Remix.run Logo
jhbadger 3 hours ago

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!

LgWoodenBadger 2 hours ago | parent | next [-]

Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate.

Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).

voakbasda an hour ago | parent [-]

FWIW, they put a header in the message that you can spot from a thousand miles away. That is how they get past the filters.

I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely.

It’s compliance theater. No real security is gained, but it checks all the boxes.

starky 3 hours ago | parent | prev | next [-]

We have a training thing at work that sends out phishing emails and you are supposed to report them using a handy button in the email app. If they are training emails you get a good job website that pops up. I greatly enjoy reporting every single genuine email that reads anything like a potential phishing email as there is someone in IT that reviews them and probably gets annoyed at the various groups sending sketchy emails for official business.

AlotOfReading 2 hours ago | parent | prev | next [-]

I'm forced to have a relationship with a bank that sends out iPad giveaway emails, where your chance of winning is contingent on filling out a survey with personal information. These occasionally go out on the same day as their periodic "how to recognize scams" newsletter.

ern 2 hours ago | parent | prev [-]

A significant number of phishing attempts would be thwarted if email apps had the option to expand the links next to URLs on platforms without mouseover, like mobile.