Remix.run Logo
LgWoodenBadger 2 hours ago

Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate.

Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).

voakbasda an hour ago | parent [-]

FWIW, they put a header in the message that you can spot from a thousand miles away. That is how they get past the filters.

I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely.

It’s compliance theater. No real security is gained, but it checks all the boxes.