Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
bamhand
Apr 15, 2010
We have those emails monthly. We are also a financial institution so I think it's perfectly reasonable to expect employers not to be idiots with security.

Adbot
ADBOT LOVES YOU

Yngwie Mangosteen
Aug 23, 2007

bamhand posted:

We have those emails monthly. We are also a financial institution so I think it's perfectly reasonable to expect employers not to be idiots with security.

I work for a company that makes training for financial institution types, none of our information or knowledge is secret it's literally just repackaging law updates, statues, etc. into slightly more easily digestible forms.


I (and everyone else) receive 1-3 phishing test emails a day.

Shifty Pony
Dec 28, 2004

Up ta somethin'


The people who design the phishing tests can be real fuckers.

A former friend worked at Google was also friends with some of the penetration testing team who told him about their biggest hit: a very senior employee that had been there basically since the founding of the company and was in charge of a bunch of sensitive projects that they judged would be of interest to a state level actor.

So they used info from the guy's LinkedIn profile to see when he hit either 15 years with the company (can't remember which) and then FedExed him a large congratulations package at work (main mail drop address, "Attn: Employee Name") a few months later. One of the many professionally done items was a custom engraved crystal plaque which lit up with Google colors... for a couple minutes at which point the included power adapter died. But don't worry there was also a usb cord!

Impermanent
Apr 1, 2010
That's amazing but: is there any evidence that real phishing attempts are ever that intricate?

Professor Shark
May 22, 2012

Impermanent posted:

That's amazing but: is there any evidence that real phishing attempts are ever that intricate?

Greetings my dear,
Today our records indicated that you have won a $500 AMAZ0N giftcard! Please click here to keep your account from permanently being deleted.
Sincerely,
Tom MacDonald

Shifty Pony
Dec 28, 2004

Up ta somethin'


For a state level actor after something really critical it could be a plausible spear-phishing scenario but there's no way that it would deployed against some Google search developer.

Google employees tend to have a pretty inflated opinion about the importance and value of their ad-sales empire

Arsenic Lupin
Apr 12, 2012

This particularly rapid💨 unintelligible 😖patter💁 isn't generally heard🧏‍♂️, and if it is🤔, it doesn't matter💁.


Google did get phished by state actors in the early teens, IIRC. It was a big deal.

Poldarn
Feb 18, 2011

My org also does phishing tests, but they aren't too difficult to detect. There was a period of a few months where some of them were pretty goofy, and I think the person writing them got told to tone it down.

Here is my favourite, about a poor astronaut trapped on the ISS. Will you help get him down?

IT posted:

Dear Mr. Sir,
I am Dr. Bakare Tunde, the cousin of Nigerian Astronaut, Air Force Major Abacha Tunde. In the 14-years since
he has been on the station, he has accumulated flight pay and interest amounting to almost $ 15,000,000 USD.
If we can obtain access to this money, we can place a down payment with the Russian Space Authorities for a
Soyuz return flight to bring him back to Earth. I am told this will cost $ 3,000,000 American Dollars. In order to
access the his trust fund we need your assistance.
My colleague and I are willing to transfer you the 3,000,000 USD in order to help bring him home.
Kindly expedite action as we are behind schedule to enable us include downpayment in this financial quarter.
Please click on this link to enter your banking information.
Yours Sincerely, Dr. Bakare Tunde
Astronautics Project Manager

movax
Aug 30, 2008

Poldarn posted:

My org also does phishing tests, but they aren't too difficult to detect. There was a period of a few months where some of them were pretty goofy, and I think the person writing them got told to tone it down.

Here is my favourite, about a poor astronaut trapped on the ISS. Will you help get him down?

I’d almost want to wire a few bucks for the chuckle that brought me.

BRINGE MAJOR TUNDE HOME

Remulak
Jun 8, 2001
I can't count to four.
Yams Fan
I don’t think I’ve posted this here, but I’m I’m haunted by the call I few weeks ago:

quote:

“Hi I’m (arbitrary white girl name), you said you’d call me back, do you remember?
Just a brilliant, horrifying way to convince seniors they’re for real, as even the most-together old person is afraid they lost it.

I talked to my (old) mom about this, and she got it in the newsletter for her community, but wow such cynicism to come up with this. I just said “oh for gently caress’s sake” and hung up, but goddamn in retrospect I wish I asked if they had a conscence.

PhazonLink
Jul 17, 2010

Impermanent posted:

That's amazing but: is there any evidence that real phishing attempts are ever that intricate?

the buttcoin thread has had some dumbasses getting usb chargers that they remember ordering and then using.

peanut
Sep 9, 2007


My org also does phishing tests, but they aren't too difficult to detect. There was a period of a few months where some of them were pretty goofy, and I think the person writing them got told to tone it down.

Here is my favourite, about a poor astronaut trapped on the ISS. Will you help get him down?

IT posted:
Dear Mr. Sir,
I am Dr. Bakare Tunde, the cousin of Nigerian Astronaut, Air Force Major Abacha Tunde. In the 14-years since
he has been on the station, he has accumulated flight pay and interest amounting to almost $ 15,000,000 USD.
If we can obtain access to this money, we can place a down payment with the Russian Space Authorities for a
Soyuz return flight to bring him back to Earth. I am told this will cost $ 3,000,000 American Dollars. In order to
access the his trust fund we need your assistance.
My colleague and I are willing to transfer you the 3,000,000 USD in order to help bring him home.
Kindly expedite action as we are behind schedule to enable us include downpayment in this financial quarter.
Please click on this link to enter your banking information.
Yours Sincerely, Dr. Bakare Tunde
Astronautics Project Manager


perfection

Comstar
Apr 20, 2007

Are you happy now?
An old job at $megacorp had a report phishing button. It would auto remove the email from your mailbox and send it to cybersecurity.

If it was fake (or I presume, a test), no reply.

A week later I would sometimes get an email back saying the email was legitimate. With no way to get the original email back, read or reply to it.


Which was a great way for my boss or HR to then ask me why I hadn't done whatever the email was about.

Cast_No_Shadow
Jun 8, 2010

The Republic of Luna Equestria is a huge, socially progressive nation, notable for its punitive income tax rates. Its compassionate, cynical population of 714m are ruled with an iron fist by the dictatorship government, which ensures that no-one outside the party gets too rich.

Perfectly formatted, apparently from the correct domain email that talks about relevant activities in a timely manner and makes a reasonable request. IT phising test.



Dear <misspelled surname>

You must resolve this issue with your payments celery. If you do not you might not get enough money in your next payments.

Payments.ru/banking/safe

Please be kind enough to click this link and fill in your personal details so we can resolve.

If you do not your manger will be informationed.

Best God bless
Sarah


Legitimate email from hr that requires immediate attention

Professor Shark
May 22, 2012

URL isn’t working for me

Discendo Vox
Mar 21, 2013

We don't need to have that dialogue because it's obvious, trivial, and has already been had a thousand times.
Actual cyber and phishing that we’ve seen has included spoofing our own emails down to formatting and sender. We’ve also had a company who gets compromised have their email server immediately used to phish all their contacts using manually prepped messages continuing recent email conversations.

The threat is real, is what I’m saying.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shifty Pony posted:

The people who design the phishing tests can be real fuckers.

A former friend worked at Google was also friends with some of the penetration testing team who told him about their biggest hit: a very senior employee that had been there basically since the founding of the company and was in charge of a bunch of sensitive projects that they judged would be of interest to a state level actor.

So they used info from the guy's LinkedIn profile to see when he hit either 15 years with the company (can't remember which) and then FedExed him a large congratulations package at work (main mail drop address, "Attn: Employee Name") a few months later. One of the many professionally done items was a custom engraved crystal plaque which lit up with Google colors... for a couple minutes at which point the included power adapter died. But don't worry there was also a usb cord!

The Google security team has a tradition of attempting to (with consent) steal the password of coworkers who are leaving the security team.

The attacks are frequently semi elaborate, but also good practice as it allows them to think creatively to find possibly existing security holes through which to act. My favorite part is that TEMPEST attacks are banned for being too easy, which I feel gives an idea of the level of effort.

Impermanent posted:

That's amazing but: is there any evidence that real phishing attempts are ever that intricate?

I don't expect that these get publicized much for obvious reasons, but Google is absolutely dealing with the Mossad side of the Mickens Mossad/Not Mossad dichotomy. Snowden's leaked content shows that this is absolutely a valid level of concern.

:nsa:

BiggerBoat
Sep 26, 2007

Don't you tell me my business again.
I went to listen to a podcast on my phone this morning and got one of those McAfee "scanning device/THREAT FOUND!" popups which I've never experienced on that device before.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

BiggerBoat posted:

I went to listen to a podcast on my phone this morning and got one of those McAfee "scanning device/THREAT FOUND!" popups which I've never experienced on that device before.

Straight to factory reset, right away.

Long answer: long press the notification so you can see which app actually sent it, and then press the little options button to go to notification preferences for that app, then click the app's icon in the preferences window to go to its main preferences, and click "uninstall"

Volmarias fucked around with this message at 16:57 on Nov 18, 2023

wesleywillis
Dec 30, 2016

SUCK A MALE CAMEL'S DICK WITH MIRACLE WHIP!!

BiggerBoat posted:

I went to listen to a podcast on my phone this morning and got one of those McAfee "scanning device/THREAT FOUND!" popups which I've never experienced on that device before.

The threat was that some guys were going to show up to your house and poo poo in your mouth.

Desert Bus
May 9, 2004

Take 1 tablet by mouth daily.

BiggerBoat posted:

I went to listen to a podcast on my phone this morning and got one of those McAfee "scanning device/THREAT FOUND!" popups which I've never experienced on that device before.

I hope you took care of the threat.

Strategic Tea
Sep 1, 2012

Impermanent posted:

That's amazing but: is there any evidence that real phishing attempts are ever that intricate?

I mean given that "social engineering" is just a phrase to make the concept of spying palatable to tech brains, sure

Why this one time mossad social engineers planted palm trees above Syrian artillery positions and claimed it was for shade, little did they know it was a 'zero day kinetic red team hack' in which Israel then blew them to pieces

Strategic Tea fucked around with this message at 15:04 on Nov 19, 2023

axolotl farmer
May 17, 2007

Now I'm going to sing the Perry Mason theme

An administrator at Solna City, close to Stockholm in Sweden has over a few years transferred over 4 M SEK (~380K USD) from city funds to a scammer.

She believed all the time that she was talking to Mick Jagger from the Rolling Stones and that they would get married and be together forever :allears:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

axolotl farmer posted:

An administrator at Solna City, close to Stockholm in Sweden has over a few years transferred over 4 M SEK (~380K USD) from city funds to a scammer.

She believed all the time that she was talking to Mick Jagger from the Rolling Stones and that they would get married and be together forever :allears:

Forever for Jagger is what, another 4 years? Sheesh.

Desert Bus
May 9, 2004

Take 1 tablet by mouth daily.
A school principal tried to send 100k of the school's money to a fake Elon Musk:

"I am a very smart lady. Well-educated. I fell for a scam,” McGee said at the meeting, before claiming she had been groomed into handing over the cash."

https://fortune.com/2023/04/03/school-principal-quits-fake-elon-musk-scam-florida/

Collateral Damage
Jun 13, 2009

I keep forgetting that Jagger is still alive and making toxicologists question their research.

Fil5000
Jun 23, 2003

HOLD ON GUYS I'M POSTING ABOUT INTERNET ROBOTS

Collateral Damage posted:

I keep forgetting that Jagger is still alive and making toxicologists question their research.

Jagger nothing, Keith Richards is the one pushing up LD50s for everything he can cram in his mouth.

Collateral Damage
Jun 13, 2009

Oh right, I got them mixed up.

Wee Bairns
Feb 10, 2004

Jack Tripper's wingman.

The trapped astrounaut scam has a kinda interesting history.

Poldarn
Feb 18, 2011

Wee Bairns posted:

The trapped astrounaut scam has a kinda interesting history.

:popeye:

That's fascinating.

Weatherman
Jul 30, 2003

WARBLEKLONK

quote:

“I am a very smart lady. Well-educated. I fell for a scam,” McGee said at the meeting, before claiming she had been groomed into handing over the cash.

“Grooming is when you talk to somebody and you believe in them, and they get you to trust them that this is really real, and so I fell for it,” she said.

First off I don't think she's "very smart", and that's not what "grooming" means, so I'm doubting that she's "well-educated" too.

Got a feeling she's picked up chuds' chanting of GROOMER GROOMER GROOMER all the time and selected that word specifically to pick up some pity points.

MightyJoe36
Dec 29, 2013

:minnie: Cat Army :minnie:

Wee Bairns posted:

The trapped astrounaut scam has a kinda interesting history.

I guess if you try a scam long enough, someone is going to fall for it.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Weatherman posted:

First off I don't think she's "very smart", and that's not what "grooming" means, so I'm doubting that she's "well-educated" too.

Got a feeling she's picked up chuds' chanting of GROOMER GROOMER GROOMER all the time and selected that word specifically to pick up some pity points.

Uh

What do you think "grooming your successor" means? The usage is perfectly fine in this context, it doesn't have to be sexual in nature.

HopperUK
Apr 29, 2007

Why would an ambulance be leaving the hospital?
And she might well be very smart. Being smart is no defense against these scams.

FMguru
Sep 10, 2003

peed on;
sexually
If there is one kind of person scammers love to encounter, it's someone who believes they are too smart to fall for scams.

wesleywillis
Dec 30, 2016

SUCK A MALE CAMEL'S DICK WITH MIRACLE WHIP!!
As if goons know anything about grooming.

Yngwie Mangosteen
Aug 23, 2007

wesleywillis posted:

As if goons know anything about grooming.

Mods(?! or . Your call)

Weatherman
Jul 30, 2003

WARBLEKLONK

Volmarias posted:

Uh

What do you think "grooming your successor" means? The usage is perfectly fine in this context, it doesn't have to be sexual in nature.

Yeah, fair point. I've just (1) heard chuds complaining about supposed groomers so much recently that my brain snapped to that meaning, and (2) thought that "fooled" was a much better word for the situation. Or "suckered". I still think she was trying to evade responsibility by choosing "groomed".

Fruits of the sea
Dec 1, 2010

It’s always funny when folks fall for this sort of scam but I think a lot of the time, they are terribly lonely people who are vulnerable to the right approach at the right time. Or senile or otherwise disadvantaged to some degree.

All that said, folks who blithely click through security training and consequently fall for dumb cons out of willful ignorance need to get their poo poo sorted out :argh:

Adbot
ADBOT LOVES YOU

Agents are GO!
Dec 29, 2004

But you don't understand, it's mean to do effective anti-phishing training :qq:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply