Are people really so gullible & trusting?
Are people really so gullible & trusting?
That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.
If a company gets owned because they failed to implement SPF or DKIM properly, IT is at fault, not the employee.
Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers."
I do builds by hand of this product because I can't get resources allocated to automate it
I have never heard of any of these people before. I reply asking, "I am sure I can accommodate you, but, Who are you and why I haven't been told about this before now?"
To my shock, the guy replies, "I'm the European Vice President for product X, we didn't ask before now because it has never been a problem in the past. Who are you?"
I reply, "I'm the only person in the entire world with the encryption keys to provision the product, and that has to be done on one single computer in Santa Ana. It's only a fluke that I am here today-- my car wouldn't start this morning, and I had planned to take the day off to fix it, and then by some miracle an hour later it started. That's why it's important to know about things ahead of time."
That's what working at a big organization is like, you interact with people who don't know all the time. And frankly, nobody is ever allocated time for "security" in their schedule. My dance card at that company was scheduled for 8 hours of development a day, no e-mail answering, no security, no time to do the build system. No time for meetings. Nothing.
The chaos that surrounds you, the facts that astound you, at last your number has found you, your bus number is one.
But when your big org is hiring, let me know :)
Yes, and it is not a “bad” thing outside the niche of security I think. We should all hope to live a life where we can implicitly trust other human beings.
Skepticism and rational thinking require effort, and thus as people are rushed or tired, those are the first defenses to fail. You can train to recognize patterns of phishing, but learning those patterns takes time, repetition and effort.
All that a good phish requires is finding the right buttons to push on the right person, and they have many potential victims to press them on, and little to no consequence to getting it wrong.
So, the answer is people are not particularly gullible, but the weak links are a constantly changing, largely unknown dynamic and the phishers can hammer at all of them simultaneously until they get through.
If they value "responsiveness to their authority over procedure" then people will send the entire financial records to "the CEO" for fear of getting fired otherwise.
Most cases I've seen of successful (or nearly successful) spearphishing would have been solved by someone picking up a phone and calling their co-worker.
"I know you sent me an email, but can you just explain again why you want me to buy $1000 in iTunes gift cards and email them to you?"
"I got that invoice you sent. Just wanted to confirm the amounts -- $50k wire transfer?"