Can’t make the wrong people look bad.

  • CMDR_Horn@lemmy.world
    link
    fedilink
    arrow-up
    46
    ·
    11 days ago

    Ive often suggested to our security team that they send one out spoofing the monthly mandatory training vid

    • wizardbeard@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      63
      arrow-down
      1
      ·
      11 days ago

      The issue is that people’s egos get bruised when they fall for it, and they’ll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.

      What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there’s no way to check the actual link before you click it since they’re all just like garbagesec.com/4a12c89e7f now.

        • CMDR_Horn@lemmy.world
          link
          fedilink
          arrow-up
          16
          ·
          11 days ago

          Ours is exactly the same as this lol. The joke is we are an IT firm so everyone except from sales and hr easily detetct it.

        • Ziglin (it/they)@lemmy.world
          link
          fedilink
          English
          arrow-up
          14
          ·
          11 days ago

          But real phishing emails will have the same treatment as normal emails making them harder to detect. Sounds like a really bad system that probably doesn’t offer any advantages over a pihole.

        • dendie@piefed.social
          link
          fedilink
          English
          arrow-up
          5
          ·
          11 days ago

          Ours seems to set a header like X-Phishing-Test on the email so it’s trivially easy to get them right every time

      • SpiceyDejarik@infosec.pub
        link
        fedilink
        arrow-up
        3
        ·
        10 days ago

        At work, we use Safe Links in Microsoft Defender so examining the URL of a link in an email was always a pain, but Microsoft actually made a useful change recently. Now when I over over the link in Outlook, it displays the Original URL without all of the Safe Links gibberish. The link itself still goes through Safe Links, but the hover shows me the destination URL. I was pleasantly surprised when I noticed this.

        • wizardbeard@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 days ago

          We were doing that, until our infosec team needed to justify themselves, and decided an easy win would be to pay another vendor even more for the link protection that was already included in our Microsoft licensing.

      • SendMePhotos@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        9 days ago

        Yours too? I hate it. I can’t scan the URL and it drives me crazy. You just took away a way to identify a scam attempt.

    • Bane_Killgrind@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      23
      ·
      11 days ago

      PFF I don’t click on any training emails unless my manager is asking about it in person.

      If it’s not important enough for them to follow up on, it’s not important.

      • hemko@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        5
        ·
        11 days ago

        Yeah I created a rule that checks for a specific header in the mail from the phishing test platform, and junks those emails. Luckily, also the monthly security training emails also have the same X header