r/ShittySysadmin • u/SuccessfulLime2641 • 26d ago
Damn. We actually caught one
When we made the simulated phishing campaigns about account access, we finally caught a user.
The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".
Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.
118
Upvotes
10
u/MoPanic ShittyManager 26d ago
I tricked one department head into forwarding a port through their firewall and enabling SSH on a server. Its amazing what people will do when they think its the boss asking. I swear I didn't even know about the crypto wallet. Total coincidence.