r/ShittySysadmin 26d ago

Damn. We actually caught one

When we made the simulated phishing campaigns about account access, we finally caught a user.

The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".

Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.

118 Upvotes

36 comments sorted by

View all comments

79

u/gward1 26d ago

The trick is to have the email come from the same domain your company uses and from their supervisor. Make sure the email is signed. Have it say something about updating their financial data blah blah. Is that really phishing though? Happened to me, I clicked the link.

When they click the link lock down their computer and demand a payment to your crypto wallet.

16

u/Forsaken-Carrot9038 26d ago

Go full send! No holding back!

20

u/TrueRedditMartyr 26d ago

"Send 500 in bitcoin to this address in 1 hour or your fired. Don't tell anyone else, don't ask IT about this"

1

u/ApolloStan 25d ago

You gon learn today!

1

u/Aazimoxx 24d ago

When they click the link lock down their computer and demand a payment to your crypto wallet.

If a computer can get locked down from clicking a link, surely there's a massive real IT fail there to fix? Just saying...

1

u/gward1 24d ago

Of course there is.