Post B6pegcSCr6H5DpjJia by nest@infosec.exchange
(DIR) More posts by nest@infosec.exchange
(DIR) Post #B6kdncxCK9Gd3TCiUy by 0xabad1dea@infosec.exchange
1 likes, 3 repeats
the infosec people at my work are rioting because the Distant Corporate Overlord sent an email that scores 10/10 on the phishing scale (“We want to give you a present to thank you for all your hard work! [Click here] to claim your gift!”)
(DIR) Post #B6m6mWdBREGiz5d4pU by 0xabad1dea@infosec.exchange
0 likes, 2 repeats
phishing training really doesn’t spend enough time on “how to structure your mass corporate communications in such a way that your employees won’t conclude that you communicate exactly like scammers and still expect a reply so they’d better assume scammy emails are legitimate”
(DIR) Post #B6m6mWtqRHb1olQNnc by david_chisnall@infosec.exchange
0 likes, 1 repeats
@0xabad1dea Microsoft put a big blue banner on all the broadcast-internal emails.I was in a meeting of the D&I Council where someone said they'd sent an email about an event and was surprised I didn't know about it. I eventually found the email: it had the same blue banner.That was when I learned that I had been trained to ignore any email that started with the blue banner. Asking around, I was not the only one. A lot of the internal communication problems had the root cause that there was so much pointless broadcast email that everyone ignored them and missed the important ones.Someone did an internal thing for a hackathon as an Outlook plugin that would estimate the reading time for emails, interrogate the employee database to find the levels, multiply by the average salary for that level scaled to the reading time, and then give you an estimate of how much an email was costing the company if the recipients read it. It never shipped because management didn't like being reminded that they were burning tens of thousands of dollars with their emails.
(DIR) Post #B6pedohmqhLkLlgIqW by lupinia@infosec.exchange
1 likes, 0 repeats
@0xabad1dea This heavily overlaps with a wider societal problem of legitimate customer service communication being largely indistinguishable from scams to most people - intentional confusion and constant change, huge amounts of information disclosure required to do anything without always knowing why (and hesitation can be penalized), and so on. Pretty much entirely by design, in an attempt to minimize anyone's desire to ever contact companies directly.
(DIR) Post #B6pegcSCr6H5DpjJia by nest@infosec.exchange
1 likes, 0 repeats
@0xabad1deamy job did this before christmas. they even went an extra mile and registered a new domain "company name christmas gift dot com" and even created a new corporate email address. i was working on infosec department there and we had a looong talk with the marketing folks after this.
(DIR) Post #B6pemjURbmGAmWgxKC by 0xabad1dea@infosec.exchange
1 likes, 0 repeats
@bremner I have in fact said to my coworkers "Emails from the corporate overlord aren't real until my manager asks why I haven't responded yet" [to be clear, we were a small company that was acquired by a much bigger company in another country]
(DIR) Post #B6pepPS2ZIyHV8qNcm by crankylinuxuser@infosec.exchange
1 likes, 0 repeats
@0xabad1dea The real scary email isnt some dumb phishing. The scary is straight forward."We are a #ransomware operator. We would like for you to run this script on your work machine. If you do, we'll pay you $1000 in your choice of crypto. If they pay the ransom, we pay you 10%."That weaponizes ransomware so that everybody is a potential #insiderthreat. And given these days with so much job abuse due to terrible conditions, sending a few of these emails are sure to hit someone disgruntled enough to say fuckit.
(DIR) Post #B6petEbSqKKZ104kiW by paul_ipv6@infosec.exchange
1 likes, 0 repeats
@0xabad1dea a large company i worked at had mandatory phishing training as a video. they outsourced but HR forgot to let anyone know that the email for the video would come from an external firm and the link would also be a seemingly random outside link.engineering mostly reported the email as a phishing attack. the VP of eng was proud, HR was pissed and embarassed.some of us argued that we should be given a passing grade and not have to watch the video but, sadly, they still made us waste our time watching it.