6 ms·
Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in
by kaesar14 4y ago
Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.
- metadat 4y agoNot everyone is paranoid and jaded. It's pointless to judge the stupid ones. Bottom line is Uber got pwned, and the dirty laundry is now out in the open for all to see and inspect. Tomorrow it'll be for sale on the darkweb.
- kaesar14 4y agoIf the theory posted elsewhere in this thread is true there was definitely gross negligence elsewhere in the security chain so it’s not the fault of that one person for sure.
- kirbys-memeteam 4y ago“Paranoid and jaded” is reading as “not stupid” to me here.
- Undertow_ 4y agoeveryone is susceptible to it,,, everyone
- spoils19 4y agoWe don't run internal honeypots and no one has ever been caught in our company, so I disagree. And yes, a reply may be "That you know of...", but considering that we run weekly audits and nothing has leaked, I can be 100% sure of it.
- cyral 4y agoDo you really know for sure though? That is what keeps me up at night. The irony is that one of the leaked screenshots is of an internal security auditing/monitoring tool.
- vimda 4y ago> How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? This is bottom of the barrel phishing. Attacks against big companies get _far_ more sophisticated. Things like complete mocks of internal login sites, realistic internal emails. There's big money in hacking big companies, and plenty of shady characters willing to invest in a potential payoff
- helpfulclippy 4y agoFirst, people have fundamental drives that can override logical reason. Gift cards probably aren't your button. Maybe your buttons aren't even ones that are easily poked at by e-mail, I dunno. But EVERYONE has buttons somewhere that make them exploitable, and a lot of them ARE e-mail accessible... maybe as easy as offering free money, which is a pretty common one, and it's why marketers have been obsessed with it for ages. Another factor is that a lot of people have jobs where they're really busy and deal with a lot of e-mail from people with all kinds of bizarre communication styles. Catch one of them with the right e-mail on the right day, and you'll get a careless click. Black hats get to try every day across lots of people, and they only need it to work one time against one person to score.
- heavenlyblue 4y ago> careless click Careless click is not enough to compromise someone unless they are also running software that is not up to date. For example, how do you compromise someone if password login is disabled in all of the systems?
- cyral 4y agoProbably because it was more sophisticated than a gift card.. There are some screenshots on Twitter from the hackers with all kinds of internal uber tools and admin panels, many on non-uber domains (like uber.<third-party>.com). With all the internal email lists that employees are on for different departments in these large companies, it's not unimaginable that they click a link that appears to be some malicious site in disguise of an uber property, and enter their credentials.
- yeuxardents 4y agoThis is one of my biggest fears about companies constantly outsourcing easily deployed internal apps as SaaS and just using mycompany.saasprovider.com Normal users stand no chance, especially when there are URLs that are sketchy because oops, saasprovider already has a customer with your requested url, so you end up with mycompany0.saasprovider.com or mycompany-1.saasprovider.com Its terrible practice all around and lazy systems and services administration
- Thorrez 4y agoEven without SaaS I get weird URLs on login pages. The login page for my personal Chase account is https://secure07a.chase.com/web/auth/#/logon/logon/chaseOnline?treatment=chase&lang=en At least the etld+1 makes sense, but most people aren't going to recognize that generally the etld+1 is what you need to verify and you can ignore the rest.
- czinck 4y agohttps://arstechnica.com/information-technology/2022/08/im-a-security-reporter-and-got-fooled-by-a-blatant-phish/ https://arstechnica.com/information-technology/2022/08/im-a-... has a good example of how sophisticated phishing attempts can be. Even for less sophisticated messages, they can cast a really wide net and just need to find someone on a busy day with an urgent request from "their boss".
- icare_1er 4y agoIt can be much more subtle than that and I have seen people like you fall for it (or for other social-engineerings attacks) more than once...
- wglb 4y agoThere is nobody that it totally immune to phishing. No one.