you are viewing a single comment's thread
view the rest of the comments
[–] 183 points 10 months ago (8 children)

A previous (huge) company of mine sent out a lot of phishing test emails, some of which were pretty convincing.

As developers, we quickly discovered that all the emails had a metadata header in them which identified them as a phishing test, so we set up a filter for it so every email since is clearly coded with a bright red "Phishing test!" label.

  • source
  • hideshow 16 child comments
  • [–] 78 points 10 months ago (2 children)

    ... You must be one of my co-workers. Except that we just delete ours rather than labeling them.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 86 points 10 months ago* (1 child)

    We needed to label them because the requirement was not only that we don't click them, but that we use the "report phishing" function on them.

    Also some of them were pretty funny.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 10 months ago (2 children)

    Was it hoxhunt? It's a bit spammy but they seem to push for a more gamefied approach over collective punishment.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 19 points 10 months ago

    Not in my case, no. The content was completely custom to the organisation. I assume they were big enough that they felt like a lot of the risk would come from coordinated spearphishing carefully crafted to look like genuine corp email.

  • source
  • parent
  • [–] 16 points 10 months ago

    Here they started doing such phishing tests a while ago and our IT department had significantly worse stats than other departments, in terms of how often we would click on the link in the phishing mail.

    And yeah, the conclusion was that we were just being asshats that decided to poke around in the obvious phishing mails for the fun of it. Rather than getting extra security training, management told us to just stop dicking around, so that our stats look better.

  • source
  • parent
  • [–] 2 points 10 months ago (1 child)

    Did it also label real phishing mails?

    Because those tests are send out for a reason. And in my experience, developers are some of the worst at cybersecurity.

  • source
  • parent
  • hideshow 2 child comments