Email: “Hi, this is IT. It looks like your password is expired. Please change your password by clicking this link. Ignore the weird from address and the fact that the link obviously goes to a noncompany website. We’re really from your IT department. Promise!”
Way too many users: “Yup. This looks legit. Better coick that link and enter all of my information right now!”
“Hi Karen , this is HR. You can now log anonymous complaints about IT, by logging into this external website with your company credentials. We provide this for your security because IT is able to monitor in network communication.”
You guys are killing me! I know so many people who get their Facebook profiles hacked like this. It just cracks me up because it seems silly to fall for. It always looks wrong and the address is ridiculous.
on some level, scammers are deliberating targeting the easiest marks. If you send out millions of phishing emails, your looking to catch few dozen of the least tech savvy people you can.
A lot of companies now configure their email security software to prepend a “this email came from an external source. Be careful!” notice to all emails that come from outside the company, to try and avoid issues like this.
Email: “Hi, this is IT. It looks like your password is expired. Please change your password by clicking this link. Ignore the weird from address and the fact that the link obviously goes to a noncompany website. We’re really from your IT department. Promise!”
Way too many users: “Yup. This looks legit. Better coick that link and enter all of my information right now!”
“Hi Karen , this is HR. You can now log anonymous complaints about IT, by logging into this external website with your company credentials. We provide this for your security because IT is able to monitor in network communication.”
You guys are killing me! I know so many people who get their Facebook profiles hacked like this. It just cracks me up because it seems silly to fall for. It always looks wrong and the address is ridiculous.
on some level, scammers are deliberating targeting the easiest marks. If you send out millions of phishing emails, your looking to catch few dozen of the least tech savvy people you can.
There are such third party services for company to receive anonymous ethics complains, or to poll employees pseudo-anonymously.
If done well it’s not using the company credentials.
Legitimate? Anything like that is at least one of two kinds of painfully obvious trap, namely:
A lot of companies now configure their email security software to prepend a “this email came from an external source. Be careful!” notice to all emails that come from outside the company, to try and avoid issues like this.