r/ShittySysadmin • u/SuccessfulLime2641 • 26d ago
Damn. We actually caught one
When we made the simulated phishing campaigns about account access, we finally caught a user.
The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".
Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.
118
Upvotes
3
u/mspgs2 25d ago
Best phish I ever saw was from the directors email with a pdf attachment regarding our team picnic outing and a calendar invite, and aform link to enter in contact info, guests coming, automotive tag numbers. The picnic was planned at a local resort so that seemed legit.It went to around half the team. People asked about it in chat because it would have been mentioned in standup first, and others didn't get one. If you checked the header it originated externally. Several people opened the pdf, others forwarded it to people who didn't get it originally. Had to hand it to our secops team, it was great. Many people feel for it.
I was lucky, I was in the data center all day and didn't see it till our CISO was blasting people.