‘They risk damaging confidence’: A Canadian health board outraged staff with phishing tests offering paid leave – experts say it shows why you need to be careful with cyber awareness campaigns
Phishing tests require a delicate touch, emulating realism while not “exploiting goodwill”
Security experts have urged organizations to take a more considerate approach to cyber awareness training after a Canadian health board sent emails to staff offering paid leave as part of a phishing test.
Ron Johnson, interim chief executive at Newfoundland and Labrador Health Services, apologized for the phishing test last week, admitting the emails were sent in poor taste.
“We acknowledge the approach taken in this particular exercise was not appropriate, and we sincerely apologize to employees, physicians, and union representatives,” he wrote.
The phishing simulation prompted backlash after being circulated to hundreds of employees, and has since prompted a review of future activities, Johnson added.
“We value the feedback and are reviewing how future awareness exercises are developed and communication,” he said.
“It is important they reflect employee and physician perspectives, as well as our organizational values to foster a respectful and supportive workplace culture.”
This isn’t the first time an organization has been forced into a U-turn after a controversial phishing test campaign.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
As ITPro reported in late 2024, the University of California Santa Cruz (UCSC) was heavily criticized for a “tone deaf” campaign which used a fake Ebola virus track and trace alert.
The campaign caused a panic on campus and was highly convincing, even employing links to a fake webpage set up to support those affected by the “outbreak”.
Phishing tests are a vital part of cyber hygiene
While this particular incident sparked ire among employees, phishing tests are a common practice by cybersecurity professionals to ensure staff remain vigilant to potential security threats.
Phishing attacks, in particular, are a leading cause of breaches at organizations across a range of industries – and the healthcare sector specifically is a prime target for cyber criminals.
Add AI into the equation, and the threat landscape faced by enterprises today is becoming increasingly perilous, with threat actors using the technology to refine techniques and curate highly convincing emails.
Rob Anderson, head of reactive consulting services at Reliance Cyber, told ITPro that the “best phishing exercises are realistic” – after all, they are intended to emulate the tactics used by cyber criminals.
"They should use the same sneaky tactics that threat actors may use, hopefully triggering the trained, instinctive suspicion we want staff to develop when handling unexpected emails,” he said.
“However, there is a fine line. Nobody likes to be made a fool of, especially at sensitive times.”
Anderson pointed to a phishing exercise by one UK police force’s Information Protection Unit, which circulated emails targeting staff in a typical fashion. Those who fell foul were met with a message stating: “whoops, you’ve failed this training”.
In this instance, Anderson said the Information Protection Unit had “failed to read the room”.
“A week earlier, the force had announced a restructure, with likely compulsory redundancies and transfers,” he said. “Police officers can be a vocal and cynical bunch, and they made their feelings known.”
A delicate balancing act
It’s here that phishing tests often become a delicate balancing act, according to Simon McNalley, identity and access management (IAM) technical director at Thales.
Ultimately, cybersecurity professionals need to ensure that simulations are “realistic enough to reflect the tactics attackers use” without “exploiting goodwill”.
“Scenarios involving pay, bonuses, annual leave, personal hardship, or other highly sensitive employment matters should be approached with caution, as they risk damaging confidence in legitimate internal communications,” he told ITPro.
Anderson echoed McNally’s comments, adding that human resources (HR), communications, and senior leadership should be consulted before campaigns go live.
Ultimately, McNally said the NL Health Services incident should serve as an example to other organizations hoping to keep staff on their guard in light of rising threats.
“There is a place for phishing simulations as part of building cyber awareness, especially as attackers routinely use such techniques. However, it’s vital that these exercises do not come at the expense of trust between employer and employee. Trust is a critical component of security culture,” he said.
“If awareness programs leave employees feeling misled, embarrassed or manipulated, organizations risk undermining the very behaviors they are trying to encourage.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware
-
Two US nationals sentenced for role in prolific fake worker laptop farmsNews The Americans were raising money for the North Korean regime by allowing fake IT workers to appear as legitimate US-based employees
-
Beware of emails threatening a code of conduct reviewNews A widespread phishing campaign has targeted tens of thousands of employees
-
‘The inbox is no longer the only frontline’: Phishing attacks are evolving as cyber criminals ramp up ‘multi-channel’ campaigns over email and Microsoft TeamsNews New research shows threat actors are ramping up “multi-channel” phishing attacks by combining lures via email and Microsoft Teams
-
Tycoon 2FA is down, but not out – researchers warn the phishing as a service operation is still a huge threat to businessesNews Millions of Tycoon 2FA attacks are still hitting businesses, according to research from Barracuda
-
Zephyr Energy hackers swiped £700,000 after redirecting a contractor paymentNews Payment to a Zephyr Energy contractor was siphoned off, but the incident has been contained and new security measures implemented
-
Microsoft and NCSC issue alerts over hacker campaigns targeting WhatsApp, Signal messaging appsNews Microsoft warns about a sophisticated attack that starts with WhatsApp messages, while the NCSC says such incidents are on the rise
-
'AI-generated phishing became the baseline' for hackers last year – Kaseya warns it's going to get worse in 2026News Forget looking for typos and bad grammar, phishing campaigns are using AI to boost their attack success
