• jjagaimo@lemmy.ca
    link
    fedilink
    English
    arrow-up
    64
    ·
    3 years ago

    Today I got an email from management, something along the lines of “you didnt click the link in this email we sent as a required questionnaire about phishing, some people reported it as phishing: a reminder, all emails from IT@company.com are not phishing”

    There was no previous email

    I checked the message details and it said “THIS IS A PHISHING TEST BY external company”

    It was a phishing test disguised as an urgent reminder to answer a phishing questionnaire, replying to a nonexistent email. I can’t wait until Monday when they round up everyone who clicked the link

      • chiliedogg@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        3 years ago

        I work for a small-ish but fast-growing municipality, and we’re getting increasingly well-targeted actual attacks. Instead of posing as “The IT department” they’re posing as my boss or the City Manager by name.

        This week they even started name-dropping the conference most of the directors were actually attending as an excuse why we wouldn’t be able to reach out and talk to them before the "request$ was due.

    • dditty@lemm.ee
      link
      fedilink
      arrow-up
      12
      ·
      3 years ago

      Wow damn that’d trick whole swaths of our org 🤦. Sad how many people we still get with the super obvious “Free $5 on Venmo” phishing tests…