Social engineering GoDaddy (2021)
g.livejournal.com
g.livejournal.com
Most associates knew or had seen the names (they were required to be posted in the break room) but often times never met the people in question. The attacker got associates and other shift/associate managers to do everything from giving up secure information on the registers to ring up gift cards.
It was happening two to three times a week in our district at times despite weekly training and conference calls on the subject. Some people are just born to be duped.
Nah, all people are born to be duped. Nobody can be vigilant all the time. There's a point where you have to let down your guard and trust that there's no monster ready to pounce on you from the shadows. Vigilance has its own costs that often work against the tasks at hand, and can really fry your body if held high for too long.
As GM you may have been especially vigilant about this issue because you saw yourself as the steward of your store(s), but those associates weren't in the same position and were bound to be more lax on net.
It doesn't sound like these social engineering attacks tanked the company, so whatever dynamic existed between everyone seemed to work adequately.
https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
https://medium.com/@espringe/amazon-s-customer-service-backd...
The screenshots of the attack/transcript make my stomach hurt.
* Supervisor communication will always come through Slack, or email or some other mechanism. * Never trust that the identity of anyone on the phone is someone internal unless you initiated the call.
Someone posted malicious stuff on his website, which showed up when googling my friends name. This costed him quite some business.
He knew the email address of the website owner, and the provider where the website was hosted. So he registered the same email address under a different free email hosting provider. Then he sent the website hoster an e-mail where he told them about a new email address and if they could change it. With that he could reset the password and delete the website.
We had to call GoDaddy and cancel the domain transfer, they would give us no information on how it happened.
Maybe they committed some other crime against GoDaddy, but I'm not a lawyer and I'm not sure what. They impersonated a call center manager, but I'm not sure if that's against the law. After that the employee willingly told them things.
As a non-sequiter, I'd say GoDaddy is a crime against humanity