The ironic thing is what made me realize it was legitimate: She was initially asking me about my physical address; I didn't give her the information but asked what she had on file. Two numbers were transposed. When I realized it was probably legitimate was when she was trying very hard to send me a bill for a statement they mailed to the wrong zip code, and she was insisting that I must have lived in that town at some point.
I told her I wasn't going to pay them a cent for a mistake on their part, and that I needed to talk to my local branch. So I hung up, called them, and found it it was legitimate. One of the employees transposed two digits on an account I'd just set up about a month prior.
But holy crap do you have to be careful about giving any information out. I can't imagine if this had been a phishing attempted from the bank itself. I think I would've dumped them to be sure!
I suppose with internal users you can theoretically target test-failures for individual training or performance intervention - for customers you can’t do that.
That annoyed me to no end.
Literally the email domain, address, company, etc would match something in real life (I checked).
Is that phishing or just being a dick?
It was obviously fake, but the timing was so suspicious, and it came in to the wrong email address - so my first thought was not ‘ah, here’s my Google play invoice’; nor was it ‘ah, a phishing test, let me report it and feel smug’. It was ‘oh crap, my phone must be compromised’ - if someone knows I just updated a Google play subscription, and they cross-associated it with my work email, the only place those come together is on my phone.
Then when I got confirmation that it was a simulated phishing email, my second thought was ‘wait, did the corporate endpoint security system monitor that I was just on the Google play store and send me a targeted phishing attack?’ - which is a significant hit to the degree of trust I place in my employer.
Turns out no, it really was just a randomly selected phishing template and a wild coincidence. But for me it says it is a very bad idea to send out phishing emails that masquerade as real services your employees might use in their private life.
So my train-of-thought goes something like: If my customers are going to get hacked, its better they get hacked by my good-guys than actual criminals. If they're more suspicious about clicking on links from my bank (or links that LOOK like they're from my bank) - it isn't necessarily a bad thing.
Yeah but they are not mutually exclusive.