phishing
Health board phishing test offered nurses a fake day off
2026-06-22

Newfoundland and Labrador Health Services has apologised after a phishing simulation aimed at its own staff offered something almost no nurse in the country could resist: an extra paid day off. Click the link, the email said, and claim your reward. Click the link, the system then noted, and you've failed our security test.
The timing made it worse. The fake email landed just after staff had pushed through long hours launching CorCare, the organisation's new clinical software system. The message even thanked them for that work before offering the bogus bonus day. It is hard to imagine a more precise way to poke a bruise.
The apology
Interim CEO Ron Johnson conceded the exercise "missed a mark" and acknowledged that the usual review lenses had not been applied before it went out. He has promised to look into how it was approved and to rethink how future awareness exercises are designed.
The Registered Nurses Union was less measured. President Yvette Coffey pointed out that nurses are already fighting hard to secure paid time off, and using it as bait was, in her words, in very poor taste. Burnout and chronic staffing shortages have been wearing the sector down for years. Dangling a fictional day off at people running on fumes is the kind of thing that gets remembered long after the post-mortem is filed.
Why this keeps happening
Phishing tests have become a default ritual in most large organisations, and healthcare is no exception. The threat is genuine. Hospitals are attractive targets, ransomware in a clinical environment can cancel procedures and put patients at risk, and credentials harvested from a single nurse can open doors that should stay closed.
The trouble is that the standard playbook, the surprise lure followed by a gotcha landing page, has drifted a long way from anything resembling adult learning. Staff are not told it is a drill. They are tested on whether they can spot an unannounced trick during a working shift, then quietly logged as a failure if they cannot. The lesson many take from this is not "be more careful with email". It is "my employer is willing to lie to me to catch me out".
Does the gotcha actually work?
The honest answer is that the evidence is thin. Click rates on simulations do tend to drop over time, but whether that reflects real behaviour change or just pattern recognition of internal test emails is debatable. What is clearer is the cultural cost. Tests that feel like betrayals erode the trust that good security depends on. Staff who think the security team is out to embarrass them are less likely to report the real phish when it lands, which is the moment that actually matters.
There is a version of awareness training that treats people as colleagues rather than suspects. It explains what to look for, gives staff a safe way to report and ask, and measures success by how quickly real threats get flagged, not by how many tired nurses can be tricked with a fake day off.
Newfoundland's apology is a start. The more useful conversation is the one Johnson has now promised: not just how this particular email got out the door, but whether the broader format is doing what anyone hoped it would.