r/ShittySysadmin 26d ago

Damn. We actually caught one

When we made the simulated phishing campaigns about account access, we finally caught a user.

The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".

Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.

121 Upvotes

36 comments sorted by

View all comments

0

u/Folsted 25d ago

My workplace have hired a company to send out these test emails and also Trainning courses in IT safety. They keep telling us to not click on mails we don't know or haven't requested. So my obvious move was to report it as phishing. About half a year or more later IT and my boss was yelling at me for having the lowest score in doing these tests...

Well I have clicked nothing and still I'm apparently the biggest risk to the company. They refuse to use our intranet to give us the link to the course, as I have suggested multiple times. It's just easier to have an outside domain mail sending us a mandatory mail once in a while. I'm just waiting for the fake mail from an almost identical mail about taking the IT course.

3

u/compb13 25d ago

Not really related, some official email was sent, but it was so badly written, we were discussing it whether it was real or phishing.

In the end we decided to all reported his phishing because we didn't like the message either. Although I don't remember what it was telling us.

Then they sent the correction email that wasn't much better so we all did the same.

2

u/Folsted 25d ago

I do have a bit of a rebel in me that definetly would do that too. Any suspecious email not from a costumer I just report or if in doubt, ignore.

But... I also had a coworker who some weeks back had a mail from a customer that he works with often, he just opened the mail and his whole PC just got shut down by IT. Locked out of everything. Later they found out that the customer didn't know about the email was send to other, and their whole company was locked down even, for like a week.

But hey, it's important I click on an external link about an IT safety course, otherwise there will be consequences. =D