Can’t make the wrong people look bad.
I’m out of the loop, what happened here?
This email is the phishing attempt test itself. It says you are exempt from the phishing testing, but then tells you to put your account information on a random website.
Oooh, yes!
I think the implication is that this is the fishing attempt they sent this to the higher ups / IT staff and got bites.
Fun fact, those fishing emails usually share header information unique to the phishing email test service.
That is exactly how I phish (ha) them out as they hit my inbox!

You guys are making pastries without me?

The Bullshit thing about these phishing email tests is if you look at the actual headers they are allowed past the server level spam filters and in a back door to your email address. They would never pass the basic filters. They are not even training you for reality.
These “online safety” companies create this baloney meat training so that your IT manager can say they are doing something, and your company can report compliance with whatever code they are responsible to, so they can be insured.
Just bring this truth up and wait for an undue amount of pressure and scrutiny to suddenly fall upon you. You are getting in the way of a scam that all parties are aware of and perfectly ok with.
TLDR your company needs insurance to secure its assets/accrue investment but its actually impossible to train your staff to prevent sophisticated and professional hacker ingress. They are all pretending that a paper clip wrapped around the gate latch is adequate, and will be very upset with you if you expose the reality of this fraud.
You are getting in the way of a scam that all parties are aware of and perfectly ok with.
As a moron, I wish companies would just fucking tell me about their scams. I never catch on until a few months after I leave the company.
The Bullshit thing about these phishing email tests is if you look at the actual headers they are allowed past the server level spam filters and in a back door to your email address. They would never pass the basic filters.
Being able to bypass the automated filtering is entirely logical, because they are testing and training humans and not the spam filters.
They are not even training you for reality.
They are training you to be the next line of defense after the automated filters are defeated. Which is, obviously, a thing which does happen frequently - eg, in every real phishing attack which succeeds.
These “online safety” companies create this baloney meat training so that your IT manager can say they are doing something, and your company can report compliance with whatever code they are responsible to, so they can be insured.
There is some truth to that, but on the other hand at any large enough organization many people will still fail these tests. And, even if you’re sure that you’re too smart for them, don’t you think that being periodically subjected to these tests probably does actually make some people a bit more cautious?
I’m usually really good about security, but even I once failed one of the tests. I was doing some work for the city with Wells Fargo and was expecting an email from them, and that week’s phishing test was a fake Wells Fargo email, and it got me.
It taught me that nobody is immune from fucking up.
Well if just clicking on a link counts as “gotcha” then consider me guilty as charged. Because I’ve been unsure about the underlying URL and wanted to know what page loads. But my web browser is jailed. My point is: you didn’t get phished until you give away any info other than “someone received the email and clicked on the link”
Some mail providers will show you a link preview on click or on hover.
They’re testing to see what happens when their filter fails to catch something.
They don’t know how to simulate an email that would get through the filters. If they knew how to do that, they’d just update the filters.
Instead, they say “hypothetically, if something did make it through our filters, would people fall for the phishing attempt?”
Sure, there’s some CYA behaviour here, and trying to look busy. But, just because they’re using a trick to get past the spam filters doesn’t mean the test is invalid. They’re not testing the spam filters, they’re testing the users.
So… not entirely accurate.
When setting up campaigns in software like KnowBe4, you must make sure the existing protections don’t flag emails you send in your campaigns. These are usually defined in something like defender for cloud as a policy, and so additional policies for knowB4 mail campaigns have to be set so you don’t prevent them from being caught.
However, this is mostly just to ensure you get targeted content for a campaign to end users, and most every email we send would pass through anyway. We set the defender for cloud exceptions because we do not want to falsely impact measures on targeted cohort performance with defender policies.
The above email for example would not be flagged as phishing by any current policies in place in our organization.
While it is easy to be cynical about the phishing email campaigns, they do exist to try and get to a more mindful state of your users. We have research that supports their efficacy, and while you won’t ever get end users to universally “good” levels of behaviors around phishing, we can’t make that perfection be the enemy of trying to be more mindful.
Still, it is humorous when you define a campaign and make it more specifically targeted for C suite cohorts only to get told to tone it down. They missed the point indeed.
My employer uses Google for email, etc. There are email headers in the tests we get like X-PHISHTEST and X-SECURITY-TEST. I wrote a Google script that analyzes incoming emails for these headers and adds a “Phishing” tag to anything with one of these headers. So they show up highlighted in my inbox. I doubt I’m the only person who has done something like this.
If the words “email headers” are anything more than gobblygook to you, then you’re not the one the clicker trainings are intended for.
The phish test emails are however quite handy for staying vigilant. When good defenses make it take years for a real phishing email to sneak through, then being already primed by the quarterly phish tests to be suspicious helps ensure that as many people as possible don’t get compromised
The people who know how to do that are probably not the people falling for the mails anyway.
My company: Don’t click on suspicious links.
Also my company: It’s employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx
I mark them as phishing attempts every damn time.
Heh, an employee at my work got an email saying his anti-malware was failing to update, and to run http://10.3.4.2/xbejdjr.exe and that they need to click allow when the browser warns them that it is rejected, then right click, run as administrator, and they need to click allow in two other places to let it run.
So he reported as phishing, then IT contacted his manager saying he was failing to help IT run a required update, it was evidently totally legit, but just the most scammy looking way they imagined.
That is so fucking sketchy, I’d have to talk to the IT guy myself or get on a video call to make sure their email or the group chat or whatever wasn’t compromised.
Lol. That’s not sketchy at all. /s
I tried to make the case to IT that hyperlinks are not a threat vector on their own. They should train against opening attachments and entering credentials once the link is clicked. I haven’t heard back yet, I’m not sure they liked my message. But they did send a message letting us all know that reporting non-phishing surveys wastes their time.
The argument regarding hyperlinks is generally that there are 1-2 click zero-day vulnerabilities pretty frequently, so clicking a hyperlink will take you to a server controlled by the attacker which may or may not employ one of those. Additionally there’s a constantly rotating array of obscure HTML/CSS hacks to trick even the savviest of users into thinking an attacker controlled window is something else or otherwise compromise a users system without utilizing zero-days. And finally good ol’ social engineering typically relies on several vectors at once, so by the time someone’s clicked the link there’s a good chance they might go further for the attacker before they clue in.
So yeah, theoretically if everything was as it should be, clicking the hyperlink and downloading and executing literal malware wouldn’t work, but security is about trying to make sure the weak points of every part of the chain don’t line up, because when those holes in all of the layers of security line up, you’ve got a nice big compromise to clean up, and those buggers are like bedbugs, once they get in, you can be chasing them for months or years until you’re finally rid of them
The web is very locked down already. People click so many links from email, but also outside of email. Clicking a hyperlink in an email is not a threat vector. If it was, we can’t vote on when to meet, open shared documents, or basically do anything other than plaintext email. Aha! That’s the solution. Plaintext email - all attachments and HTML are blocked.
Do we work in the same company?
You work for GSK don’t you
I have gotten texts from our Cybersecurity warning me not to open links in texts…and they include a link to a web page for more information.
I just delete all emails, i’ve never felt more productive
We have to take monthly “education” videos that are supposed to be fun, but come off as try-hard.
They blast out phishing attempts that most morons would ID in a heartbeat. They send out “top 5 signs it’s a phishing attempt”
Then the director loses his shit at people when something he sends out very literally meets all the criteria from his Top 5 Signs example and it gets reported by 50+ people.
Whenever id report something and it’s give that “you make the company safer” popup id always Photoshop onto that “This is worthless” meme and send it to people
My old boss used to sometimes send random links in the chat. Sometimes with a “check this out” generic description.
I’d tell him that looked like phishing every time, but he didn’t care.
99% of the time you can tell by checking the sender domain.
I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.
Don’t whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.
I’m not sure who these courses were even for. I was born in the scams. Moulded by them. I didn’t see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.
My org has us do the standard phishing training and then sends out completely legit links that ring all the alarm bells. Lots of survey links coming from whatever random domains they found to host it. Links to official applications that ask for to many permissions and are shady as fuck. Its surprising we don’t get got more often.
I remember those paper schemes!!! If everyone just sends money around it will multiply and you can make millions! I got one and tracked down some of the people on the list to see how much they got. I was 17 and just heading to college at the time.
The best defence against phishing I have found is to just utterly ignore my email inbox at work.
You missed our recent phishing email, try to report it next time
No, I was so cautious I avoided my whole inbox because it might contain suspicious messages.
Hey at least that was somewhat tempting.
My organization sends out just braindead crap that wouldn’t catch anyone, even boomers. I just flag half of them and then respond to their little congratulatory popup to remind them how pathetic they are with their half-assed attempt, that they should feel bad for failing this hard, and posting the link to the study that none of this crap helps with mitigating phishing and then click the ever loving crap out of the other half.
My organization sends out just braindead crap that wouldn’t catch anyone, even boomers
You’d be surprised at the click-thru rate of those! I don’t think I’ve ever seen a phishing test get less than 10% click through rate

IT guy here…
DAMN, that was brilliant!
Same. I saved it to add to our KnowBe4 templates
You can always forward it back to IT saying it’s a suspicious link, according to this blog link you found. The blog link… Your own phishing link.
Two can play this game.
I was working IT Support for a company and we got really busy.
At the next all hands the VP mentioned everyone gets doordash giftcards to cover a company lunch remotely and asked for confirmation. First time doing this.
I said I didn’t have mine. Why? Sent to spam of course!
Gift card? From my company?? Must be spam!
It’s like driving a white minvan and offering random kids candy. I get it, you’re just trying to do something nice for the community, but you dont have to do it the exact same a child rapists hunts for victims!












