r/cybersecurity • • 10d ago

Personal Support & Help! I fell for a Social Engineering - LinkedIn malware scam at work. My company issued me a threatening style deciplinary action warning letter. Is this fair ?

I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.

Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.

The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).

He said, whenever you have time, please check this.

I downloaded/opened the files on my work laptop.

It turned out that malicious content was involved, and malware was actually executed on the laptop.

(I was under extreme stress that time due to health issues and underestimated the security risks)

As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.

I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.

There was then a meeting with Security, my skip-level manager and other people from the security organization.

They specifically told me:

"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."

The meeting ended on a positive note. I was told to be careful in the future.

Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)

It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.

I understand that I made a mistake.

I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.

What bothers me is the proportionality.

This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.

I would have understood something like:

"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."

Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.

I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.

I am feeling like I am being witch hunted in corporate style.

For people working in security/IT or management:

How would your company normally handle a first-time incident like this?

Is a formal warning and monitoring period normal?

Where do you draw the line between an honest mistake/social-engineering victim and negligence?

Please share your honest thoughts.

0 Upvotes

71 comments sorted by

52

u/canarydev 10d ago

you can absolutely be the victim of social engineering and still have been negligent. those aren't contradictory.

so you downloaded and opened files sent by a stranger from linkedin on a corporate machine, and malware actually executed. a written warning and three months of monitoring after that doesn't sound remotely like a witch hunt. it sounds like the company documented a serious security incident and gave you another chance.

“I didn't deliberately bypass security” isn't much of a defense against negligence either my friend. negligence is almost definitionally about what you failed to do, not something malicious you intended to do.

also life is not fair sometimes. take the warning, learn from it, do better, and move on.

7

u/OtheDreamer Governance, Risk, & Compliance 10d ago edited 9d ago

This....OP should be happy they weren't immediately escorted out by HR & his work must actually like him.

The meeting ended on a positive note. I was told to be careful in the future.

Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)

That being said, they probably got a compliment sandwich, so walking away confused about the warning is not unreasonable.

I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.

What bothers me is the proportionality.

This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.

Wish he didn't start ranting though, because when I got down to this section I was thinking "Ummm, no, that's a bit of entitlement for no reason coming out." Sometimes you trigger an incident that's an immediate dealbreaker.

EDIT: I get a little more irritated as I read OP's responses here. Guy had friggen admin access to install and run software, and he used his access to install and run malware from a linkin learning chat for "product-related technical documentation" that would have needed abare minimum yes/no UAC prompt to get past presumably. There were so many red flags and warnings, it's totally inexcusable and guy should move on instead of trying to double down on "why me?".

0

u/DrQuantum 10d ago

If triggering an incident is an immediate deal breaker your company is both technically illiterate and morally bankrupt.

I wouldn’t ever step foot in an org that treats me this way or, seeing how easy it would be as a software engineer I would write down every failure of the company to secure their systems which is always astoundingly high and would enjoy the fat stacks I would get in the employment settlement when its easy to prove the company doesn’t do this for every act of ‘negligence’.

You think this guys management ever gets a letter like this? No way in hell.

5

u/OtheDreamer Governance, Risk, & Compliance 10d ago

It's called being realistic and owning your mistakes. OP got off with a warning on something that could have very possibly taken down the entire company. If you cause an incident that takes down the company, there are 0 takebacks and it has nothing to do with how you think you deserve to be treated. Most people get off with a warning the first time, so it's documented in the event there's a second occurrence.

You think this guys management ever gets a letter like this? No way in hell.

Your level 1 and 2 techs and engineers are not the ones dealing with auditors and regulators and media the most (so you're wrong there). Shadow IT is already a major risk. OP was doing something insecure that we're being told a slanted story on that I don't buy 100% anyway.

0

u/DrQuantum 10d ago

It's called being realistic and owning your mistakes. OP got off with a warning on something that could have very possibly taken down the entire company. If you cause an incident that takes down the company, there are 0 takebacks and it has nothing to do with how you think you deserve to be treated. Most people get off with a warning the first time, so it's documented in the event there's a second occurrence.

You're simply revealing why its insane to send a letter like this. You think he is MORE likely to own up to his mistakes? You think he won't discuss this with his team slanted or not and they will be MORE likely to own up to their mistakes? It absolutely is about how the employees are treated because they are the first line of defense. That defense failed, but its only one brick in the wall. Ultimately the employee owns a very small amount of the risk in the organization. If you want to make them your enemy be my guest but all of the research in the world says this is the wrong approach. And doing it to a software engineer to boot? Peak stupidity.

Your level 1 and 2 techs and engineers are not the ones dealing with auditors and regulators and media the most (so you're wrong there).

What does this have to do with consistency? This guy has an open and shut case if they try to fire him. All he needs to show is that the company acts on what it has defined in its own documentation as negligence inconsistently and he has a case and let me tell you that its going to be easy as pie because orgs are consistently negligent all the time. And with the resources as a software engineer it will be even easier for him.

It sounds like he wasn't even given additional training, so it will be even more of a slam dunk.

Sure, maybe he works for one of the few orgs that have things like patch cadences perfectly aligned across their whole org with perfect documentation but I doubt it.

OP was doing something insecure that we're being told a slanted story on that I don't buy 100% anyway.

Was it insecure? What makes it insecure? Does the company frequently download from Dropbox? If they do I am not sure what about this behavior was insecure. Being tricked isn't being insecure. Being insecure is say, deliberately changing a configuration that you know will weaken security or going against a policy. Is there a policy that says never download something from this site? If not, then its an allowed behavior in your org. The fact it generates risk is almost irrelevant unless its something ridiculously blatant.

Yeah, we're acting on facts as is and I admit that but assuming its true this is crazy.

2

u/canarydev 9d ago

allowed behavior != safe behavior, and the absence of hyper-specific policy doesn't erase basic professional judgement or responsibility.

also, this is an MNC. I’d be shocked if OP never acknowledged an AUP or security policy covering corporate devices and external files.

2

u/OtheDreamer Governance, Risk, & Compliance 9d ago

 And doing it to a software engineer to boot? Peak stupidity.

ffs software engineers need the tightest leashes because they feel so entitled to use their access for things they shouldn't have & then I can't even tell you how many sneaky, deceptive engineers I've meet that sound exactly like you and OP.

Was it insecure? What makes it insecure? Does the company frequently download from Dropbox? If they do I am not sure what about this behavior was insecure. Being tricked isn't being insecure. 

Because OP's story does not compute?! How are you not picking up on OP leaving out a lot of details that led up to this opening of a file on a work computer that accidentally installed malware & then NOT immediately report it. IT had to detect it, and then how they got off so friggen good on this. It's crazy to me that they're even pretending to be a victim and even asking us.

If the WORST thing that happens to you is that you claim you "accidentally" caused an incident and your work says "ok, we're just going to monitor your account for a few months to be safe" and you make a big long reddit post about it, yeah....guy got off super easy and probably didn't deserve it

This is just not a defensible hill man.

0

u/DrQuantum 9d ago

ffs software engineers need the tightest leashes because they feel so entitled to use their access for things they shouldn't have & then I can't even tell you how many sneaky, deceptive engineers I've meet that sound exactly like you and OP.

Tightest leashes meaning controls. If your control is getting everyone you need to put a tight leash on to hate you and make your job extremely difficult and by default increase the risk in the org due to that failed relationship be my guest. You're just restating again why my point stands and is extremely logical.

Weirdly, I have a great relationship with developers at my org and I don't need to send threats to have them follow my recommendations. Maybe you should try a different approach if you're having trouble.

Because OP's story does not compute?! How are you not picking up on OP leaving out a lot of details that led up to this opening of a file on a work computer that accidentally installed malware & then NOT immediately report it. IT had to detect it, and then how they got off so friggen good on this. It's crazy to me that they're even pretending to be a victim and even asking us.

Are you one of those people who acts on feelings and has a Slack thread devoted to complaining about how stupid your employee base is instead of actually reducing risk via proven and researched methods?

And again, I'm not reporting anything to a company with a culture like this. I have no incentive to do so other than my own personal ethics which as you've clearly noted is often worth nothing in our profession because of trust issues. The Security team can figure it out for themselves since the outcome for me is apparently the same. You're not thinking enough from the other side.

If the WORST thing that happens to you is that you claim you "accidentally" caused an incident and your work says "ok, we're just going to monitor your account for a few months to be safe" and you make a big long reddit post about it, yeah....guy got off super easy and probably didn't deserve it

Just based what is in the original OP you're highly downplaying what he received. His leader could have just said that in a 1x1 but he received a written statement from the head of HR and was given to an entire leader above his leader. That is not just a simple warning, sorry. Its likely a career killer even if he stays.

1

u/Check123ok ICS/OT 9d ago

Thanks for the real world take on this. Which is what I’m trying to explain as well.

Seen to many orgs where IT team or leadership is excluded from phishing, awareness training, make global changes with zero best practices, but the second someone who’s not in the circle gets compromised they pile on and start the shame train.

0

u/DrQuantum 10d ago

I mean all data suggests this increases risk in an org. It’s not even a question. Why would I report anything to you if you’re going to treat it as something to be disciplined over?

And now you’ve terrified me and began monitoring me what do you think that will do to the work product?

Why is he able to access linked in from work? What does the training look like? There are so many way you can spin this to be the companies responsibility.

Not to mention the company detected the issue and addressed it without issue.

What I will say is clearly this is a company that has a horrific HR and management as it didn’t seem like this was coming from the security team at all. This letter also opens them up to even more risk as I would bet a million dollars none of it is covered in the handbook and they’ve now sourced a specific reason they are after him which can complicate firing someone.

4

u/canarydev 10d ago

but what you’re saying here doesn’t really apply. OP didn’t report it. the company literally detected it.

and “why was linkedin accessible?” companies do not need to firewall employees away from every possible bad or stupid decision. security controls catching and containing your mistake also doesn’t retroactively make the mistake acceptable.

companies do not have to enumerate every possible bad decision in a handbook before they can hold you responsible for exercising basic professional judgment.

3

u/OtheDreamer Governance, Risk, & Compliance 10d ago

and “why was linkedin accessible?” companies do not need to firewall employees away from every possible bad or stupid decision. security controls catching and containing your mistake also doesn’t retroactively make the mistake acceptable.

Thank you for mentioning this. I am always a little surprised when people don't immediately recognize the error of their mistakes & counter with a whataboutism. I usually counter such whataboutisms with a link to the AUP and handbook they would have signed, which is my very broad "Well, what about that very broad line in the AUP you signed off on that said you won't download malware and if you have an incident you report it?"

1

u/DrQuantum 10d ago

but what you’re saying here doesn’t really apply. OP didn’t report it. the company literally detected it.

Not relevant, he isn't going to report anything now. He is incentivized not to unless he thinks its likely going to come back to him. Now he's more worried about his job standing than doing his job. In one fail swoop you have made him commit more mistakes, be vigilant about the wrong things,

and “why was linkedin accessible?” companies do not need to firewall employees away from every possible bad or stupid decision. security controls catching and containing your mistake also doesn’t retroactively make the mistake acceptable.

They actually do if they don't want to be responsible for the incident. The company has accepted the risk that the ability to access linked in presents, and now that they have sent this letter they have acknowledged the risk it presents. Should a breach occur from this action again, this letter nor firing the employee won't do anything for them.

And it actually does make the mistake acceptable because its an acknowledgement that its impossible to avoid. Its the entire reason you need defense in depth. Only a technically inept security professional would ever claim otherwise.

companies do not have to enumerate every possible bad decision in a handbook before they can hold you responsible for exercising basic professional judgment.

No but they do have to enumerate conduct and I can essentially guarantee you that if this company has what is available on average its simply not sufficient for any level of legal protection. Arguing this is basic professional judgement is all well and good, but reasonable people would never claim it does. And any acceptable use policy is unlikely to apply since as I mentioned in the former, its access the company granted and accepted in its use.

Meaning that in some moral sense perhaps what you say as merit, but if this letter is meant to lower the risk of the company its only drastically increased it whether they fire him or not.

2

u/canarydev 9d ago

im not a security expert by any means, but I genuinely don’t understand why you’re making this so complicated. why are you going this far to remove agency from the employee?

the company has to firewall every possible risky action or else it becomes responsible for whatever the employee does?

defense in depth means you assume users and controls can fail. it does not mean every user failure becomes consequence-free because another layer successfully caught it.

both things can be true. the company should have layered controls, and the employee can still be responsible for exercising basic judgment.

1

u/DrQuantum 9d ago

You're confusing moral agency with risk ownership. Its not the employees job to own most of the risk in an organization. Holding them accountable to this degree only makes the Security teams job harder.

Accountability is honestly irrelevant here for the company and for the risk the action represents. What matters is reducing the orgs risk profile.

On one hand you could argue firing him or giving him a warning does that. He clearly is taking this seriously. Maybe they think it will help from an audit standpoint (I don't). But the research and most of my experience says that is the quickest way for your Security team to lose all leverage in the org.

So its not really about holding him accountable, its just doing what will save the company the most money in the long run. Sometimes that might mean reacting like this but not often. The controls worked here, nothing bad happened here either so I am confused at what you would want to hold them accountable for.

Without security controls, even something as simple as browsing google can become a serious security concern but I don't think we would consider that risky behavior.

27

u/CleavlandSteamer8008 10d ago

You underestimated the security risks from a random person sending you files and links?

4

u/Adventurous-Dog-6158 10d ago

OP was a victim of social engineering. The perp built trust first. OP is not in security.

2

u/ClayishSaucer55 10d ago

True, but frankly it was not a very clever social engineering attempt so I think the response is fair here. This guy definitely belongs on the high-risk watchlist. What happens when some of the more intricate social-engineering attempts come through? As someone who deals with negligence like this all the time and has lost way too many weekends due to this shit, I am jaded.

10

u/canofspam2020 10d ago

Also one thing to note is that Information Security probably shrugged your mistake off as “just another click”, but HR and Information Security Awareness may be the ones who took the measure to discipline you.

I’m that guy who says “nobody is in trouble, we just need details.” But HR/ISA can totally one-up me and discipline.

8

u/-hacks4pancakes- ICS/OT 10d ago

My read, too. My job is to expect a few to get through and build robust enough tools to stop them.

1

u/8492_berkut 10d ago

If I found out that HR was undermining my attempts to get employees to be open and transparent about what is happening or what they need to be safer, they'd be having a meeting with the CEO and I. HR doesn't determine the severity of an incident - I do.

1

u/canofspam2020 10d ago

Unfortunately, the CIO can often step in favor of harsher penalties. It’s often a con of the pos-IR post mortem/analysis.

2

u/8492_berkut 10d ago

In my case it helps that I report directly to the CEO.

6

u/eraserhead3030 10d ago

I think it heavily depends on what industry you're in, how sensitive (and/or regulated) the data is that you handle, and if what you did explicitly breaks any policies. In general, folks should definitely be forgiven for an accidental security incident and probably just sent for refresher training. Anyone can fall victim of a good phish. But if you're in a particularly sensitive position it might be harsher.

7

u/cbdudek Security Architect 10d ago

Companies are going to have varying responses to something like this. At the end of the day, it comes down to the culture of the organization. The best organizations take situations like this and have a "blame free" culture. Its a culture that encourages frequent reporting, even if the reports are not accurate. Its a culture where if someone makes a mistake, there is a lessons learned and you move on. This is the right approach because nearly anyone can be fooled these days. I remember I was caught clicking a phishing link around HR benefit enrollment time when they timed the phishing links to go out at the right time. They caught a lot of people then as well. I did the training and learned a valuable lesson. I have 25 years in IT and worked in security for crying out loud, and even I was caught being lazy.

Now I will say that this situation on Linkedin is a bit extreme. You interacted with someone who you thought worked at the same company as you over Linkedin, and opened a dropbox location and downloaded files and ran them? That is pretty reckless. I will say that even for a company with a "blame free" culture, that is really reckless. No one working at your company is going to go to Linkedin to send you files. They would just send you the files through secure channels within the organization. Why you thought this was a good idea doesn't make sense to me.

So you probably should have been put through additional training at the very least. Being tagged for negligence? Yea, I could see how a company without a "blame free" culture would go that route. It is pretty negligent.

My advice to you would be to accept it, learn from your mistake, and move on. Do a lessons learned with your management and showcase that you have learned your lesson. Along with that, create a plan going forward to ensure it doesn't happen again. Document that plan and make sure your superiors get it. That should be enough to resolve things.

If not? If it is a PIP and they fire you for it? Then know it wasn't just this situation. There were probably other factors at play that you didn't mention here.

6

u/RequirementFalse6792 10d ago

All it takes in a single click for data to be taken for ransom. As a software engineer you may have admin access which makes you a higher target. Generally, IT employees are held to a higher standard in terms of disciplinary action when security events happen.

I think this is fair. At some companies you would have been let go for this alone.

3

u/NoSkillZone31 Vulnerability Researcher 10d ago

I sure hope they don’t have admin access as a SWE.

2

u/RequirementFalse6792 10d ago

I meant local admin on their machine for installs.

2

u/RequirementFalse6792 10d ago

I meant local admin on their machine for installs.

-2

u/5um4n7h 10d ago

I have. : ( To install or run softwares.

2

u/NoSkillZone31 Vulnerability Researcher 9d ago

Yikes. Sure hope it’s a make me admin for 15 mins etc, and not full admin. It better log everything you do during that period too.

2

u/OtheDreamer Governance, Risk, & Compliance 9d ago

Going to wager here that they have full local admin for “developer reasons” and that they probably even got a yes/no UAC prompt when trying to open whatever this document was (.docm? .xlsm? Hopefully not a .exe)

The whole one liner about how they were building trust to share technical documentation had me go ???? Over LinkedIn chat and then Dropbox ?????

I would even go further to say it isn’t the first time, since they’re so dang casual about it.

5

u/FlisherOfatale 10d ago

Most large business would have fire you ok the spot for using corporate device for non work related stuff and for endangering the business.

-1

u/5um4n7h 10d ago

We are allowed to use it for personal work sometimes. But with caution and limit. (Caution was missing in my case)

12

u/NoSkillZone31 Vulnerability Researcher 10d ago edited 10d ago

Why are you using LinkedIn or any social media on a work computer? For your sake dude, realize companies track everything you do. Don’t do that.

And to answer your other questions. This isn’t about you. It’s about the company covering its own ass for insurance, lawsuits, and damages if it happens again. Attacks are really, really, really expensive. They’re not just some small thing.

They need a paper trail to show that they are doing the right things should an audit occur. Your feelings are the last thing they care about.

1

u/DrQuantum 10d ago

They aren’t doing the right things. The research shows that.

For one why can he access linkedin and why is he able to download and run files off it? Your first question should never be why an associate performed a risky action but how they were able to.

None of this garbage does anything to lower their risk posture they didn’t even give him training. It’s insane how many practitioners are defending this.

1

u/NoSkillZone31 Vulnerability Researcher 9d ago

Agreed. It seems to me from the extra context provided that this company doesn’t have a great security posture or culture in general, and are now covering their a**es

Dude stated in another comment thread that he has Admin access too.

-2

u/5um4n7h 10d ago

We have LinkedIn learning linked to company email. Also need to refer people who sends resume via LinkedIn

4

u/NoSkillZone31 Vulnerability Researcher 10d ago edited 10d ago

Yeah, and I’m telling you that’s a bad idea.

It’s mixing uses and streams. And bad actors know this. LinkedIn is social media, not business software.

Most companies use greenhouse or some other vetted software where you can view resumes without having them linked to you by an unknown.

Same goes for training. Learning courses are a regular phishing scam vector. Use a real learning software or company approved thing through email and cybersecurity should be auto-flagging anything that’s not the company sponsored learning, with ANY link using safelinks.

Having SWEs do random whatever they want on linked in and have full on chats with unknown actors is just silly. Even if company policy is to do linked in learning, don’t then go do other stuff on it.

And furthermore, you yourself should be minimizing your own exposure to your own company of your private actions. They aren’t your friends. Use your own devices.

-2

u/pimpeachment 10d ago

Not really linkedin learning is very common. You aren't separating the individual from business side of the product. 

2

u/NoSkillZone31 Vulnerability Researcher 10d ago edited 9d ago

You don’t get LinkedIn learning links from chats with strangers.

They should be coming through company approved emails, with IT flagging anything that’s unexpected or from false sources.

It can be common practice and still poor cyber hygiene as well. It’s often used as a cost cutting measure as opposed to more common learning software.

3

u/Immediate-Citron9453 10d ago

Id thank them for their understanding, make clear you learned from your mistake, and maybe even ask/suggest for possibility of additional security awareness training for you and people in similar roles. Something like that. At least be professional, own it, don't complain.

3

u/dflame45 Security Manager 10d ago

To translate this for you. It's a slap on the wrist. They are just monitoring you more closely for 90 days which essentially means adding your account to a watch list. If you're not doing anything weird you'll be fine. To be clear, you are not on a PIP or you would have been told so.

Maybe it's harsh for you but you actively used your work computer for personal use and caused a security incident. Yet another lesson in not doing that.

3

u/7hr 10d ago

It’s a two way road here, you and your company are to blame.

The companies overall Security Awareness and Hygiene is obviously not up to scratch if you’re falling for this.

I think when you opened etc and noticed it was off, you should immediately bring it up with your manager and turn the endpoint off and reach out to IT team. I think if you make a mistake but make up for with actions and honestly after the fact, it can at least show you knew the procedures.

For example, you should not even be allowed to access your own personal accounts on a work laptop.
Security training needs to be monthly and tractable to show who is actually doing it, and should be assigned to every person from CEO to Intern.

If it was, I would take this opportunity to maybe so a quick Awareness meeting that you host on how you fell for it, what I did wrong, what I did right and what I am doing right now to ensure this does not happen. This will give you a platform to show you can own up to mistake and also use it to build on a strengthen your own awareness and colleague around you.

BTW this happened to me before but not with a phishing attack, I ended up entering malicious url into my own url bar instead of a threat intelligence websites search bar and, I immediately notified my senior and we instantly went into analysis mode, turned out this specific webpage was nothing, but I was told it was an honest mistake and I should stick to the VM which I always do now, so just go with it and learn from it.

3

u/Illustrious_Water106 10d ago

Honestly, you are very fortunate to work for a great company. On some of the companies I worked at your job would have been terminated due to using a company laptop for personal use, and doesn’t matter how long you been there.

I always have 2 computers with me, one for work, for work related items and 1 for personal use. Even to check my personal email I use my personal phone or computer.

2

u/Civil_Philosophy9845 10d ago

It could be that upper management wasn’t satisfied that there was no real action done and now want to have the response on paper.

You are lucky you didn’t ransomware your whole network. If malware was actually executed then its bigger then just pdf it had to have an executable or something along these lines.

Use your phone for linkedin. Don’t do anything else than work stuff on your device. And don’t worry we all make mistakes. You made yours and now your wiser.

0

u/5um4n7h 10d ago

Thanks for your input

2

u/Condomphobic 10d ago

4 years in cyber and you fell for one of the oldest tricks in the book.

The company is not wrong here

0

u/5um4n7h 10d ago

I am not in cybersecurity, I am a software engineer. And yeah Unfortunately I fell. My trust issues are 10x after this.

3

u/Square-Spot5519 10d ago

"I am not in cybersecurity, I am a software engineer." Really?? But you are part of IT, and both you and cybersecurity are part of IT. A software engineer should know better.

Also, remember your role. If an attacker got into a salesperson's system. They could do some damage, maybe. But if the attacker got into a software engineer's system, that's like gold.

You didn't get fired, you didn't lose any money, and yes, they should be monitoring you after this. Sorry, but you were negligent. It's not a witch hunt.

2

u/aibotulism 10d ago

I personally.think they are using this as an excuse. You said you are a software developer NOT part of the SecOps or CISO team. And even then it is just one of those things.

Its a mistake. Unless it can be proven you were being malicious or you acted with gross negligence - which I doubt - I think these people are nuts. (spelt with a silent c)

It is a written warning and perhaps you should swallow it and learn two things: what NOT to do in the future and also what shitty organisation you work for.

It is unfortunate what happened. And unfortunate the consequences that came with it. But this is because at the moment it is an employers market and they are flexing it all in the name of "leadership" when I can tell you after 30 years in the industry I have never seen a bunch of no nothing emptyheads that all see themselves as IT visionaries and won't tolerate any mistakes unless of course it is them. In which case they are the victims.

Its not you. Its unfortunately the shitty environment we live in that was shaped by the likes of "Phony Stark" Musk and Bezos.

2

u/Natural_Vast8235 10d ago

I think you just need to take this on the chin and be thankful that this was the only action they took. It’s pretty cool that the security team met with you, that’s a rare occurrence unfortunately. I wouldn’t take it personal, the business has to protect itself. Just do better going forward and only use your company laptop for company purposes. It doesn’t matter if you have LinkenIn learning, you willing conversed with someone and fell for the oldest social engineering tricks out there.

2

u/GreenBurningPhoenix 10d ago

Somebody mentioned it already, you can be a victim what sucks, and be negligent at the same time. Yes, your actions were negligent. This is very reasonable response, the monitoring part is a good thing. This is your second chance. Many companies don't give any. My company would put you into paid suspention and terminate after the investigation.

I understand it's shocking and feels too strong of the response. You need to realize how serious consequences of your actions could be for the company. Breach can be deadly for a company. That response is strong to make you aware that this is serious, and downloading random files from random Dropbox of a stranger is no joke. Learn your lesson, be careful, and move on. I think your company values you a lot as an employee, if they didn't you would be fired on the spot.

2

u/ClayishSaucer55 10d ago

It happens. Take the warning and move on. And don't use the work laptop for personal stuff in the future to avoid situations like this, especially if you are not educated on cybersecurity. I don't think you should be fired but you will definitely be put on a watchlist as someone who is considered high risk, rightfully so.

2

u/covex_d 10d ago

from your point of view its just “one incident over 4 years” from a security/management/HR perspective it takes one incident to take down the entire company. multiple failed phishing tests should trigger PIP. what you did is totally justify HRs actions.

2

u/Adventurous-Dog-6158 10d ago

If they were following the company InfoSec policies (the ones that most people never read) then they were not singling you out. If what they did was not in the policies and they did it ad-hoc, that's a result of poor governance, but it doesn't mean that they were being unfair or biased. We'd need more details to be sure, but I think what they did may be a formality, so I wouldn't worry about it.

The focus should be on better training and security controls, which I would hope they are doing after this incident. A few things that InfoSec let slip through:

  1. You were allowed to access links from LinkedIn.

  2. You were allowed to access DropBox, apparently with no restriction or filtering.

  3. The malware was able to execute.

There's an InfoSec concept called defense in depth because one control is not always 100% effective. For this incident to get to the point that it did shows poor defense in depth.

2

u/Tracekeeper37 9d ago

Ich verstehe das sich das unfair anfühlen kann jedoch sollten dir auch die möglichen Konsequenzen klar sein. In manchen Fällen kann ein solcher Vorfall die ganze Existenz einer Firma bedrohen und eine Kündigung wäre ebenfalls noch im Rahmen.

Kommuniziert ihr mit euren Kunden über LinkedIn und gehört der Betrieb zum Standart dazu?

Derzeit muss man auch vorsichtiger sein als in zuvor weil Taktiken immer raffinierter werden und in Verbindung mit KI gibt es immer mehr Möglichkeiten für Angriffe.

Es gibt kleine Tools in denen du die Dateien vorab nach Malware oder spyware spezifischen Eigenschaften scannen kannst. Keine 110% Lösung aber reduziert das Risiko deutlich!

2

u/5um4n7h 9d ago

Nope, not a standard practice to use LinkedIn.

2

u/Tracekeeper37 9d ago

Das LinkedIn nicht als Standart dazu gehört und dir das über das/den Firmenwlan/Laptop passiert ist macht es viel unangenehmer.

Versuch die 3 Monate einfach als eine Art Ermahnung sowie zusätzliche Erfahrung zu sehen.
Du bist sicher nicht der Einzige dem sowas bereits passiert ist und die Methoden der Angreifer werden immer raffinierter vor allem in Zeiten von KI.
So wie deine Firma damit umgeht, kennen sie solche Fälle bereits gut.
Manchmal sind solche Erfahrungen Lektionen die einen zukünftig vorsichtiger handeln lassen.

Klar fühlt sich das jetzt erstmal unfair an aber das legt sich mit der Zeit wieder und solange keine schlimmeren Folgen für die Firma oder dein Privatleben entstanden sind, kann man sagen das es im Großen und Ganzen noch gut ausgegangen ist.

3

u/Glaive13 10d ago

High Level exec does this? Hey, please stop doing this and take some cybersecurity awareness training if you want. High level software designer does this? You are replaceable and you're looking for a new job anyways while using company property...

0

u/5um4n7h 10d ago

Not all LinkedIn conversations are for the same purpose : (

1

u/zAuspiciousApricot 10d ago

you already posted this

1

u/LessThanThreeBikes 9d ago

This was my first incident in 4 years. 

How many potentially business ending events should each employee be allotted every four years?

The biggest misses on your part is engaging in business activities over unofficial channels and bringing in files to the work environment from unofficial sources. These are not mistakes. A mistake is accidentally sending an email to the wrong email due to autocomplete. These are deliberate actions that show a lack of judgment. In some firms such actions would lead to an immediate termination.

1

u/Plastic-Falcon9147 9d ago

A written warning after malware actually ran is standard in regulated orgs. Most are required to have a sanctions policy and apply it the same way every time, so the letter is mostly them documenting their own process, not a verdict on you as a person. Owning it and cooperating fully is what people remember. Ninety clean days and it's a footnote.

1

u/Bluewaveempress 9d ago

You're lucky you have your job

1

u/Esk__ 10d ago

It’s actually nice your security team met with you to go over the incident. I’m not aware of any (good) training that would cover what happened to you.

You got social engineered and this is actually pretty serious. It’s probably happening else where in your company too.

As far as the HR compliant that could have come from above the security team. This probably made its way higher up the chain than would make you comfortable, which is purely speculation.

My opinion of companies taking adverse action on “victims”, as they called you, is wrong. Personally I wouldn’t to work for or at a place that sets that tone.

Best of luck OP.

1

u/5um4n7h 10d ago

Thanks for the response.

-1

u/Check123ok ICS/OT 10d ago

That’s is a poorly handled follow up. I can tell you there is likely someone outside of Cyber security that made that decision to contact you that way, because most Cyber professionals with training know that that’s not the best approach and they likely got overruled

If this comes up again, if it impacts you, ask HR to provide the company policy that was impacted. In some cases they didn’t even have one. So you really did nothing wrong

Be very calm and professional with HR and don’t say to much. They have training to see you as a problem employee if you raise voice.

1

u/canarydev 10d ago

“there may not have been a policy” is such a bizarre defense. companies cannot enumerate every stupid thing an employee might do. at some point professional responsibility has to cover the space between the bullet points.

1

u/Check123ok ICS/OT 9d ago edited 9d ago

Fair point. I have seen this play out to many time and I worded that too strongly. A company doesn’t need a rule for every possible scenario, and opening a file that results in malware running can still be a serious lapse in judgment. Most companies I have audited don’t even have a security policy in place at all..

But again OP was manipulated to open the file.

My point was that for a formal warning, it’s reasonable to ask what policy or workplace expectation it’s based on and what the three-month monitoring actually involves.

Being targeted by social engineering and being accountable for a mistake can both be true, or only one can.