Back to glossary

Hoax

4 min read

A hoax is a false message that travels by email, chat or social media and whose only goal is that you keep passing it on: a fake virus alert, a chain message, an invented security warning. There is nothing technical inside it, which is why no filter stops it. It spreads because checking it costs more than forwarding it.

July 30, 2026
Compartir:

How it spreads

A hoax survives because forwarding it costs less than checking it. The message arrives from somebody you know, asks for something trivial (pass it on, warn your contacts) and adds enough urgency to make verification feel like a waste of time. That is the whole mechanism. It needs no vulnerability, because the person spreading it is the recipient.

The shapes that circulate have barely changed in decades: the fake virus alert that tells you to delete a system file, the chain message that promises something in exchange for forwarding, the rumour about a company or a product, and the invented security warning that impersonates a real authority to sound credible.

What has changed is production, not the pattern. Convincing text and a plausible image or voice clip now cost nothing to make, so the old filter of clumsy spelling no longer helps. Verification has to go to the source, which is the same ground deepfakes occupy.

A hoax is not phishing, and the difference matters

They get confused because both are deceptive messages, but they want different things. Phishing wants a specific action from the recipient that benefits the attacker: credentials, a payment, an approved second factor. A hoax wants the message to keep travelling, and nothing else.

The difference shows in what you have to do about each. Phishing is blocked, pulled from mailboxes, and measured by how many people clicked. A hoax has no link to block and no credential to rotate: the response is to correct it on the same channel it arrived through, and to do it quickly, because the damage accumulates for as long as nobody says anything.

Nor is it business email compromise, which targets one person and wants the opposite of an audience: that nobody else notices until the payment has gone out.

The damage it actually does

The comfortable answer is that a hoax does no harm because it executes nothing. It is not true. The first cost is operational: a fake virus alert that tells people to delete a system file turns the user into the person who breaks their own machine, and the instruction carries the authority of a colleague who forwarded it in good faith.

The second cost is credibility. Every rumour that runs through internal channels burns the time of whoever has to correct it and, more importantly, burns trust: in an organisation where three false warnings have circulated, the fourth warning gets read with less attention even when it is real. It is the same mechanism by which too many alerts eventually switch off the response.

The third cost is no longer internal. A rumour about a breach that never happened, or an offer the company never made, forces a public answer at short notice. Knowing where the organisation’s name is being used before somebody else tells you is what digital risk protection covers.

What to do when one is going round

First, do not argue with it inside the same thread. A correction posted into the chain lengthens the chain. The correction that works comes from the official channel, states in one sentence what is false, and gives the source anyone can check.

Second, treat it as a small incident with the same parts as a large one: who confirms, who communicates, and through which channel. Deciding that in advance buys back the half hour a rumour needs to go round the company, and it is exactly what incident response is for.

Third, find out whether your people can tell a false message from a legitimate one, which is only knowable by measuring it. That is what a phishing simulation does, and what it looks for is not a list of who failed: it is which channel people use to ask when they are unsure. Against a message with nothing technical inside it, that channel is the only defence left, and the same holds for social engineering generally.

Want to see how we work at Asperis Security?

Schedule a 30-minute call with one of our experts. We’ll review your stack, agree on scope, and tell you what’s worth pentesting first.