Can’t make the wrong people look bad.

  • fribbtastic@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    4 hours ago

    That reminds me of a recent situation.

    As someone working in software development, we are required to take part in the security trainings, the usual “don’t open things from people you don’t know” and “verify that a link is ‘known’ even if you get something from a person you do know”, yada yada. You know the drill.

    Recently, I got an email from our Boss saying something about “Here is something that you need to click on so that you are being authorised to do this stuff”. Here was my thought process:

    1. This is from the boss’s Email. But this cannot be trusted since it can be faked
    2. This is about something we/our software can do. But I don’t know why I have to do this, since this isn’t really something I am part of or even know anything about
    3. It looks like a legit email
    4. I hovered over the link, which had some weird target location that I didn’t know

    So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: “Got an email that tells me that I should open this link, but I don’t know this link. What should I do?”. The response was simple: Mark as Phishing and delete the Mail, done.

    2 hours later, I got a message on Teams from IT which said: “Well, apparently that mail you marked as phishing was actually from us (was legit)”. Great. Mail is gone now, don’t know where Outlook put it, and frankly, I don’t care.

    If you train your people to “question everything” and not open links they don’t know where they are going, then don’t use some idiotic “middle man” or referer links in your official emails either. Even better, announce things before sending something out. I don’t know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.

    • ryathal@sh.itjust.works
      link
      fedilink
      arrow-up
      4
      ·
      1 hour ago

      I had a previous company send out a company wide announcement from a sketchy sender with a weird file attachment(apparently it’s a voice mail file format), and the email was essentially listen to this attachment with no signature or anything else. They had to send out a second email explaining the suspicious email is actually real. Companies seem intent on ensuring there is minimal difference between phishing and legitimate email.

    • Bytemeister@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      Honestly, this is preferable, and pretty funny. IT can always resend invites to tools and services. I’d rather send 1000 of those than have to lock someone out and have to talk to a human.

  • altphoto@lemmy.today
    link
    fedilink
    arrow-up
    1
    ·
    2 hours ago

    By the way, did you already donate for the annual November nothing day celebration? Click this 🔗 to donate, everyone is doing it!

      • filcuk@feddit.uk
        link
        fedilink
        arrow-up
        3
        ·
        5 hours ago

        I’ve setup a filter based on email headers that include ‘Phishing_Training’ lol, can’t be asked

    • Lucky_777@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      12 hours ago

      Work in IT and my old cyber security architect would always try to get us. He did some great tricks and got a few salesmen. Never the engineers. Then they did similar tests for clients, they got hammered bad.

  • BigBoyShuanzee@aussie.zone
    link
    fedilink
    arrow-up
    17
    ·
    14 hours ago

    I already know the way to get me to click a phishing link is to send me 5 emails from the same company all 100% legit but have the unsubscribe link be the phishing link.

    I would fall for that because I’m unsubscribing from companies emails all the time.

    Of course now I’ve admitted this I’ll be avoiding the unsubscribe link for a while too.

    • MonkderVierte@lemmy.zip
      link
      fedilink
      arrow-up
      3
      ·
      5 hours ago

      Even IT people click on random unsubscribes? I’ve learned that the hard way in my teens, that you only get more spam then. Only unsub from sites you know you have an account on.

      • BigBoyShuanzee@aussie.zone
        link
        fedilink
        arrow-up
        2
        ·
        3 hours ago

        Random? No I think my original message misses a point.

        I don’t look at ads. I don’t respond to messages I don’t answer phone calls from anyone besides my wife.

        I’m so overly cautious and uninterested I could possibly miss a call telling me my parents are dying.

        I’ve been in IT so long that everything these days is spam to me, I’m always looking for a way to disable every notification and block every call/message.

        The last time I had a real social media message that I cared about was back when MSN messenger existed… So at least 18+ years ago

        Now don’t get me wrong, I’m a ridiculous human being… I am a big fat loudmouth but even as far back as Bebo then Myspace then Facebook I’ve been more interested in getting attention face to face.

        Now I’ve gone on and on… That’s because I’m in my late 30s and I hate my job and I’ve drank too much alcohol.

        Good luck to you and I wish you well

  • Bieren@lemmy.today
    link
    fedilink
    arrow-up
    7
    ·
    12 hours ago

    Me and some coworkers got yelled for reporting the phishing attempt. And then still clicking on the links. The halfass made up sites it took you to were worth it. It’s wouldnt take you to some site saying you failed. It would be like a lunch menu for some made up place. It was great.

  • _lilith@lemmy.world
    link
    fedilink
    arrow-up
    28
    ·
    18 hours ago

    Fun fact, those fishing emails usually share header information unique to the phishing email test service.

    • HerbGrower@slrpnk.net
      link
      fedilink
      arrow-up
      1
      ·
      3 hours ago

      We once had one that had what looked like a user ID in the URL. Checked with a coworker. The IDs appeared to be given sequentially. So I copied the URL and visited the site many times with different IDs.

      A lot of people failed the phishing test that month and would deny it.

    • njordomir@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      14 hours ago

      Yeah, I used to see these when I worked at a big corp. I would do a whois search on the domains used and 9/10 times it would come back as some compliance contractor the company used. I then proceeded to roll my rolly chair up and down every aisle warning my engineers. I spent so much time rolling in that job they should have bought me a rascal scooter with a built in desk. :D

    • eestileib@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      11 hours ago

      I fell for a fucking obvious pathetic text when I moved to a new country because my bullshit immune system had not adapted to the new landscape.

      It’s FUN to turn over all of your bank cards after a month!

    • Fleppensteyn@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      8 hours ago

      My company used some security software that scrambled up every url in emails.

      You could’ve spotted their fake meeting invite if only it would have shown its true url.

    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      53
      ·
      edit-2
      17 hours ago

      Heh, an employee at my work got an email saying his anti-malware was failing to update, and to run http://10.3.4.2/xbejdjr.exe and that they need to click allow when the browser warns them that it is rejected, then right click, run as administrator, and they need to click allow in two other places to let it run.

      So he reported as phishing, then IT contacted his manager saying he was failing to help IT run a required update, it was evidently totally legit, but just the most scammy looking way they imagined.

      • Bytemeister@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 hours ago

        If that was legitimately IT, then that whole department either need the funds to acquire some remote management software, or they all need to be axed. Only the budget will tell.

        • jj4211@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          2 hours ago

          It’s the latter. They actually get thrown all sorts of money in part because they say they need tools. The standard corporate load has at least 3 patch management software suites, two ‘cybersecurity monitoring solutions’, three anti-malware software products.

          Sometimes their automation fails and this was one of those situations where his and at least in our department only his where their automation failed for some reason or another. So they fall back to a sketchy looking exe on some random web server they don’t even bother to enable https on (they also provision root CAs, so it’s not like it would be a challenge for them to have https on an internal domain).

          They aren’t very good, but they are doing things perfectly right; so long as the one deciding what is right is the sales reps of the software they use.

      • Alcoholicorn@mander.xyz
        link
        fedilink
        arrow-up
        23
        ·
        24 hours ago

        That is so fucking sketchy, I’d have to talk to the IT guy myself or get on a video call to make sure their email or the group chat or whatever wasn’t compromised.

        • Vardøgor@mander.xyz
          link
          fedilink
          arrow-up
          2
          ·
          13 hours ago

          is it tho? that’s a LAN IP, so just a file on the company’s network. browsers whine about http by default bc its security over WAN. then windows just whines about everything

          • Larry@piefed.social
            link
            fedilink
            English
            arrow-up
            7
            ·
            13 hours ago

            Yes. An average employee doesn’t know the difference between public and private IP’s

            • Vardøgor@mander.xyz
              link
              fedilink
              arrow-up
              3
              ·
              13 hours ago

              well of course. just meant the IT guy didnt necessarily do anything sketchy or wrong, just a consequence of all those modern security prompts. totally get why folk would be apprehensive seeing that, deal with it all the time. but i’ve also never seen a company where they have an SSL cert for the LAN or something either, it just gets explained

              • Larry@piefed.social
                link
                fedilink
                English
                arrow-up
                6
                ·
                13 hours ago

                I think teaching nontechnical employees that its okay to enter an IP address they don’t know, given to them by a remote person and bypassing security prompts would qualify as “wrong”.

                • Vardøgor@mander.xyz
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  12 hours ago

                  by explain, i didn’t mean teach everyone it’s always okay to ignore security prompts. maybe that’s just how the cookie crumbled as the fix but it should’ve been explained why it’s being done that time, that’s where I think they’re wrong, I rescind that. you’re right that especially remotely it’ll create bad habits.

                  IME IT just walked our asses over when it’s something like that, never worked in a giant office, so that’s where I spoke from, ya feel me

    • antlion@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      8
      arrow-down
      2
      ·
      1 day ago

      I tried to make the case to IT that hyperlinks are not a threat vector on their own. They should train against opening attachments and entering credentials once the link is clicked. I haven’t heard back yet, I’m not sure they liked my message. But they did send a message letting us all know that reporting non-phishing surveys wastes their time.

      • Trainguyrom@reddthat.com
        link
        fedilink
        English
        arrow-up
        5
        ·
        15 hours ago

        The argument regarding hyperlinks is generally that there are 1-2 click zero-day vulnerabilities pretty frequently, so clicking a hyperlink will take you to a server controlled by the attacker which may or may not employ one of those. Additionally there’s a constantly rotating array of obscure HTML/CSS hacks to trick even the savviest of users into thinking an attacker controlled window is something else or otherwise compromise a users system without utilizing zero-days. And finally good ol’ social engineering typically relies on several vectors at once, so by the time someone’s clicked the link there’s a good chance they might go further for the attacker before they clue in.

        So yeah, theoretically if everything was as it should be, clicking the hyperlink and downloading and executing literal malware wouldn’t work, but security is about trying to make sure the weak points of every part of the chain don’t line up, because when those holes in all of the layers of security line up, you’ve got a nice big compromise to clean up, and those buggers are like bedbugs, once they get in, you can be chasing them for months or years until you’re finally rid of them

        • antlion@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          15 hours ago

          The web is very locked down already. People click so many links from email, but also outside of email. Clicking a hyperlink in an email is not a threat vector. If it was, we can’t vote on when to meet, open shared documents, or basically do anything other than plaintext email. Aha! That’s the solution. Plaintext email - all attachments and HTML are blocked.

    • Arthur Besse@lemmy.ml
      link
      fedilink
      English
      arrow-up
      28
      arrow-down
      1
      ·
      edit-2
      18 hours ago

      The Bullshit thing about these phishing email tests is if you look at the actual headers they are allowed past the server level spam filters and in a back door to your email address. They would never pass the basic filters.

      Being able to bypass the automated filtering is entirely logical, because they are testing and training humans and not the spam filters.

      They are not even training you for reality.

      They are training you to be the next line of defense after the automated filters are defeated. Which is, obviously, a thing which does happen frequently - eg, in every real phishing attack which succeeds.

      These “online safety” companies create this baloney meat training so that your IT manager can say they are doing something, and your company can report compliance with whatever code they are responsible to, so they can be insured.

      There is some truth to that, but on the other hand at any large enough organization many people will still fail these tests. And, even if you’re sure that you’re too smart for them, don’t you think that being periodically subjected to these tests probably does actually make some people a bit more cautious?

      • toddestan@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        11 hours ago

        Having a few of those phishing test emails actually get snagged by the spam filters wouldn’t actually a bad idea. I can review the quarantined and spam email for the rare case there is a false positives, and it’s entirely possible that someone could find something in there, be like “hey that looks legit”, and get phished.

        Though on the subject of spam filters, I really wish IT would invest some resources into some better filtering. I mean, it’s the first line of defense and from what I can tell they just use some default crappy Microsoft filter that barely catches anything and lets some of the spammiest spam just sail right through. So I guess in that sense not letting the fake phishing emails get snagged by the filters is entirely believable.

      • chiliedogg@lemmy.world
        link
        fedilink
        arrow-up
        13
        ·
        18 hours ago

        I’m usually really good about security, but even I once failed one of the tests. I was doing some work for the city with Wells Fargo and was expecting an email from them, and that week’s phishing test was a fake Wells Fargo email, and it got me.

        It taught me that nobody is immune from fucking up.

        • Mic_Check_One_Two@reddthat.com
          link
          fedilink
          arrow-up
          3
          ·
          13 hours ago

          I got tricked by a phishing test once, because I had raised a ticket with IT about an unrelated issue. They sent me a fucking phishing test link that looked like it came from IT Help Desk, while I was on the phone with the IT Help Desk person that I had called. Like I literally initiated every single communication, so it’s not like a “hey this is {fake IT} calling and I need you to install this exe for me” cold call that happened to get lucky.

          The Help Desk tech was like “okay I’m sending you a link to {program installer}, then once it’s downloaded I can remote into your laptop and install it with admin rights.” The “hey we need you to click this link” phishing email from {Fake IT Help Desk} chose that exact moment to hit my inbox. Again, I had called IT, using an internal company phone system, using a direct phone extension that I had looked up in our internal company directory. So it’s not like there was any reason for me to distrust the tech or suspect that he was actually a phisher. The actual email with the real link arrived like a minute after I had already failed the test.

          Even the Help Desk tech was like “okay, that’s actually the first time I’ve ever heard of someone failing a phishing test while actively talking to IT… Did they really send that at the same time I said I was sending my email?? Bro you got swindled… At least the training videos will give you a chance to eat lunch at your desk?”

        • raspberriesareyummy@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          15 hours ago

          Well if just clicking on a link counts as “gotcha” then consider me guilty as charged. Because I’ve been unsure about the underlying URL and wanted to know what page loads. But my web browser is jailed. My point is: you didn’t get phished until you give away any info other than “someone received the email and clicked on the link”

          • Mic_Check_One_Two@reddthat.com
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            12 hours ago

            My point is: you didn’t get phished until you give away any info other than “someone received the email and clicked on the link”

            Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.

            The actual method of attack (and any protections you have set up for your browser) is irrelevant, because they’re not testing to see if your browser is hardened. If they were going to do a software audit to see if browsers were vulnerable, you probably wouldn’t ever even hear about it. Because IT would handle it directly, via the access they already have to your company computer.

            Tricking you into disclosing sensitive info is only one specific type of attack. The phishing link isn’t checking to see if you’d give info away. If they were testing that, they could do it in other ways, like a fake email from your manager asking for the info. No need to click a link to fail that test. But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link. That link exists in a quantum state where every single piece of malware that ever did/will exist can load as soon as you click it.

            • raspberriesareyummy@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              6 hours ago

              Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.

              To consider an employee clicking on a potentially malicious link as “allowing an attack to happen” takes a special kind of incompetence on the part of the IT (security) team.

              If simply clicking a link compromises a system, that’s on corporate IT, not on the user. As you say, “they weren’t testing to see if your browser would allow an attack to happen”. Because - in a corporate setting - if it would, they done fucked up. And if it wouldn’t, then clicking a link alone is no problem.

              But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link.

              I dislike that you incite me to respond to that because I don’t want to insult you personally, but I have very strong feelings about this attitude. This particular, take from a corporate IT department, is moronic. If clicking a link to check where it leads compromises IT security, that is 100% the fault of corporate IT. That is what they must fix with firewalls and filter policies.

              As an IT security responsible, if you push responsibility for single keypress actions to the user, you are an idiot, and a liability to your company’s IT security, and you should not be allowed anywhere near a sensitive system or policy.

              The role of IT security is not to set legal frameworks in which when a fuckup happens, a responsible person that is not them can be found. The role of IT security is to protect the intranet and users from external attacks, be it hacking or phishing or malware - and to protect the same intranet from internal attacks in the best way feasible. That includes a user intentionally clicking a link if that is sufficient to compromise intranet systems.

              About the only thing you can make users responsible for is to not disclose information through phishing or social engineering attacks, and to not intentionally sabotage anything.

              • chiliedogg@lemmy.world
                link
                fedilink
                arrow-up
                1
                ·
                3 hours ago

                The point is to have multiple layers of protection. With users who are vigilant it’s less likely for something to get through even if IT fails to filter out an attack.

                Think of it like gun safety. Even though a gun is unloaded you don’t aim it at someone.

                • raspberriesareyummy@lemmy.world
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  2 hours ago

                  No argument there - training cybersecurity awareness is fine, but singling users for clicking on a link alone is moronic. Most security fuckups in my experience result from stupid IT policies and rarely do the responsible admins / managers ever get flak for their fuckups.

          • grepe@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            15 hours ago

            funny thing is that our company masks all links in emails and routes them via an internal security shield solution. so you have no chance to actually see what the url is until you click on it. if it was a training email you get to waste 20 minutes watching a training video and i suspect if it would be actual phish the shield would probably not catch it.

    • merc@sh.itjust.works
      link
      fedilink
      arrow-up
      15
      arrow-down
      1
      ·
      19 hours ago

      They’re testing to see what happens when their filter fails to catch something.

      They don’t know how to simulate an email that would get through the filters. If they knew how to do that, they’d just update the filters.

      Instead, they say “hypothetically, if something did make it through our filters, would people fall for the phishing attempt?”

      Sure, there’s some CYA behaviour here, and trying to look busy. But, just because they’re using a trick to get past the spam filters doesn’t mean the test is invalid. They’re not testing the spam filters, they’re testing the users.

    • pelican476@discuss.online
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      You are getting in the way of a scam that all parties are aware of and perfectly ok with.

      As a moron, I wish companies would just fucking tell me about their scams. I never catch on until a few months after I leave the company.

    • Krudler@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      14 hours ago

      You’ve not heard of ISO compliance. Time to delete your surly, ill-informed diatribe.

    • sudoshakes@reddthat.comOP
      link
      fedilink
      arrow-up
      3
      ·
      19 hours ago

      So… not entirely accurate.

      When setting up campaigns in software like KnowBe4, you must make sure the existing protections don’t flag emails you send in your campaigns. These are usually defined in something like defender for cloud as a policy, and so additional policies for knowB4 mail campaigns have to be set so you don’t prevent them from being caught.

      However, this is mostly just to ensure you get targeted content for a campaign to end users, and most every email we send would pass through anyway. We set the defender for cloud exceptions because we do not want to falsely impact measures on targeted cohort performance with defender policies.

      The above email for example would not be flagged as phishing by any current policies in place in our organization.

      While it is easy to be cynical about the phishing email campaigns, they do exist to try and get to a more mindful state of your users. We have research that supports their efficacy, and while you won’t ever get end users to universally “good” levels of behaviors around phishing, we can’t make that perfection be the enemy of trying to be more mindful.

      Still, it is humorous when you define a campaign and make it more specifically targeted for C suite cohorts only to get told to tone it down. They missed the point indeed.

    • IphtashuFitz@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      19 hours ago

      My employer uses Google for email, etc. There are email headers in the tests we get like X-PHISHTEST and X-SECURITY-TEST. I wrote a Google script that analyzes incoming emails for these headers and adds a “Phishing” tag to anything with one of these headers. So they show up highlighted in my inbox. I doubt I’m the only person who has done something like this.

      • Trainguyrom@reddthat.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        15 hours ago

        If the words “email headers” are anything more than gobblygook to you, then you’re not the one the clicker trainings are intended for.

        The phish test emails are however quite handy for staying vigilant. When good defenses make it take years for a real phishing email to sneak through, then being already primed by the quarterly phish tests to be suspicious helps ensure that as many people as possible don’t get compromised

      • horse@feddit.org
        link
        fedilink
        arrow-up
        2
        ·
        18 hours ago

        The people who know how to do that are probably not the people falling for the mails anyway.

  • Blackmist@feddit.uk
    link
    fedilink
    English
    arrow-up
    37
    ·
    1 day ago

    I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.

    Don’t whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.

    I’m not sure who these courses were even for. I was born in the scams. Moulded by them. I didn’t see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.

    • Burninator05@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      1 day ago

      My org has us do the standard phishing training and then sends out completely legit links that ring all the alarm bells. Lots of survey links coming from whatever random domains they found to host it. Links to official applications that ask for to many permissions and are shady as fuck. Its surprising we don’t get got more often.

    • monkeyslikebananas2@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      I remember those paper schemes!!! If everyone just sends money around it will multiply and you can make millions! I got one and tracked down some of the people on the list to see how much they got. I was 17 and just heading to college at the time.