My company: Don't click on suspicious links.
Also my company: It's employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx
I mark them as phishing attempts every damn time.
My company: Don't click on suspicious links.
Also my company: It's employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx
I mark them as phishing attempts every damn time.
Report the email for phishing attempt.
Uhm. It is the phishing attempt. If you click that link it will tell you, you failed the test. And looking at the comments, a lot of people would fail this test.
...... That's why you would report the email as a phishing attempt.
That reminds me of a recent situation.
As someone working in software development, we are required to take part in the security trainings, the usual "don't open things from people you don't know" and "verify that a link is 'known' even if you get something from a person you do know", yada yada. You know the drill.
Recently, I got an email from our Boss saying something about "Here is something that you need to click on so that you are being authorised to do this stuff". Here was my thought process:
So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: "Got an email that tells me that I should open this link, but I don't know this link. What should I do?". The response was simple: Mark as Phishing and delete the Mail, done.
2 hours later, I got a message on Teams from IT which said: "Well, apparently that mail you marked as phishing was actually from us (was legit)". Great. Mail is gone now, don't know where Outlook put it, and frankly, I don't care.
If you train your people to "question everything" and not open links they don't know where they are going, then don't use some idiotic "middle man" or referer links in your official emails either. Even better, announce things before sending something out. I don't know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.
I had a previous company send out a company wide announcement from a sketchy sender with a weird file attachment(apparently it's a voice mail file format), and the email was essentially listen to this attachment with no signature or anything else. They had to send out a second email explaining the suspicious email is actually real. Companies seem intent on ensuring there is minimal difference between phishing and legitimate email.
100% success rate if you mark every email as a phishing attempt.
I take great pleasure in flagging the training emails from my company's IT contractor as phishing emails. After all, they're unexpected emails with big link that I simply must quickly click on. That sounds like phishing to me!
I've genuinely done this once or twice as it really looked like phishing to me. External email, big red button, hey, you have to finish this training until date xy!
Yeah, no, fuck you, report as phishing.
Whoops (:
Fun fact, those fishing emails usually share header information unique to the phishing email test service.
I already know the way to get me to click a phishing link is to send me 5 emails from the same company all 100% legit but have the unsubscribe link be the phishing link.
I would fall for that because I'm unsubscribing from companies emails all the time.
Of course now I've admitted this I'll be avoiding the unsubscribe link for a while too.
If IT did the phishing tests nobody would stand a chance lol
I'd always pass because I never look at any of my emails. Checkmate, IT department
Work in IT and my old cyber security architect would always try to get us. He did some great tricks and got a few salesmen. Never the engineers. Then they did similar tests for clients, they got hammered bad.
I used to report just about any email I got from HR/IT/Executive Management that had a link as spam... I got a lot of interesting replies from IT over the years.
Time to update your benefits SPAM/PHISHING!
Sign up for the holiday "pot luck" SPAM/PHISHING!
Tells us how you feel in thie "anonymous" survey... you guessed it SPAM/PHISHING!
IT guy here....
DAMN, that was brilliant!
I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.
Don't whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.
I'm not sure who these courses were even for. I was born in the scams. Moulded by them. I didn't see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.
The Bullshit thing about these phishing email tests is if you look at the actual headers they are allowed past the server level spam filters and in a back door to your email address. They would never pass the basic filters.
Being able to bypass the automated filtering is entirely logical, because they are testing and training humans and not the spam filters.
They are not even training you for reality.
They are training you to be the next line of defense after the automated filters are defeated. Which is, obviously, a thing which does happen frequently - eg, in every real phishing attack which succeeds.
These “online safety” companies create this baloney meat training so that your IT manager can say they are doing something, and your company can report compliance with whatever code they are responsible to, so they can be insured.
There is some truth to that, but on the other hand at any large enough organization many people will still fail these tests. And, even if you're sure that you're too smart for them, don't you think that being periodically subjected to these tests probably does actually make some people a bit more cautious?
I'm usually really good about security, but even I once failed one of the tests. I was doing some work for the city with Wells Fargo and was expecting an email from them, and that week's phishing test was a fake Wells Fargo email, and it got me.
It taught me that nobody is immune from fucking up.
They're testing to see what happens when their filter fails to catch something.
They don't know how to simulate an email that would get through the filters. If they knew how to do that, they'd just update the filters.
Instead, they say "hypothetically, if something did make it through our filters, would people fall for the phishing attempt?"
Sure, there's some CYA behaviour here, and trying to look busy. But, just because they're using a trick to get past the spam filters doesn't mean the test is invalid. They're not testing the spam filters, they're testing the users.
You can always forward it back to IT saying it's a suspicious link, according to this blog link you found. The blog link... Your own phishing link.
Two can play this game.
Ive often suggested to our security team that they send one out spoofing the monthly mandatory training vid
The issue is that people's egos get bruised when they fall for it, and they'll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.
What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there's no way to check the actual link before you click it since they're all just like garbagesec.com/4a12c89e7f now.
Our IT solution to that was to MITM all the links except for the phishing tests. So anyone savvy enough to realize that always passes.
Yours too? I hate it. I can't scan the URL and it drives me crazy. You just took away a way to identify a scam attempt.
PFF I don't click on any training emails unless my manager is asking about it in person.
If it's not important enough for them to follow up on, it's not important.
The best defence against phishing I have found is to just utterly ignore my email inbox at work.
You missed our recent phishing email, try to report it next time
No, I was so cautious I avoided my whole inbox because it might contain suspicious messages.
I'm out of the loop, what happened here?
This email is the phishing attempt test itself. It says you are exempt from the phishing testing, but then tells you to put your account information on a random website.
The email is a phishing test, and clicking the link automatically enrolls you in mandatory rudimentary cybersecurity awareness training.
I think the implication is that this is the fishing attempt they sent this to the higher ups / IT staff and got bites.
I have gotten texts from our Cybersecurity warning me not to open links in texts...and they include a link to a web page for more information.
I have a rule that searches the email headers for the test emails and just deletes them.
top 50 comments