As someone working in software development, we are required to take part in the security trainings, the usual “don’t open things from people you don’t know” and “verify that a link is ‘known’ even if you get something from a person you do know”, yada yada. You know the drill.
Recently, I got an email from our Boss saying something about “Here is something that you need to click on so that you are being authorised to do this stuff”. Here was my thought process:
This is from the boss’s Email. But this cannot be trusted since it can be faked
This is about something we/our software can do. But I don’t know why I have to do this, since this isn’t really something I am part of or even know anything about
It looks like a legit email
I hovered over the link, which had some weird target location that I didn’t know
So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: “Got an email that tells me that I should open this link, but I don’t know this link. What should I do?”. The response was simple: Mark as Phishing and delete the Mail, done.
2 hours later, I got a message on Teams from IT which said: “Well, apparently that mail you marked as phishing was actually from us (was legit)”. Great. Mail is gone now, don’t know where Outlook put it, and frankly, I don’t care.
If you train your people to “question everything” and not open links they don’t know where they are going, then don’t use some idiotic “middle man” or referer links in your official emails either. Even better, announce things before sending something out. I don’t know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.
I had a previous company send out a company wide announcement from a sketchy sender with a weird file attachment(apparently it’s a voice mail file format), and the email was essentially listen to this attachment with no signature or anything else. They had to send out a second email explaining the suspicious email is actually real. Companies seem intent on ensuring there is minimal difference between phishing and legitimate email.
Honestly, this is preferable, and pretty funny. IT can always resend invites to tools and services. I’d rather send 1000 of those than have to lock someone out and have to talk to a human.
That reminds me of a recent situation.
As someone working in software development, we are required to take part in the security trainings, the usual “don’t open things from people you don’t know” and “verify that a link is ‘known’ even if you get something from a person you do know”, yada yada. You know the drill.
Recently, I got an email from our Boss saying something about “Here is something that you need to click on so that you are being authorised to do this stuff”. Here was my thought process:
So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: “Got an email that tells me that I should open this link, but I don’t know this link. What should I do?”. The response was simple: Mark as Phishing and delete the Mail, done.
2 hours later, I got a message on Teams from IT which said: “Well, apparently that mail you marked as phishing was actually from us (was legit)”. Great. Mail is gone now, don’t know where Outlook put it, and frankly, I don’t care.
If you train your people to “question everything” and not open links they don’t know where they are going, then don’t use some idiotic “middle man” or referer links in your official emails either. Even better, announce things before sending something out. I don’t know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.
I had a previous company send out a company wide announcement from a sketchy sender with a weird file attachment(apparently it’s a voice mail file format), and the email was essentially listen to this attachment with no signature or anything else. They had to send out a second email explaining the suspicious email is actually real. Companies seem intent on ensuring there is minimal difference between phishing and legitimate email.
Honestly, this is preferable, and pretty funny. IT can always resend invites to tools and services. I’d rather send 1000 of those than have to lock someone out and have to talk to a human.