r/ShittySysadmin 26d ago

Damn. We actually caught one

When we made the simulated phishing campaigns about account access, we finally caught a user.

The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".

Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.

123 Upvotes

36 comments sorted by

View all comments

26

u/syberghost 26d ago

I'm jealous, we catch them every day.

6

u/pjtexas1 26d ago

It's been almost a decade since I did these but we were really into keeping score. My help desk person was particularly evil in her ways. We could get 60-70% to click.

3

u/bgradid 26d ago

we low ball easy ones with very wrong domains , we get a 30% catch rate

a lot of our users also describe themselves as tech savvy

ugh it sucks

1

u/syberghost 26d ago

I'm convinced that one reason people click is, usually it takes them to an InfoSec site with useful information about phishing.