In 2024, Kaspersky researchers started tracking a scam that almost exclusively targets Gen Z workers. Scammers lure candidates into interviewing for roles at a fully remote “company.” During onboarding, the “company” instructs the new hire to sign out of their personal Apple ID and sign in with a “corporate” one to install company software. When the new hire complies, the scammer activates Lost Mode, bricks the iPhone to make it unusable, and holds it for ransom. The scam is extreme, but it highlights a broader issue many organizations still underestimate: digital fluency does not automatically translate into security awareness.
In many workplaces, people still assume the youngest employees are the most tech savvy, and therefore the most secure and least likely to fall for scams. The data tells a different story. Recent surveys show Gen Z reuses passwords more often than older generations, interacts with phishing attempts more frequently, and leans heavily on personal details like birthdays or pet names in passwords. Because Gen Z both engages more with phishing and uses weaker password hygiene, they now fall for scams at roughly twice the rate of older generations.
Why does this gap exist? The issue is less about intelligence or technical skill and more about how different generations interact with technology every day, including:
-
Familiarity turns into overconfidence. Older employees often approach a new link with healthy paranoia. Younger employees have spent most of their lives interacting with apps, links, and notifications at high speed, which can normalize rapid clicking and response behavior.
-
Speed is the default. Younger workers read, click, and reply faster. Most phishing is engineered to convert before the brain catches up with the thumb.
-
Blurry lines between work and personal. Nearly half of Gen Z workers juggle a freelance side hustle, a primary job, and personal browsing on the same device, dramatically expanding the attack surface.
What we can learn from this:
-
Stop accepting the stereotype. Everyone needs security and awareness training, regardless of age, job title, or how confident they feel with technology.
-
Modernize training content. Training built around outdated email scams (remember the Nigerian prince who needed your help accessing his money?) does little to prepare employees for today’s attacks. Today’s programs need to cover QR phishing, MFA fatigue, deepfakes, and social engineering on Teams, Slack, LinkedIn, and job platforms.
-
Reward reporting, not perfection. When people can report a potential issue without fear of embarrassment or punishment, security culture gets stronger. Younger employees are less likely to report if they worry about looking foolish.
At Network 1, we focus on awareness programs that reflect how attackers actually operate, phishing simulations that reach the entire workforce, and phishing‑resistant MFA so one bad click doesn’t automatically turn into one bad breach. The employee who can rebuild your laptop and the employee who still prefers paper notes both deserve security training and tools calibrated to today’s threats. Attackers increasingly target behavior, speed, convenience, and trust rather than technical skill level.
If you’d like to assess where your organization stands and strengthen security training for every generation on your team, reach out to [email protected] to continue the conversation.