970
The devil did this. (i.postimg.cc)
submitted 4 months ago* (last edited 1 month ago) by Irelephant@lemm.ee to c/iiiiiiitttttttttttt@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] _core@sh.itjust.works 27 points 4 months ago

I'm on our cybersecurity team and our last phishing sim was so real looking and legit sounding I thought it was real, and I knew the phish was coming. The only indicator was the sender email was a slight misspelling of Microsoft. I pointed out that that phish is not a fair phish, our users are not going to meticulously examine every email for microscopic indicators. Half if them are barely tech literate, but they're doctors or nurses and only know what they need to know to do their job. Our cybersecurity lead was completely in "wtf are you talking about? From Micrasoft.com is totally illegitimate" mode, I had to point out that our users flag 70% of the emails as phish, and phishing tests that look like completely legitimate emails aside from a single character out of place in an obscure location most of our users aren't even thinking if looking at undermine legitimate emails and increase our workload b/c we've trained our users to think every email is a phish test from cybersecuriry.

[-] jfrnz@lemm.ee 15 points 4 months ago

I don’t see the problem, is that not the point of phishing tests? Users need to ensure the sender is legitimate before taking action such as clicking links.

[-] baines@lemmy.cafe 8 points 4 months ago

good way to get me to ignore all emails

[-] LordKitsuna@lemmy.world 4 points 4 months ago

Not to mention the fact that the majority of email clients these days don't even actually show you the full URL of the mail server that the mail is coming from. It gets obfuscated away over the display name and you have to explicitly go out of your way to actually see the full URL

[-] Charzard4261@programming.dev 5 points 4 months ago

This is so crazy to me. Why the hell did they start hiding the address? The one thing that can't be faked? Couldn't believe how hard it was the first time I needed to check.

this post was submitted on 29 Mar 2025
970 points (100.0% liked)

[Moved to !iiiiiiitttttttttttt@programming.dev, check pinned post.] iiiiiiitttttttttttt.

922 readers
1 users here now

you know the computer thing is it plugged in?

Moved to !iiiiiiitttttttttttt@programming.dev.

founded 2 years ago
MODERATORS