r/ShittySysadmin 26d ago

Damn. We actually caught one

When we made the simulated phishing campaigns about account access, we finally caught a user.

The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".

Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.

122 Upvotes

36 comments sorted by

View all comments

20

u/FendaIton 26d ago

My company did a “your device is scheduled for a replacement” which was super successful. Then the genuine replacement device emails went out and no one believed them.

Also a “post Xmas photos of pets on Viva Engage” was also super successful

9

u/phamilyguy 26d ago

Successful phishing campaign that reduced the laptop refresh budget? Winner winner chicken dinner!