And twice last week. Few times the month before that.
Even configured Exchange to give people a “report suspected phishing” button in their outlook clients.
They keep on clickin’.
(Each time was a different person btw)
Edit following the comments: maybe reversing the approach would work, by attaching monetary rewards to correctly reporting phishing emails? That would encourage everyone to be extra suspicious and report anything that looks amiss for the chance of getting some extra cash while avoiding the negatives of firing people on sight.
This time is much better spent securing the environment: spend the money on Yubikeys, lock down your default browser or use an isolation system, beef up your network filtering, etc. — things which can actually work and won’t make your users think you’re just trying to get them fired.
I guess instead of a penalty a more user-friendly way would be to attach monetary rewards to reporting phishing emails? That would incentivize reporting anything that looks even just slightly suspicious, which is probably a better outcome from a security point of view even with false positives.
We use one of those services, too, and you have to use a very light touch. Just using them at all makes people paranoid. If there are people you find who pose a risk, yes, you should do something about that, but terrorizing your workforce is a terrible idea for multiple reasons.
> putting their own employment at risk
Even looking at it amorally, that only really works in declining industries where people don't have a choice. Do that to engineers in a hot economy, and I suspect you'll be employing only the otherwise-unemployable soon.
Less than 3 months later, HR was begging people to click the link in their email to set up their benefits for the year, because they had a 0% click-through rate.
Hang up, look up, call back.
Turns out it was the link to our mandatory security training portal. Of all the people to get it wrong....
This is why I would usually focus on things like WebAuthn (making phishing much harder) or locking down the default browser environment more so it takes more than one click to cause a major problem. That doesn’t prevent social engineering, of course, but that requires a lot more work and gives more time for other safeguards to work.
Getting the money would be hard, and you would be easy to track.
They would probably be better off just collecting the credit card info and selling it.
I endorse absolutely none of this, just to be clear.
The best scam is the one that isn't detected. There's a story about a guy who collected £3 from every visitor to the Bristol Zoo car park here in the UK. Supposedly he did it for nearly two decades. Car park was free. No idea if it's real.
https://www.youtube.com/watch?v=FsWcc-9KMEc
This one's actually rather clever.
https://www.courthousenews.com/hertz-settles-flap-over-golde...
Smart person? Sounds more like a person looking for trouble.
Maybe the fake app can say "Now you need to go to walmart.com to buy a gift card and enter that gift card code's to pay for parking", but that would filter out a lot of people who was looking for convenience in the first place. If I were consulting for this criminal, I'd say "You need to get to their greed by offering them a big prize, e.g. 1 year free parking in $CITY...".
These scammers are either smart and done everything anonymously, or too stupid to understand how this can all be tracked, but unfortunately this stupidity does often end up paying off.
You're telling me. (not so humble brag) I developed a software solution and 3 patents granted over 10 years ago to stop these kind of shenanigans. Ahead of our time.
*Unfortunately, matrix barcodes may sometimes reference malicious websites, which may be used to steal confidential information (e.g., user credentials or credit card numbers) as part of a phishing attack or exploit vulnerabilities in mobile web browser software that may allow malware to be downloaded to a user's mobile computing device. Furthermore, some legitimate Internet resources (through the use of spam, comment posts, etc.) may be used to redirect users to malicious websites. Accordingly, the instant disclosure identifies a need for systems and methods for providing security information about quick response codes.*
https://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=...