Can’t make the wrong people look bad.

top 50 comments

sorted by: hot top controversial new old
[–] 122 points 5 days ago (8 children)

My company: Don't click on suspicious links.

Also my company: It's employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx

I mark them as phishing attempts every damn time.

  • source
  • hideshow 9 child comments
  • [–] 61 points 5 days ago* (last edited 5 days ago) (6 children)

    Heh, an employee at my work got an email saying his anti-malware was failing to update, and to run http://10.3.4.2/xbejdjr.exe and that they need to click allow when the browser warns them that it is rejected, then right click, run as administrator, and they need to click allow in two other places to let it run.

    So he reported as phishing, then IT contacted his manager saying he was failing to help IT run a required update, it was evidently totally legit, but just the most scammy looking way they imagined.

  • source
  • parent
  • hideshow 9 child comments
  • They can send executable links through emails and get their pants in a twist when the users do the right thing and report it for being shady AF, but they can't use RMM to automatically install their updates? Bullshit IT department needs to be fully replaced.

  • source
  • parent
  • [–] 2 points 2 days ago (1 child)

    10.0.0.0/8 is a reserved lan name space, so I'd probably have ran it after confirming the headers (anything 10.x.x.x will be on your local network) but I do agree, shady and stupid af especially since IT presumably should be running their own dns and it's trivial to implement a redirect to an internal corporate tld.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 days ago (1 child)

    I would have assumed a beach head where they compromised a system on the internal network and then phished to extend the reach.

    I figured IT of all people would have allocated some DNS and some certificate. I would have taken the lack of TLS and DNS as a consequence of an attacker not having enough access to make those things a reality, and banking on people viewing 10. as safely internal like you are inclined to suggest.

    Just because it has an internal address does not mean it is safe, particularly as number of employees goes up and any one of them can get a system under their control compromised.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 days ago*

    I never said it was safe, I said it was internal. If it's on 10.x.x.x, sent with email headers verified against my orgs Auth, it's beyond my or any normal user's pay grade to deal with it and should've been caught far far before this point by design. Though, what you're saying does align with defense in depth principals, I think you'll find they cannot be expected in real life use, but perhaps you're the type to independently verify every file you interact with via hash. Idk, some people on lemmy go hard. 🤷‍♂️

  • source
  • parent
  • load more comments (3 replies)
  • load more comments (7 replies)
    [–] 164 points 5 days ago
    [–] 137 points 5 days ago (2 children)

    Report the email for phishing attempt.

  • source
  • hideshow 4 child comments
  • [–] 102 points 5 days ago (2 children)

    Uhm. It is the phishing attempt. If you click that link it will tell you, you failed the test. And looking at the comments, a lot of people would fail this test.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (1 reply)
  • [–] 20 points 4 days ago (2 children)

    That reminds me of a recent situation.

    As someone working in software development, we are required to take part in the security trainings, the usual "don't open things from people you don't know" and "verify that a link is 'known' even if you get something from a person you do know", yada yada. You know the drill.

    Recently, I got an email from our Boss saying something about "Here is something that you need to click on so that you are being authorised to do this stuff". Here was my thought process:

    1. This is from the boss's Email. But this cannot be trusted since it can be faked
    2. This is about something we/our software can do. But I don't know why I have to do this, since this isn't really something I am part of or even know anything about
    3. It looks like a legit email
    4. I hovered over the link, which had some weird target location that I didn't know

    So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: "Got an email that tells me that I should open this link, but I don't know this link. What should I do?". The response was simple: Mark as Phishing and delete the Mail, done.

    2 hours later, I got a message on Teams from IT which said: "Well, apparently that mail you marked as phishing was actually from us (was legit)". Great. Mail is gone now, don't know where Outlook put it, and frankly, I don't care.

    If you train your people to "question everything" and not open links they don't know where they are going, then don't use some idiotic "middle man" or referer links in your official emails either. Even better, announce things before sending something out. I don't know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.

  • source
  • hideshow 3 child comments
  • [–] 6 points 4 days ago

    I had a previous company send out a company wide announcement from a sketchy sender with a weird file attachment(apparently it's a voice mail file format), and the email was essentially listen to this attachment with no signature or anything else. They had to send out a second email explaining the suspicious email is actually real. Companies seem intent on ensuring there is minimal difference between phishing and legitimate email.

  • source
  • parent
  • load more comments (1 reply)
    [–] 96 points 5 days ago (2 children)

    100% success rate if you mark every email as a phishing attempt.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 73 points 5 days ago (2 children)

    I take great pleasure in flagging the training emails from my company's IT contractor as phishing emails. After all, they're unexpected emails with big link that I simply must quickly click on. That sounds like phishing to me!

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 32 points 5 days ago (4 children)

    Fun fact, those fishing emails usually share header information unique to the phishing email test service.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 33 points 5 days ago (1 child)
    load more comments (1 reply)
    [–] 21 points 4 days ago* (4 children)

    I already know the way to get me to click a phishing link is to send me 5 emails from the same company all 100% legit but have the unsubscribe link be the phishing link.

    I would fall for that because I'm unsubscribing from companies emails all the time.

    Of course now I've admitted this I'll be avoiding the unsubscribe link for a while too.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 20 points 4 days ago (2 children)

    If IT did the phishing tests nobody would stand a chance lol

  • source
  • hideshow 4 child comments
  • [–] 9 points 4 days ago

    Work in IT and my old cyber security architect would always try to get us. He did some great tricks and got a few salesmen. Never the engineers. Then they did similar tests for clients, they got hammered bad.

  • source
  • parent
  • [–] 64 points 5 days ago (1 child)

    I used to report just about any email I got from HR/IT/Executive Management that had a link as spam... I got a lot of interesting replies from IT over the years.

    Time to update your benefits SPAM/PHISHING!

    Sign up for the holiday "pot luck" SPAM/PHISHING!

    Tells us how you feel in thie "anonymous" survey... you guessed it SPAM/PHISHING!

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 53 points 5 days ago (1 child)

    IT guy here....

    DAMN, that was brilliant!

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 39 points 5 days ago (2 children)

    I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.

    Don't whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.

    I'm not sure who these courses were even for. I was born in the scams. Moulded by them. I didn't see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [+] 31 points 5 days ago* (last edited 5 days ago) (9 children)
  • [–] 27 points 5 days ago* (last edited 5 days ago) (2 children)

    The Bullshit thing about these phishing email tests is if you look at the actual headers they are allowed past the server level spam filters and in a back door to your email address. They would never pass the basic filters.

    Being able to bypass the automated filtering is entirely logical, because they are testing and training humans and not the spam filters.

    They are not even training you for reality.

    They are training you to be the next line of defense after the automated filters are defeated. Which is, obviously, a thing which does happen frequently - eg, in every real phishing attack which succeeds.

    These “online safety” companies create this baloney meat training so that your IT manager can say they are doing something, and your company can report compliance with whatever code they are responsible to, so they can be insured.

    There is some truth to that, but on the other hand at any large enough organization many people will still fail these tests. And, even if you're sure that you're too smart for them, don't you think that being periodically subjected to these tests probably does actually make some people a bit more cautious?

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (1 reply)
  • [–] 14 points 5 days ago

    They're testing to see what happens when their filter fails to catch something.

    They don't know how to simulate an email that would get through the filters. If they knew how to do that, they'd just update the filters.

    Instead, they say "hypothetically, if something did make it through our filters, would people fall for the phishing attempt?"

    Sure, there's some CYA behaviour here, and trying to look busy. But, just because they're using a trick to get past the spam filters doesn't mean the test is invalid. They're not testing the spam filters, they're testing the users.

  • source
  • parent
  • load more comments (7 replies)
    [–] 40 points 5 days ago

    You can always forward it back to IT saying it's a suspicious link, according to this blog link you found. The blog link... Your own phishing link.

    Two can play this game.

  • source
  • [–] 49 points 5 days ago

    Seems legit. Click the link

  • source
  • [–] 46 points 5 days ago (2 children)

    Ive often suggested to our security team that they send one out spoofing the monthly mandatory training vid

  • source
  • hideshow 4 child comments
  • [–] 62 points 5 days ago (5 children)

    The issue is that people's egos get bruised when they fall for it, and they'll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.

    What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there's no way to check the actual link before you click it since they're all just like garbagesec.com/4a12c89e7f now.

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (3 replies)
  • [–] 14 points 4 days ago

    Purple link, lol

  • source
  • [–] 23 points 5 days ago

    The best defence against phishing I have found is to just utterly ignore my email inbox at work.

    You missed our recent phishing email, try to report it next time

    No, I was so cautious I avoided my whole inbox because it might contain suspicious messages.

  • source
  • [–] 14 points 5 days ago (3 children)

    I'm out of the loop, what happened here?

  • source
  • hideshow 6 child comments
  • [–] 13 points 5 days ago

    I have gotten texts from our Cybersecurity warning me not to open links in texts...and they include a link to a web page for more information.

  • source
  • [–] 19 points 5 days ago (2 children)

    I have a rule that searches the email headers for the test emails and just deletes them.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 20 points 5 days ago

    Don’t fall for it.

  • source
  • load more comments
    view more: next ›