate in the expense platform. It's tidy and plausible, and there's a small flattery in it, because being given a card means someone trusts you with spend. The "Activate Card" button sits under a line about the old card being retired at the end of the month, which adds just enough movement without anyone feeling pushed.
Real-World Risk: "Activate Card" opens a spoofed Expensify, Concur or Ramp portal behind a company SSO prompt, and the credentials are harvested on entry. The activation flow is the more interesting part. Confirming your old card's last four digits, expiry and billing address is what a real activation might ask, so people supply it. Those details don't give an attacker a working card, but they make a follow-up call or email pretending to be Finance far more convincing, and that's usually where the real damage happens.
Learning Moment: Card changes come through your expense platform or from Finance directly, so reach the platform through your bookmark and see whether a new card is actually waiting. Teach people that a form asking for both a login and existing card details is doing two jobs at once, and the second one almost never gets a second look. If Finance really is issuing cards, a message to them costs thirty seconds and confirms everything.
Nobody has their guard up for something they're looking forward to.
Flattery is the trigger people are least prepared to notice, because it doesn't feel like pressure.
The Hook: An event registration email, sender Event Registration, subject Your attendee pass is ready, says your pass for an upcoming industry conference has been generated and asks you to download the QR code before the event. September and October are peak conference season, so most teams have at least one person who has registered for something and a few more who assume they might have been. The "Download Pass" button feels like collecting a ticket, not signing in.
Real-World Risk: The button leads to a cloned registration platform, in the style of Cvent or Eventbrite, that asks you to sign in with your company account "to link the pass to your profile". Credentials are harvested, and the profile step is a natural excuse to collect job title, mobile number and dietary requirements, all of which help a follow-up call sound legitimate. Because attendees expect to hand over details to event organisers, the whole exchange sits in a category most people never think of as risky.
Learning Moment: A genuine pass comes from the organiser you registered with, to the email you registered with, and you can reach it by going to that platform yourself. If you didn't register for anything, the answer is simple: you don't have a pass. An event you're looking forward to can make a routine-looking email easier to trust, which is why event and travel emails deserve the same pause as finance ones.
A poll is about the friendliest thing that can land in an inbox, and that's the point of it.
The Hook: An email from the People Team says planning for the Christmas party has started and asks everyone to vote on a date and venue before bookings close. It's cheerful, it's early enough to be believable, and September really is when this begins because December venues fill up fast. The poll needs you to sign in "so each vote counts once", which is presented as fairness rather than as a login. The "Cast Your Vote" button is the kind of thing people click while still reading.
Real-World Risk: The button opens a spoofed Microsoft Forms or Google Forms page behind a fake SSO prompt, and the credentials are harvested before any voting happens. This one spreads by itself: colleagues forward it, mention it in team chats, and ask each other which date they picked, which gives it a legitimacy that no security header can undo. A social lure also lands on everyone at once, so the attacker gets a wide net of logins from a single send.
Learning Moment: Internal polls and event planning come through channels your team already uses, whether that's the intranet, a known colleague or a Teams or Slack post. A sign-in requirement isn't the tell, because genuine internal forms often ask for one; the check is to confirm the poll exists through one of those known channels before you type a password into anything the email sent you to. Pair it with a reminder that the emails that feel like fun are the ones people scrutinize least, and attackers are perfectly happy to be fun.
None of this month's templates need you to be frightened. They need you to be in September, a month where new things are handed out constantly and the ordinary admin picks back up, so a fresh certificate, a new card, a pass, a voicemail or a party poll all look like more of the same. The vulnerability isn't any single email. It's the reflex that treats "here's your new one" as information rather than as a request.
Which makes the useful habit a small one. When an email says something has been issued to you or is waiting for you, go and find it where it would actually live: the phone app, the expense platform, the registration site, the intranet. If it's real, it's there. If it isn't, you've just learned everything you needed to know without typing a password. And when that happens, report it through whatever your organisation uses for suspicious messages, because the person who spots one is usually not the only person who received it.
Explore our phishing simulation library and pick the variations that best match the tools your team actually uses.
Want to explore more? Browse our blog for additional templates, and stay ahead of cyber threats with our curated training resources.
Ready to level up? Register for a free trial of Wizer Boost to access our full library of phishing templates and exercises!
Learn how to set up your first simulation in minutes.