Sequoia Capital says it was hacked
axios.com
axios.com
The click rate for links in those emails is shockingly high.
If you have a sophisticated attacker using spear fishing using company information then it's even more effective.
"Hey, [coworker X] told me I should send you our latest policy document for [project Y], here's the link"
Many people were upset to find out that the free gift was, surprise, extra security refresher training.
I work for a large company with a common email address format, and I'm constantly getting personalised emails, complete with my name and vaguely related to my work, advertising training and seminars (although I'm yet to be targeted by a spear phishing attack).
I assume they just trawled LinkedIn to find people working at the company and their role. Our email addresses follow a standard format, so it's trivial to guess what my email address is.
We also get monthly simulated phishing emails from our security team.
I've just gotten into the habit of not reading emails. Everything important comes through Slack, my email inbox is mostly automated emails from a dozen different services and company announcements that I don't bother reading.
1. Educate them not to open links until they are sure - in emails originated from outside or obscure looking domains 2. Spot for spelling mistakes to find out if it’s a phishing email
His most important lesson was: don't vote or you enable the fraud and corruption pretending to give you a choice.