Skip to content
  • Kategorien
  • Aktuell
  • Tags
  • Beliebt
  • World
  • Benutzer
  • Gruppen
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Standard: (Kein Skin)
  • Kein Skin
Einklappen

other.li Forum

  1. Übersicht
  2. Uncategorized
  3. the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work!

the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work!

Geplant Angeheftet Gesperrt Verschoben Uncategorized
8 Beiträge 7 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • ? Offline
    ? Offline
    Gast
    schrieb zuletzt editiert von
    #1

    the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work! [Click here] to claim your gift!”)

    ? ? ? 3 Antworten Letzte Antwort
    0
    • ? Gast

      the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work! [Click here] to claim your gift!”)

      ? Offline
      ? Offline
      Gast
      schrieb zuletzt editiert von
      #2

      @0xabad1dea Every few months, it seems, we get email at work from an address we've never seen before, along the lines of "log into the new HR portal at [dodgy external address]", signed "HR department". Nothing to connect it to this specific employer, no names, etc. Every time I report it as obvious phishing. Every time it turns out the great and powerful overlords have signed a new contract with an even dodgier provider.

      1 Antwort Letzte Antwort
      0
      • ? Gast

        the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work! [Click here] to claim your gift!”)

        ? Offline
        ? Offline
        Gast
        schrieb zuletzt editiert von
        #3

        phishing training really doesn’t spend enough time on “how to structure your mass corporate communications in such a way that your employees won’t conclude that you communicate exactly like scammers and still expect a reply so they’d better assume scammy emails are legitimate”

        ? ? ? 3 Antworten Letzte Antwort
        0
        • ? Gast

          phishing training really doesn’t spend enough time on “how to structure your mass corporate communications in such a way that your employees won’t conclude that you communicate exactly like scammers and still expect a reply so they’d better assume scammy emails are legitimate”

          ? Offline
          ? Offline
          Gast
          schrieb zuletzt editiert von
          #4

          @0xabad1dea our phishing training started with an unannounced mail from the training site with a button saying "click here".

          we were expected to click on it, to access the training.

          monkee@other.liM 1 Antwort Letzte Antwort
          0
          • ? Gast

            phishing training really doesn’t spend enough time on “how to structure your mass corporate communications in such a way that your employees won’t conclude that you communicate exactly like scammers and still expect a reply so they’d better assume scammy emails are legitimate”

            ? Offline
            ? Offline
            Gast
            schrieb zuletzt editiert von
            #5

            @0xabad1dea then there's ones from banks, government things, big brands etc.

            1 Antwort Letzte Antwort
            0
            • ? Gast

              phishing training really doesn’t spend enough time on “how to structure your mass corporate communications in such a way that your employees won’t conclude that you communicate exactly like scammers and still expect a reply so they’d better assume scammy emails are legitimate”

              ? Offline
              ? Offline
              Gast
              schrieb zuletzt editiert von
              #6

              @0xabad1dea I think about this so much at this time of year because I help run a car show and my job is to get everyone to register their cars and pay their entry fees. I've learned that most car enthusiasts are not very tech savvy.

              We have a limited time to do this and I'm coordinating hundreds of people. Here I am sending them progressively urgent emails, text messages, and occasional phone calls reminding them to confirm something, update their information, and pay their fees.

              My first thought: If someone sent me these messages, I'd delete them because they look like scams.

              My second thought after almost everyone does exactly what I ask them to do: "Oh shit, I'm conditioning all of these people to fall for scams."

              1 Antwort Letzte Antwort
              0
              • ? Gast

                the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work! [Click here] to claim your gift!”)

                ? Offline
                ? Offline
                Gast
                schrieb zuletzt editiert von
                #7

                @0xabad1dea
                Here I go on a tangent about CEO gifts.

                A couple years ago, a now EX-CEO proudly announced his amazing Christmas bonus for everyone.

                "It will be more personal than cash!"

                Yay, a disappointing box of borrel snacks, we thought.

                Somehow, our team's expectations weren't low enough. Cheap corporate merch; a hoodie, a travel coffee mug, and an umbrella. They really GET ME.

                So yeah, I'll bet that phishy present will be garbage anyhow.

                1 Antwort Letzte Antwort
                0
                • ? Gast

                  @0xabad1dea our phishing training started with an unannounced mail from the training site with a button saying "click here".

                  we were expected to click on it, to access the training.

                  monkee@other.liM This user is from outside of this forum
                  monkee@other.liM This user is from outside of this forum
                  monkee@other.li
                  schrieb zuletzt editiert von
                  #8

                  @fishidwardrobe@mastodon.me.uk @0xabad1dea@infosec.exchange beautiful ​​

                  1 Antwort Letzte Antwort
                  0
                  • monkee@chaos.socialM monkee@chaos.social shared this topic
                  Antworten
                  • In einem neuen Thema antworten
                  Anmelden zum Antworten
                  • Älteste zuerst
                  • Neuste zuerst
                  • Meiste Stimmen


                  • Anmelden

                  • Anmelden oder registrieren, um zu suchen
                  • Erster Beitrag
                    Letzter Beitrag
                  0
                  • Kategorien
                  • Aktuell
                  • Tags
                  • Beliebt
                  • World
                  • Benutzer
                  • Gruppen