• Rentlar@lemmy.ca
    link
    fedilink
    arrow-up
    21
    ·
    edit-2
    1 year ago

    I find that Cybersecurity training emails hit every red flag for a phishing email even if it’s legit:

    • From an external organization without my company’s letterhead.
    • Automated and I receive it at like 4am
    • A message saying something to the effect of “IT has assigned important training for you”
    • A link whose URL is a long string to an unidentifiable site
    • Clicking the link immediately takes you to a login page to enter your company email.

    If I wanted access to someone email and password maliciously, I’d totally make a cybersecurity training site like http://cybersecuritytraining.biz, tell people they are due for company cybersecurity training just like this and I bet I’d get a lot of accounts.

    • Kiloee@discuss.tchncs.de
      link
      fedilink
      arrow-up
      10
      ·
      1 year ago

      We recently got those training mails (legit ones just to make that clear) and the IT got so many tickets about it despite telling us that they were planned and showed an example of how they looked on teams, they had to make another post that essentially said „yes, this is legit, you can click the link.“

      It amused me greatly.

      • FiveMacs@lemmy.ca
        link
        fedilink
        arrow-up
        6
        ·
        1 year ago

        It just means you all passed step one of phishing training. Ask someone else so the blame is on them when shit hits the fan.

        • Kiloee@discuss.tchncs.de
          link
          fedilink
          arrow-up
          3
          ·
          1 year ago

          Yes totally. But it was also funny how that is the thing everybody is drilled on to the degree of wanting to make super extra sure.

  • DarkMatterStyx @lemmy.fmhy.net
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 year ago

    The last two companies I worked for had frozen wages due to market instability for years. Its amazing how they managed to make record profits quarter over quarter. They don’t care about my bottom line, I don’t care about theirs. I started opening every attachment that came my way.

  • ✨Abigail Watson✨@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    11
    ·
    1 year ago

    My work sends out fake phishing emails and the people who click them get in trouble. Of course, they always come from one particular address that I blocked.

    I wish they’d do more realistic emails though. “You won a prize you didn’t apply for!” is pretty basic. If it was one of those fake invoice PDFs I always get on my personal, I’d totally let a trojan onto the work network.

  • ShittyRedditWasBetter@lemmy.world
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    1 year ago

    It’s about average. Some of the emails are very bad. Some of them are quite sophisticated.

    Do education, send out a reasonable amount of testing, and if you can keep it below 15% you are in a pretty good spot.