
BGD e-GOV CIRT published an advisory on an active SideCopy campaign hitting Bangladeshi networks — spear-phishing paired with weaponized Windows shortcut files, dated 23 September 2026 BGD e-GOV CIRT. It's the fourth spear-phishing-driven advisory from the national CIRT in as many months. That's not a slow year. That's this quarter.
Most Bangladeshi companies still run phishing simulation training the way they run a fire drill: once, usually in January, then forgotten until next year's audit. Attackers don't work on that schedule, and neither does human memory. Fewer than a quarter of employees stay resistant to phishing after a single annual session — the effect fades within weeks, not months.
This piece is direct about what actually works: why one-off security awareness training doesn't hold up, what continuous phishing simulation does differently, and what a Bangladeshi business — bank, NGO, RMG exporter, or 15-person startup — needs to run instead.
A single annual session's effect fades within weeks — research found no lasting drop in real click rates from one-time content alone.
Monthly simulation + instant feedback: 70–80% improvement in 6 months, and susceptibility drops from 33% to 7% over a year.
The $81M Bangladesh Bank heist started with a spear-phishing email — not a firewall failure.
BGD e-GOV CIRT is actively tracking SideCopy, DoNot (APT-C-35), and a passkey-themed campaign hitting Bangladeshi organizations right now.

Figure 1 — Phishing susceptibility before vs. after one year of continuous simulation.
The Annual Training Trap
The problem isn't the content — it's that human memory doesn't run on a 12-month cycle, and attackers don't wait for your next scheduled session.
A randomized study at UC San Diego Health sent ten simulated campaigns to more than 19,500 employees over eight months. Completing the annual training had no significant relationship with whether someone fell for a lure, and fewer than 24% of staff even finished the training materials they were assigned Hoxhunt, 2026
A separate 15-month study at ETH Zurich, covering nearly 15,000 employees, found something sharper: embedded training after a click didn't make people more resilient — in some cases it made them worse. What actually worked, and kept working, was a simple "Report this email" button Hoxhunt, 2026
CISA's data backs up why timing matters so much: 84% of employees who receive a malicious email interact with it within ten minutes VikingCloud, 2026 — there's no room in that ten minutes for a memory of a slide from eight months ago.
What Phishing Simulation Actually Does Differently
Simulation doesn't tell employees what to do — it tests what they actually do, using a realistic fake attack, then coaches them at the exact moment of the mistake.
A fake email that looks like an IT password reset, or a vendor asking for an urgent transfer, puts someone inside the decision in real time. Click it, and the feedback is immediate and specific: here's what gave it away, here's what to check next time.
KnowBe4's 2026 Benchmarking Report — drawn from 42 million simulations across 14.8 million users at 64,000 organizations — found that consistent simulation over one year cuts susceptibility by 79% KnowBe4, 2026 . Organizations running monthly simulations with immediate feedback see 70–80%+ improvement within six months, with susceptibility falling under 5% StationX, 2026 . This isn't a one-time event. It's a rhythm.
Case Study: The Bangladesh Bank Heist Started With an Email
You don't need a foreign example to make this point — Bangladesh has its own, and it's one of the largest cyber-financial crimes in history.
In February 2016, attackers used stolen SWIFT credentials to push 35 fraudulent transfer requests, stealing $81 million from Bangladesh Bank's account at the New York Fed. They were after closer to $1 billion — a spelling error in one transfer instruction ("fandation" instead of "foundation") triggered a fraud alert and stopped a much bigger loss Infosecurity Magazine . The entry point wasn't a zero-day exploit — investigators found that malware-loaded spear-phishing emails had been sent to Bangladesh Bank employees months earlier, in December 2015 CSO Online, 2026 .
One term worth defining here: spear-phishing is a targeted phishing email built around real details about one specific person or organization — far more convincing, and far more dangerous, than a generic "you've won a prize" scam.

Figure 2 — Timeline of the Bangladesh Bank cyber heist.
That heist directly led to the founding of BGD e-GOV CIRT in 2016 Wikipedia . A decade on, the lesson still hasn't fully landed at the SME level: the technology gets patched, but the human layer only gets tested once a year, if at all.
What This Actually Costs You
A successful phishing email rarely stays a single incident — it becomes credential theft, then lateral movement, then often a full Business Email Compromise (BEC), where an attacker impersonates an executive or vendor to redirect a real payment. IBM's 2025 data puts the average BEC loss at $4.67 million StationX, 2026 Most Bangladeshi SMEs don't operate at that dollar scale, but a wiped operating account or a $10,000–$50,000 ransomware demand lands just as hard on a local manufacturer or hospital.
There's a legal dimension now too. The Cyber Security Ordinance 2025, in effect since 21 May 2025, put BGD e-GOV CIRT, the Bangladesh Computer Council, and the National Security Operation Centre in charge of real-time monitoring and coordinated response Mondaq, 2025 . If your organization touches Critical Information Infrastructure or handles sensitive financial or personal data, an untested workforce isn't just a security gap — it's a compliance exposure.
Building a Program That Actually Works
Stop treating this as a once-a-year calendar event. Here's the sequence the research above actually supports:
Baseline first. Run an unannounced simulation before you train anyone, so you know your real starting click rate — not a guess.
Go monthly, not annual. Once or twice a month is the cadence most consistently tied to sustained improvement.
Rotate the pretext. IT password resets, finance urgency, and executive impersonation are the three most common real-world hooks.
Make the report button the hero. A visible, one-click reporting habit outlasts any single training module.
Give feedback in the moment. Not a month later — right when someone clicks. That's where behavior actually changes.
Pair it with phishing-resistant MFA. Passkeys or FIDO2 stop most credential theft even when someone does click.
Know your reporting path in advance. Bookmark BGD e-GOV CIRT's incident reporting channel and assign it to a named person, not "whoever notices first."

Figure 3 — The continuous phishing simulation cycle.
What's New in 2026: AI-Written Phishing, Active Locally
The threat isn't static, so the defense can't be either. According to Hoxhunt's 2026 Phishing Trends Report, AI-generated phishing surged roughly 14× in late 2025, climbing from under 5% to 56% of detected attacks in a single month Hoxhunt, 2026 . A simulation program running on last year's templates is already behind.

Figure 4 — AI-generated phishing's rapid rise, late 2025.
Locally, BGD e-GOV CIRT's live advisory feed shows exactly what's landing in Bangladeshi inboxes this quarter:
Passkey-themed social engineering targeting cloud identities and SaaS data with fake passkey/MFA/SSO prompts (BGD e-GOV CIRT, Sept 2026) — cirt.gov.bd/advisories/passkey-social-engineering-campaign
The SideCopy campaign, pairing spear-phishing with weaponized Windows shortcut (.LNK) files to run fileless malware that standard antivirus struggles to catch (BGD e-GOV CIRT, Sept 2026) — cirt.gov.bd/advisories/sidecopy-campaign-sep-26
DoNot (APT-C-35), a cyber-espionage group running spear-phishing lures custom-built around Bangladesh's military environment (BGD e-GOV CIRT, Aug 2026) — cirt.gov.bd/advisories/donot-apt-c-35
These aren't generic spam runs. They're living-off-the-land attacks — abusing tools already installed on a victim's machine (like mshta.exe), which makes them far harder for standard antivirus to flag.
FAQ
How often should a Bangladeshi company run phishing simulations?
Monthly is the cadence most supported by behavioral research. Verizon's 2025 DBIR found employees trained within the past 30 days were four times more likely to report a phishing attempt than those trained longer ago. Quarterly is a floor, not a target.
What's the real difference between phishing simulation and security awareness training?
Training explains a threat in the abstract, usually through slides or video. Simulation sends a realistic fake phishing email and measures what an employee actually does — then coaches them at the exact moment of the mistake, which is what changes behavior.
Do we have to report a phishing incident to BGD e-GOV CIRT?
Organizations running Critical Information Infrastructure or essential services are expected to report significant incidents through BGD e-GOV CIRT's official channel. Even outside that mandate, reporting helps the national response team track active campaigns.
The Bottom Line
One training session a year teaches people to pass a quiz, not to spot a real attack eight months later. The Bangladesh Bank heist proved this at a national level a decade ago, and BGD e-GOV CIRT's live advisories this month prove attackers haven't slowed down. Monthly, realistic phishing simulation training — with instant feedback and a working report button — is what actually moves the needle, and the data on this is no longer close.
Want to see where your team actually stands? Run a baseline phishing simulation before your next scheduled training — book a free assessment today.