5 ms·
> Its part of our onboarding now to warn them that if they join our LinkedIn they will get multiple phishing attempts from the "founders". Hm, i wonder what th
by moepstar 4y ago
> Its part of our onboarding now to warn them that if they join our LinkedIn they will get multiple phishing attempts from the "founders".
Hm, i wonder what the point is to warn them beforehand?
- whylo 4y agoI think OP means that new hires are receiving actual spearphishing emails from attackers outside of the company, not that they're testing them by sending fake spearphising emails. (I misread it as the latter at first too)
- moepstar 4y agoHa - thanks for clarifying - now that i read it over again... you're probably right and it even makes sense to do so...
- haswell 4y agoI'm not sure if they ever did this during onboarding, but my former employer would regularly run fake spearphishing campaigns to raise awareness about spearphishing. The number of people who regularly fell for it was worrisome. Falling for it meant auto-enrollment in a mandatory security awareness training. Failing to take the training would result in deactivation of the individual's network credentials. I don't know if these campaigns are actually effective at changing people's behavior, but they certainly revealed how effective spearphishing is.
- bearjaws 4y agoThe main problem is they are real attacks that 100% happen as soon as they update their LinkedIn. They aren't tests like a Knowb4.