US police force pay Bitcoin ransom in Cryptolocker malware scam
theguardian.com
theguardian.com
How the hell would they even know?
It is very easy to steal data. Copy the data, and then delete the original. However, the goal of this malware is to neither delete nor copy the data. It simply sabotage the data, after which the computer user has to pay in order for getting the data restored.
Training would ideally involve the organization testing by spearphishing their own employees internally like a lot of security companies often do:
http://www.darkreading.com/end-user/how-lockheed-martin-phis...
The ones I've seen are pretty good, all the lingo is correct. They're pushing all the right buttons in the email which would immediately get an accountant or business owner to open it immediately to find out what was wrong.
The only obvious warning sign is the zip attachment.
Followup questions:
How does Microsoft avoid hiring people below the 2nd percentile in computer literacy? They have way more than 50 developers.
Should the police force screen applicants in any way?
Is using a computer part of a police officer's job?
Are the police even able to compel randomly-chosen people to work for them? If not, the premise of your numbers is fatally flawed.
Is it more or less likely? The police don't hire on technical skill, presumably people of high skill in this area end up in different careers?
The accuracy of the numbers is, frankly, unimportant. What I was illustrating was the multiplicative effect, which remains relevant. I freely admit the numbers themselves were made up.
Now, it's definitely not true that you have to be below the second percentile to get phished: http://www.locusmag.com/Perspectives/2010/05/cory-doctorow-p...
But if it were true, phishing would be largely a nonissue for workforces (other than the police, who often do set ultra-low thresholds for their screening).
I think you and I are on the same page.
I am curious on why you think I'm off the mark, even if people under the 2nd percentile are less likely to get hired, it doesn't really change the math, it's the same as saying: "but it's only people under the first percentile!"
Side note: I feel that 150 million people are employable in professions that don't require a competency with computers. At the very least I'm grateful that same property doesn't apply to carpentry or construction. As I'm easily in the first percentile for these trades, I'd NEVER get a job. I can't even hang a picture! Why does it always go wrong? T.T
They probably just don't care because they're not paying for it themselves. A construction manager told me once that the rate at which his workers' phones were breaking dropped significantly when the workers were made to pay for the new phones themselves.
Maybe something like this could serve as a basis for what you propose. The attachment I saved came from https:///mail-attachment.googleusercontent.com. Maybe the solution is as simple as webmail providers putting some standard hostname in their attachment URL that identifies it as an email attachment.
Unfortunately though, there are legitimate reasons to circumvent this (have you ever emailed yourself something so you could run it on another computer?), so it would only be a matter of time for attackers to figure out the social engineering required to convince people to jump through those hoops.