Why Business Transitions Are Prime Time for Cyberattacks
Most security programs treat training like a fixed calendar item: Set it once, run it on schedule, revisit it next year. That works fine when the business is standing still. Mergers, layoffs, leadership changes, and restructures don’t wait for the training calendar — and neither do the attackers exploiting them.
If you’ve just announced an acquisition, a restructuring, or a leadership change, you probably sense what’s coming: A spike in phishing attempts you won’t be able to stop, only clean up after. It’s a predictable pattern that you can prepare for.
Here’s the kind of thing playing out inside a lot of companies right now.
A mid-level finance employee gets an email three days into a merger, from someone on the “integration team” org chart the company sent around last week. It asks her to update wire instructions for a vendor by end of day. The old accounts are being consolidated.
She’s never met this person. She’s never met half the people on that org chart. Everyone’s inbox has been full of unfamiliar names for a week. She updates the instructions. It takes four minutes, and it feels exactly like the kind of quick, cooperative move that gets noticed in a new organization.
Nothing about that email was technically sophisticated. It just needed to arrive at a moment when “I don’t recognize this person” had already stopped meaning “something’s wrong.”
What counts as a business transition
A business transition is any organizational shift that disrupts the routines, communication patterns, or authority structures people rely on to make fast judgement calls. It’s a wider net than most security programs plan for. It includes:
- Mergers and acquisitions (M&A)
- Leadership changes
- Restructuring and workforce reductions
- Major technology rollouts
- Seasonal shifts, like holiday staffing changes
What connects them has nothing to do with the size of a company. Each one temporarily breaks the shortcuts people normally use to judge whether an email request is legitimate, which is the core of business transitions cybersecurity risk, a recurring window that opens every time the organization changes shape.
Semperis’s 2025 Holiday Ransomware Risk Report found something similar: Roughly six in ten ransomware attacks followed a major corporate event, an IPO, a merger, or a round of layoffs. 54% of those followed a merger or acquisition specifically.
The risk isn’t generic; it’s a pattern
Different business transitions don’t raise risk in the same generic way. They tend to spike specific kinds of manipulation, on a schedule predictable enough to plan around.
Retail organizations, for example, see a measurable spike in opportunity-based attacks every October through January, tied to holiday shopping urgency and seasonal hiring surges.
Around a merger, the pattern shifts toward obedience and authority: M&A cybersecurity risk concentrates in the weeks surrounding a deal announcement and close, when reporting lines are still unsettled.
Restructuring changes the pattern again. With layoffs, the risk has less to do with any one person’s reaction and more to do with the uncertainty a reduction in force creates across the team. This is the shape that layoffs cybersecurity risk usually takes.
Because these patterns are predictable, a security team can get ready before the risk shows up, instead of only cleaning up after.
(What Business Continuity Means for Your Human Layer covers the bigger picture of human-layer continuity. This post is about one specific piece of that: The window a transition opens, and how to get ahead of it.)
Why cybercriminals treat change as an opening
Social engineering doesn’t need to look suspicious to work. Most people assume it succeeds by standing out — some obviously fake email a sharp employee would catch.
During a transition, it works the opposite way: It blends in, because everything already looks a little unfamiliar. Verizon’s 2026 Data Breach Investigations Report picks up on this, too. Its theme for the year is “keeping a strong foundation in the face of change.”
The report notes attackers are leaning more on voice calls (vishing) and other phone-based methods to catch people off guard during the workday. The human element showed up in 62% of breaches this year.
New processes feel normal, even the ones nobody’s actually trained on. An employee is told she needs access to a new shared platform now that two companies are combining systems. An email arrives with a login link and a note to set up her account before the switchover date. She’s never used this vendor and has no idea what the real invite should look like, but the timing matches exactly what IT told her to expect.
She clicks, signs in with her usual credentials, and that’s the entry point. The email itself wasn’t suspicious. It just matched the dozens of other unfamiliar system notices already landing in her inbox that month.
Authority gets harder to read
A request comes in from someone whose title is “VP of Integration” or “Transition Program Lead,” a role that didn’t exist at the company a month ago. Nobody’s sure whether it’s a real approval chain or a title someone made up because it fits the moment. Under a new org chart, most people aren’t confident enough to say no, and that confusion is exactly the moment obedience-based attacks are built for.
The pressure to move fast makes judgment worse
Business transitions run on momentum, and most employees pick up fast that hesitation reads as friction. If someone’s manager asks them to fast-track an approval because “leadership wants this closed before Friday’s town hall,” they know pushing back is the kind of thing that gets noticed for the wrong reason.
Nobody wants to be the person who challenged the new CFO’s assistant and turned out to be wrong. Verification starts to feel like the risky move instead of the safe one.
Stress compounds poor decision-making
A Pacific Northwest National Laboratory study found that each one-point rise in self-reported distress raised the odds of clicking a phishing email by 15%. Transitions almost always raise stress, whether the news is good or bad for the people living through it.
A handful of predictable emotional levers — obedience, fear, curiosity, opportunity — get turned up at once, on people who were doing their jobs perfectly normally the week before. That’s pressure, not carelessness.
Why the usual training misses the moment
Most cybersecurity awareness training assumes stable workflows, familiar communication patterns, and an attack rhythm that’s fairly predictable. A transition throws all of that off, and context disappears: A password reset notice sent out during a real systems migration looks identical to a fake one sent by an attacker counting on that migration to provide cover.
Employees have no reliable way to tell the difference between “the company is genuinely changing how this works” and “someone is exploiting the fact that the company is changing how this works.” From the inside, those two things look the same.
Everyone reacts differently, and generic messaging misses most of them. One employee complies quickly with anything that looks like it came from new leadership. Another clicks a link purely out of curiosity about what’s changing, and a third just wants to be the one who got it done.
A single script aimed at “the average employee” will land for almost nobody. That’s the real argument for treating organizational change security risk as its own category, one that needs more than a single annual module.
Risk stops being evenly spread and starts concentrating, often into the first few weeks after a deal closes, or a new leader starts. It’s timed for exactly when a company’s routines are least settled.
According to the Verizon report, ransomware grew to 48% of all breaches this year. An awareness training calendar built around quarterly or annual cadence has no way to notice that window opened.
What a real response looks like
Cybersecurity leaders who treat business transitions as real inflection points tend to do a few things differently.
They swap generic phishing examples for ones close to the real thing
A fake integration-team wire request, or a login invite for a tool that doesn’t exist yet, not a generic prize notification nobody would fall for. People need to see something close to the real thing before an attacker hands them one for real.
They coach the person, not just the company
The employee who updates wire instructions in four minutes and the one who logs into a fake platform invite are failing for different reasons. (Obedience in one case, unfamiliarity in the other.) Cybersecurity during mergers and acquisitions works better when coaching addresses someone’s Emotional Susceptibility Profile instead of running one message at the whole company.
They don’t wait for the annual refresher
Awareness needs to spike the moment the company announces a merger or rolls out a new tool. It needs to stay elevated while the change is still unsettled, backed by scenario-based phishing simulations, a fake integration-team email, or a fake tool invite.
This training needs to mirror the actual transition closely enough to show whether people can apply what they’ve learned under real pressure. That gives the board something measurable to point to and gives the security team proof the program is working.
The AI wrinkle: A transition that never really ends
Every other item on this list has a start and an end. AI adoption doesn’t. It arrives in waves, as new tools and new integrations land before the last one has fully settled in. AI is also reshaping cyberattacks, stripping out the old phishing tells, like awkward phrasing and typos, and making voice and writing impersonation of the real leaders far more convincing.
Verizon’s research flagged the same shift this year, pointing to AI tools that can generate scam messages and impersonate trusted contacts with very little human effort.
One version of this shows up as a voicemail instead of an email: A manager gets a message that sounds exactly like his new regional director, asking him to approve an emergency payment before a system cutover that week. There’s no typo to catch, because there’s no text at all.
Security culture is the actual stabilizer
Every organization goes through business transitions, often more than one at a time, and leaders don’t have to treat the human element of susceptibility as inevitable.
Some organizations plan for these windows. These windows catch most organizations off guard, over and over, because their training calendar was never designed to notice one opening.
Workforce transition security awareness works when it targets the moments that elevate risk, adapts to how different people get talked into bad decisions, and rests on real security awareness metrics.
NINJIO’s approach centers on building an Emotional Susceptibility Profile for each person, so coaching addresses whichever emotional response is most likely to trick that specific person.
Where to go from here
Being able to tell your board “we saw this coming and prepared for it” is a fundamentally different conversation than explaining a spike after the fact. That’s the case for building readiness into how you plan your next transition, as much as how you respond to the last one.
Frequently Asked Questions
Because a merger temporarily removes the two things people normally rely on to judge whether a request is legitimate: Familiar faces and a stable chain of approval. Attackers don’t need new techniques to exploit that — they just need a request that fits what already feels unfamiliar.
Start before the company officially announces the transition, if you can. Employees need exposure to transition-specific threats before attackers show up with one. Keep elevated awareness going through the first 6-12 months. That’s roughly how long it takes for new routines to stop feeling new.
Time it to the deal itself rather than a fixed calendar. Start exposure to M&A-specific scenarios, like a fake integration-team request, before the announcement goes out if you can. Keep training elevated through close and the months of integration that follow, since that’s when reporting lines are least settled.
Yes, but cyberattack risk during layoffs has less to do with any individual’s reaction to the change and more to do with the uncertainty a reduction in force creates across the whole organization. Unclear reporting lines and unusual communications arise simply because the company is in flux. That uncertainty is exactly the cover an attacker needs, independent of how anyone on the team feels about the change itself.
Set verification protocols for high-stakes requests before the transition gets underway. A legitimate urgent request, like the wire change or the tool invite mentioned above, can survive a short verification step. The goal is to make verification the default, boring move, so an attacker can’t weaponize urgency as a reason to skip it.
AI removes the traditional red flags that awareness training has leaned on for years. Verizon’s 2026 DBIR researchers describe AI systems that can run persistent campaigns and automate deception at a pace human attackers never could. Combined with the general unfamiliarity of a transition, an AI-generated message impersonating new leadership can be hard to tell apart from the real thing.
Smaller organizations are not exempt. Verizon’s 2026 DBIR data makes that hard to argue with: Among ransomware cases where organization size was known, 96% of victims were small or midsize businesses. The psychological mechanics covered here don’t care about headcounts, and smaller teams often have fewer dedicated security resources to catch what training doesn’t.