New Hires, September Starts: The 90-Day Phishing Window

Daniel Okafor··5 min read
Group of new employees arriving at the office together at the start of September

September Brings the Year's Biggest Onboarding Wave

Ask any HR team which month fills the most desks and the answer is almost always the same: September. Summer hiring freezes thaw, graduate programs kick off, and postponed start dates cluster right after the holidays end. In Germany the effect is institutional - September 1 is the traditional Ausbildungsbeginn, when a new cohort of apprentices starts across virtually every industry on the same day. The result, across much of Europe and North America, is that early autumn concentrates more first days than any other point in the year.

That concentration matters for security because new starters are not just another set of users - they are, measurably, the most phishable population in any company, and attackers deliberately time and target their campaigns to catch them. When the year's largest cohort walks in the door during a single month, the organization's aggregate susceptibility spikes with it.

The Numbers: New Hires Are the Most Phishable Cohort

The scale of the gap is documented. Keepnet's 2025 New Hires Phishing Susceptibility Report, based on data from 237 companies, found that 71% of new hires click on a phishing email within their first three months. New starters were 44% more likely to fall for phishing and social engineering than seasoned employees - and when the lure impersonated the CEO, they were 45% more likely than experienced staff to click, a finding Help Net Security highlighted in its coverage.

For context, KnowBe4's 2026 Phishing by Industry Benchmarking Report puts the baseline Phish-prone Percentage of untrained employees overall at 33.2%. Untrained is risky enough; untrained and brand new is a different category altogether. A new hire has not yet learned what a normal request looks like, who actually emails them, or how their leadership communicates - and they are maximally motivated to appear responsive and helpful. Every instinct that makes someone a good new employee also makes them a good phishing target.

Why Attackers Time Campaigns to New Starters

None of this is accidental on the attacker's side. New starters announce themselves: LinkedIn posts about the exciting new role, company welcome announcements, team pages updated with new names and titles. That public signal tells an attacker exactly who joined, where, and roughly when - which is all the targeting data a CEO impersonation campaign needs.

The playbook writes itself. A message arrives in week two, apparently from the chief executive the new hire has never met: a discreet, urgent favor, a gift card purchase, a quick wire authorization, an updated payroll form. The new employee has no baseline against which the request looks strange, no established relationship that tells them the CEO would never email this way, and every social incentive to comply quickly. The 45% elevated click rate on executive impersonation lures is precisely this dynamic showing up in the data.

Seasonal cohorts amplify the opportunity. A September intake means dozens or hundreds of employees simultaneously sitting in that vulnerable window - and in apprenticeship-heavy markets like Germany, the cohort is young, new to professional email norms entirely, and started on a publicly known date. Attackers do not need to find the window; the calendar hands it to them.

Protecting the September Cohort

The defense is not to bury week-one new hires in policy documents - it is to treat the incoming cohort as a distinct, time-boxed risk population and manage it as such.

  • Enroll on account creation, automatically. The 90-day window starts on day one, so protection has to start there too. With empowsec, automated enrollment pulls new joiners into a dedicated onboarding track the moment their account exists - no manual list-building, no waiting for the next quarterly campaign that may land after the window has closed.
  • Baseline the cohort early with a simulation. A gentle phishing simulation in the first weeks shows how the cohort actually behaves and identifies who needs extra support - before a real attacker runs the same test with real stakes.
  • Train against the specific lure they will face. Executive impersonation is the documented outsized risk for this group, so warn them explicitly: attackers pose as leadership and target newcomers, urgency is a red flag, and no executive here will ever ask for gift cards or a quiet wire transfer. The Keepnet research found that adaptive simulations and behavior-based training during onboarding cut new-hire phishing risk by 30%, a finding also covered by TechRadar Pro.
  • Put managers in the loop. A manager who tells every new report 'I will never ask you to buy anything or move money by email or text' inoculates them against the exact scam headed their way. For September cohorts, brief managers before the intake arrives.
  • Watch the window, then graduate them. Track the cohort's click and report rates across the 90 days. When the curve flattens to match tenured staff, the window has closed - and your reporting can prove it.

Key Takeaways

  • September concentrates risk. Post-summer starts and Germany's September 1 apprenticeship intake make early autumn the biggest new-hire wave of the year - and the most target-rich window for attackers.
  • New hires are measurably the softest target: 71% click a phish within three months, 44% more likely to fall for social engineering, and 45% more likely to fall for CEO impersonation than seasoned staff.
  • Attackers find the cohort through public signals - hiring announcements and profile updates - and time executive impersonation campaigns to the first weeks.
  • Treat the cohort as a time-boxed risk population: automatic enrollment on day one, an early baseline simulation, explicit warnings about executive impersonation, and manager norm-setting.
  • It works: adaptive, behavior-based training during onboarding cuts new-hire phishing risk by 30% - measure the cohort until its risk curve matches tenured employees.
Share: