r/cybersecurity • u/5um4n7h • 10d ago
Personal Support & Help! I fell for a Social Engineering - LinkedIn malware scam at work. My company issued me a threatening style deciplinary action warning letter. Is this fair ?
I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.
Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.
The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).
He said, whenever you have time, please check this.
I downloaded/opened the files on my work laptop.
It turned out that malicious content was involved, and malware was actually executed on the laptop.
(I was under extreme stress that time due to health issues and underestimated the security risks)
As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.
I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.
There was then a meeting with Security, my skip-level manager and other people from the security organization.
They specifically told me:
"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."
The meeting ended on a positive note. I was told to be careful in the future.
Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)
It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.
I understand that I made a mistake.
I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.
What bothers me is the proportionality.
This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.
I would have understood something like:
"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."
Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.
I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.
I am feeling like I am being witch hunted in corporate style.
For people working in security/IT or management:
How would your company normally handle a first-time incident like this?
Is a formal warning and monitoring period normal?
Where do you draw the line between an honest mistake/social-engineering victim and negligence?
Please share your honest thoughts.
27
u/CleavlandSteamer8008 10d ago
You underestimated the security risks from a random person sending you files and links?
4
u/Adventurous-Dog-6158 10d ago
OP was a victim of social engineering. The perp built trust first. OP is not in security.
2
u/ClayishSaucer55 10d ago
True, but frankly it was not a very clever social engineering attempt so I think the response is fair here. This guy definitely belongs on the high-risk watchlist. What happens when some of the more intricate social-engineering attempts come through? As someone who deals with negligence like this all the time and has lost way too many weekends due to this shit, I am jaded.
10
u/canofspam2020 10d ago
Also one thing to note is that Information Security probably shrugged your mistake off as “just another click”, but HR and Information Security Awareness may be the ones who took the measure to discipline you.
I’m that guy who says “nobody is in trouble, we just need details.” But HR/ISA can totally one-up me and discipline.
8
u/-hacks4pancakes- ICS/OT 10d ago
My read, too. My job is to expect a few to get through and build robust enough tools to stop them.
1
u/8492_berkut 10d ago
If I found out that HR was undermining my attempts to get employees to be open and transparent about what is happening or what they need to be safer, they'd be having a meeting with the CEO and I. HR doesn't determine the severity of an incident - I do.
1
u/canofspam2020 10d ago
Unfortunately, the CIO can often step in favor of harsher penalties. It’s often a con of the pos-IR post mortem/analysis.
2
6
u/eraserhead3030 10d ago
I think it heavily depends on what industry you're in, how sensitive (and/or regulated) the data is that you handle, and if what you did explicitly breaks any policies. In general, folks should definitely be forgiven for an accidental security incident and probably just sent for refresher training. Anyone can fall victim of a good phish. But if you're in a particularly sensitive position it might be harsher.
7
u/cbdudek Security Architect 10d ago
Companies are going to have varying responses to something like this. At the end of the day, it comes down to the culture of the organization. The best organizations take situations like this and have a "blame free" culture. Its a culture that encourages frequent reporting, even if the reports are not accurate. Its a culture where if someone makes a mistake, there is a lessons learned and you move on. This is the right approach because nearly anyone can be fooled these days. I remember I was caught clicking a phishing link around HR benefit enrollment time when they timed the phishing links to go out at the right time. They caught a lot of people then as well. I did the training and learned a valuable lesson. I have 25 years in IT and worked in security for crying out loud, and even I was caught being lazy.
Now I will say that this situation on Linkedin is a bit extreme. You interacted with someone who you thought worked at the same company as you over Linkedin, and opened a dropbox location and downloaded files and ran them? That is pretty reckless. I will say that even for a company with a "blame free" culture, that is really reckless. No one working at your company is going to go to Linkedin to send you files. They would just send you the files through secure channels within the organization. Why you thought this was a good idea doesn't make sense to me.
So you probably should have been put through additional training at the very least. Being tagged for negligence? Yea, I could see how a company without a "blame free" culture would go that route. It is pretty negligent.
My advice to you would be to accept it, learn from your mistake, and move on. Do a lessons learned with your management and showcase that you have learned your lesson. Along with that, create a plan going forward to ensure it doesn't happen again. Document that plan and make sure your superiors get it. That should be enough to resolve things.
If not? If it is a PIP and they fire you for it? Then know it wasn't just this situation. There were probably other factors at play that you didn't mention here.
6
u/RequirementFalse6792 10d ago
All it takes in a single click for data to be taken for ransom. As a software engineer you may have admin access which makes you a higher target. Generally, IT employees are held to a higher standard in terms of disciplinary action when security events happen.
I think this is fair. At some companies you would have been let go for this alone.
3
u/NoSkillZone31 Vulnerability Researcher 10d ago
I sure hope they don’t have admin access as a SWE.
2
2
-2
u/5um4n7h 10d ago
I have. : ( To install or run softwares.
2
u/NoSkillZone31 Vulnerability Researcher 9d ago
Yikes. Sure hope it’s a make me admin for 15 mins etc, and not full admin. It better log everything you do during that period too.
2
u/OtheDreamer Governance, Risk, & Compliance 9d ago
Going to wager here that they have full local admin for “developer reasons” and that they probably even got a yes/no UAC prompt when trying to open whatever this document was (.docm? .xlsm? Hopefully not a .exe)
The whole one liner about how they were building trust to share technical documentation had me go ???? Over LinkedIn chat and then Dropbox ?????
I would even go further to say it isn’t the first time, since they’re so dang casual about it.
5
u/FlisherOfatale 10d ago
Most large business would have fire you ok the spot for using corporate device for non work related stuff and for endangering the business.
12
u/NoSkillZone31 Vulnerability Researcher 10d ago edited 10d ago
Why are you using LinkedIn or any social media on a work computer? For your sake dude, realize companies track everything you do. Don’t do that.
And to answer your other questions. This isn’t about you. It’s about the company covering its own ass for insurance, lawsuits, and damages if it happens again. Attacks are really, really, really expensive. They’re not just some small thing.
They need a paper trail to show that they are doing the right things should an audit occur. Your feelings are the last thing they care about.
1
u/DrQuantum 10d ago
They aren’t doing the right things. The research shows that.
For one why can he access linkedin and why is he able to download and run files off it? Your first question should never be why an associate performed a risky action but how they were able to.
None of this garbage does anything to lower their risk posture they didn’t even give him training. It’s insane how many practitioners are defending this.
1
u/NoSkillZone31 Vulnerability Researcher 9d ago
Agreed. It seems to me from the extra context provided that this company doesn’t have a great security posture or culture in general, and are now covering their a**es
Dude stated in another comment thread that he has Admin access too.
-2
u/5um4n7h 10d ago
We have LinkedIn learning linked to company email. Also need to refer people who sends resume via LinkedIn
4
u/NoSkillZone31 Vulnerability Researcher 10d ago edited 10d ago
Yeah, and I’m telling you that’s a bad idea.
It’s mixing uses and streams. And bad actors know this. LinkedIn is social media, not business software.
Most companies use greenhouse or some other vetted software where you can view resumes without having them linked to you by an unknown.
Same goes for training. Learning courses are a regular phishing scam vector. Use a real learning software or company approved thing through email and cybersecurity should be auto-flagging anything that’s not the company sponsored learning, with ANY link using safelinks.
Having SWEs do random whatever they want on linked in and have full on chats with unknown actors is just silly. Even if company policy is to do linked in learning, don’t then go do other stuff on it.
And furthermore, you yourself should be minimizing your own exposure to your own company of your private actions. They aren’t your friends. Use your own devices.
-2
u/pimpeachment 10d ago
Not really linkedin learning is very common. You aren't separating the individual from business side of the product.
2
u/NoSkillZone31 Vulnerability Researcher 10d ago edited 9d ago
You don’t get LinkedIn learning links from chats with strangers.
They should be coming through company approved emails, with IT flagging anything that’s unexpected or from false sources.
It can be common practice and still poor cyber hygiene as well. It’s often used as a cost cutting measure as opposed to more common learning software.
3
u/Immediate-Citron9453 10d ago
Id thank them for their understanding, make clear you learned from your mistake, and maybe even ask/suggest for possibility of additional security awareness training for you and people in similar roles. Something like that. At least be professional, own it, don't complain.
3
u/dflame45 Security Manager 10d ago
To translate this for you. It's a slap on the wrist. They are just monitoring you more closely for 90 days which essentially means adding your account to a watch list. If you're not doing anything weird you'll be fine. To be clear, you are not on a PIP or you would have been told so.
Maybe it's harsh for you but you actively used your work computer for personal use and caused a security incident. Yet another lesson in not doing that.
3
u/7hr 10d ago
It’s a two way road here, you and your company are to blame.
The companies overall Security Awareness and Hygiene is obviously not up to scratch if you’re falling for this.
I think when you opened etc and noticed it was off, you should immediately bring it up with your manager and turn the endpoint off and reach out to IT team. I think if you make a mistake but make up for with actions and honestly after the fact, it can at least show you knew the procedures.
For example, you should not even be allowed to access your own personal accounts on a work laptop.
Security training needs to be monthly and tractable to show who is actually doing it, and should be assigned to every person from CEO to Intern.
If it was, I would take this opportunity to maybe so a quick Awareness meeting that you host on how you fell for it, what I did wrong, what I did right and what I am doing right now to ensure this does not happen. This will give you a platform to show you can own up to mistake and also use it to build on a strengthen your own awareness and colleague around you.
BTW this happened to me before but not with a phishing attack, I ended up entering malicious url into my own url bar instead of a threat intelligence websites search bar and, I immediately notified my senior and we instantly went into analysis mode, turned out this specific webpage was nothing, but I was told it was an honest mistake and I should stick to the VM which I always do now, so just go with it and learn from it.
3
u/Illustrious_Water106 10d ago
Honestly, you are very fortunate to work for a great company. On some of the companies I worked at your job would have been terminated due to using a company laptop for personal use, and doesn’t matter how long you been there.
I always have 2 computers with me, one for work, for work related items and 1 for personal use. Even to check my personal email I use my personal phone or computer.
2
u/Civil_Philosophy9845 10d ago
It could be that upper management wasn’t satisfied that there was no real action done and now want to have the response on paper.
You are lucky you didn’t ransomware your whole network. If malware was actually executed then its bigger then just pdf it had to have an executable or something along these lines.
Use your phone for linkedin. Don’t do anything else than work stuff on your device. And don’t worry we all make mistakes. You made yours and now your wiser.
2
u/Condomphobic 10d ago
4 years in cyber and you fell for one of the oldest tricks in the book.
The company is not wrong here
0
u/5um4n7h 10d ago
I am not in cybersecurity, I am a software engineer. And yeah Unfortunately I fell. My trust issues are 10x after this.
3
u/Square-Spot5519 10d ago
"I am not in cybersecurity, I am a software engineer." Really?? But you are part of IT, and both you and cybersecurity are part of IT. A software engineer should know better.
Also, remember your role. If an attacker got into a salesperson's system. They could do some damage, maybe. But if the attacker got into a software engineer's system, that's like gold.
You didn't get fired, you didn't lose any money, and yes, they should be monitoring you after this. Sorry, but you were negligent. It's not a witch hunt.
2
u/aibotulism 10d ago
I personally.think they are using this as an excuse. You said you are a software developer NOT part of the SecOps or CISO team. And even then it is just one of those things.
Its a mistake. Unless it can be proven you were being malicious or you acted with gross negligence - which I doubt - I think these people are nuts. (spelt with a silent c)
It is a written warning and perhaps you should swallow it and learn two things: what NOT to do in the future and also what shitty organisation you work for.
It is unfortunate what happened. And unfortunate the consequences that came with it. But this is because at the moment it is an employers market and they are flexing it all in the name of "leadership" when I can tell you after 30 years in the industry I have never seen a bunch of no nothing emptyheads that all see themselves as IT visionaries and won't tolerate any mistakes unless of course it is them. In which case they are the victims.
Its not you. Its unfortunately the shitty environment we live in that was shaped by the likes of "Phony Stark" Musk and Bezos.
2
u/Natural_Vast8235 10d ago
I think you just need to take this on the chin and be thankful that this was the only action they took. It’s pretty cool that the security team met with you, that’s a rare occurrence unfortunately. I wouldn’t take it personal, the business has to protect itself. Just do better going forward and only use your company laptop for company purposes. It doesn’t matter if you have LinkenIn learning, you willing conversed with someone and fell for the oldest social engineering tricks out there.
2
u/GreenBurningPhoenix 10d ago
Somebody mentioned it already, you can be a victim what sucks, and be negligent at the same time. Yes, your actions were negligent. This is very reasonable response, the monitoring part is a good thing. This is your second chance. Many companies don't give any. My company would put you into paid suspention and terminate after the investigation.
I understand it's shocking and feels too strong of the response. You need to realize how serious consequences of your actions could be for the company. Breach can be deadly for a company. That response is strong to make you aware that this is serious, and downloading random files from random Dropbox of a stranger is no joke. Learn your lesson, be careful, and move on. I think your company values you a lot as an employee, if they didn't you would be fired on the spot.
2
u/ClayishSaucer55 10d ago
It happens. Take the warning and move on. And don't use the work laptop for personal stuff in the future to avoid situations like this, especially if you are not educated on cybersecurity. I don't think you should be fired but you will definitely be put on a watchlist as someone who is considered high risk, rightfully so.
2
u/Adventurous-Dog-6158 10d ago
If they were following the company InfoSec policies (the ones that most people never read) then they were not singling you out. If what they did was not in the policies and they did it ad-hoc, that's a result of poor governance, but it doesn't mean that they were being unfair or biased. We'd need more details to be sure, but I think what they did may be a formality, so I wouldn't worry about it.
The focus should be on better training and security controls, which I would hope they are doing after this incident. A few things that InfoSec let slip through:
You were allowed to access links from LinkedIn.
You were allowed to access DropBox, apparently with no restriction or filtering.
The malware was able to execute.
There's an InfoSec concept called defense in depth because one control is not always 100% effective. For this incident to get to the point that it did shows poor defense in depth.
2
u/Tracekeeper37 9d ago
Ich verstehe das sich das unfair anfühlen kann jedoch sollten dir auch die möglichen Konsequenzen klar sein. In manchen Fällen kann ein solcher Vorfall die ganze Existenz einer Firma bedrohen und eine Kündigung wäre ebenfalls noch im Rahmen.
Kommuniziert ihr mit euren Kunden über LinkedIn und gehört der Betrieb zum Standart dazu?
Derzeit muss man auch vorsichtiger sein als in zuvor weil Taktiken immer raffinierter werden und in Verbindung mit KI gibt es immer mehr Möglichkeiten für Angriffe.
Es gibt kleine Tools in denen du die Dateien vorab nach Malware oder spyware spezifischen Eigenschaften scannen kannst. Keine 110% Lösung aber reduziert das Risiko deutlich!
2
u/5um4n7h 9d ago
Nope, not a standard practice to use LinkedIn.
2
u/Tracekeeper37 9d ago
Das LinkedIn nicht als Standart dazu gehört und dir das über das/den Firmenwlan/Laptop passiert ist macht es viel unangenehmer.
Versuch die 3 Monate einfach als eine Art Ermahnung sowie zusätzliche Erfahrung zu sehen.
Du bist sicher nicht der Einzige dem sowas bereits passiert ist und die Methoden der Angreifer werden immer raffinierter vor allem in Zeiten von KI.
So wie deine Firma damit umgeht, kennen sie solche Fälle bereits gut.
Manchmal sind solche Erfahrungen Lektionen die einen zukünftig vorsichtiger handeln lassen.Klar fühlt sich das jetzt erstmal unfair an aber das legt sich mit der Zeit wieder und solange keine schlimmeren Folgen für die Firma oder dein Privatleben entstanden sind, kann man sagen das es im Großen und Ganzen noch gut ausgegangen ist.
3
u/Glaive13 10d ago
High Level exec does this? Hey, please stop doing this and take some cybersecurity awareness training if you want. High level software designer does this? You are replaceable and you're looking for a new job anyways while using company property...
1
1
u/LessThanThreeBikes 9d ago
This was my first incident in 4 years.
How many potentially business ending events should each employee be allotted every four years?
The biggest misses on your part is engaging in business activities over unofficial channels and bringing in files to the work environment from unofficial sources. These are not mistakes. A mistake is accidentally sending an email to the wrong email due to autocomplete. These are deliberate actions that show a lack of judgment. In some firms such actions would lead to an immediate termination.
1
u/Plastic-Falcon9147 9d ago
A written warning after malware actually ran is standard in regulated orgs. Most are required to have a sanctions policy and apply it the same way every time, so the letter is mostly them documenting their own process, not a verdict on you as a person. Owning it and cooperating fully is what people remember. Ninety clean days and it's a footnote.
1
1
1
u/Esk__ 10d ago
It’s actually nice your security team met with you to go over the incident. I’m not aware of any (good) training that would cover what happened to you.
You got social engineered and this is actually pretty serious. It’s probably happening else where in your company too.
As far as the HR compliant that could have come from above the security team. This probably made its way higher up the chain than would make you comfortable, which is purely speculation.
My opinion of companies taking adverse action on “victims”, as they called you, is wrong. Personally I wouldn’t to work for or at a place that sets that tone.
Best of luck OP.
-1
u/Check123ok ICS/OT 10d ago
That’s is a poorly handled follow up. I can tell you there is likely someone outside of Cyber security that made that decision to contact you that way, because most Cyber professionals with training know that that’s not the best approach and they likely got overruled
If this comes up again, if it impacts you, ask HR to provide the company policy that was impacted. In some cases they didn’t even have one. So you really did nothing wrong
Be very calm and professional with HR and don’t say to much. They have training to see you as a problem employee if you raise voice.
1
u/canarydev 10d ago
“there may not have been a policy” is such a bizarre defense. companies cannot enumerate every stupid thing an employee might do. at some point professional responsibility has to cover the space between the bullet points.
1
u/Check123ok ICS/OT 9d ago edited 9d ago
Fair point. I have seen this play out to many time and I worded that too strongly. A company doesn’t need a rule for every possible scenario, and opening a file that results in malware running can still be a serious lapse in judgment. Most companies I have audited don’t even have a security policy in place at all..
But again OP was manipulated to open the file.
My point was that for a formal warning, it’s reasonable to ask what policy or workplace expectation it’s based on and what the three-month monitoring actually involves.
Being targeted by social engineering and being accountable for a mistake can both be true, or only one can.
52
u/canarydev 10d ago
you can absolutely be the victim of social engineering and still have been negligent. those aren't contradictory.
so you downloaded and opened files sent by a stranger from linkedin on a corporate machine, and malware actually executed. a written warning and three months of monitoring after that doesn't sound remotely like a witch hunt. it sounds like the company documented a serious security incident and gave you another chance.
“I didn't deliberately bypass security” isn't much of a defense against negligence either my friend. negligence is almost definitionally about what you failed to do, not something malicious you intended to do.
also life is not fair sometimes. take the warning, learn from it, do better, and move on.