59
submitted 2 weeks ago by Forumite@lemm.ee to c/privacyguides@lemmy.one
all 11 comments
sorted by: hot top controversial new old
[-] AFC1886VCC@reddthat.com 39 points 2 weeks ago

At least he admitted it. That's worthy of respect I think. Just proves that nobody is invulnerable.

[-] Rooskie91@discuss.online 8 points 2 weeks ago

That's really how we should think about a lot of things. People don't fall for stuff because they're dumb. They fall for stuff because they're vulnerable.

[-] LiveLM@lemmy.zip 28 points 2 weeks ago

The biggest takeaway for me is this:

but we all have moments of weakness and if the phish times just perfectly with that, well, here we are.

We can never assume we're above it, all it takes is one not-so-good day to cause you to slip

[-] shortwavesurfer@lemmy.zip 13 points 2 weeks ago

Okay, I'm sorry, but that's just kind of ironic.

[-] MangoPenguin 12 points 2 weeks ago* (last edited 2 weeks ago)

Phishing emails are getting pretty good these days, and fairly well targeted too. I get some at work that are fairly convincing, emulating emails from services we actually use.

However...

"Hunt clicked on the phishing email, which led him to enter his credentials and one-time passcode into a hacker-controlled login page."

Using a password manager should have prevented this, or at least make it a lot more likely you would realize something is wrong, because it will only enter your credentials on the correct domain name.

I also do the whole "don't click links in emails, go to my bookmark for that service instead" thing as much as I can too. Especially for banking, I never click any link on those messages.

[-] GeekMan@sh.itjust.works 2 points 2 weeks ago

Heh yeah they're getting better.

One day working in I.T. at a bank, I received an email that was formatted and written really convincingly that someone has referred me for a bigger role with a salary bump, with light/abstract details that could 'be inferred as' relevant to my country, sector & role. It just asked to click-through to see the opportunity-

-which popped-up a warning from the company's I.T. security that this was a phishing testing/training email, and I'd failed.

I usually evade a phish, but this slightly-targeted one got me good.

After that I had to ritualistically double-check potentially legitimate emails from external domains, for sketchy domains/short URLs/links/tracking cookies etc, because they included vendors & 3rd party consultants or contractors we were working with.

At least (the) God(s) know scammers are bad people.

Heh.

[-] miss_demeanour@lemmy.dbzer0.com 6 points 2 weeks ago

Plays the 'jetlagged' card.

this post was submitted on 27 Mar 2025
59 points (100.0% liked)

Privacy Guides

18739 readers
62 users here now

In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.

This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.


You can subscribe to this community from any Kbin or Lemmy instance:

Learn more...


Check out our website at privacyguides.org before asking your questions here. We've tried answering the common questions and recommendations there!

Want to get involved? The website is open-source on GitHub, and your help would be appreciated!


This community is the "official" Privacy Guides community on Lemmy, which can be verified here. Other "Privacy Guides" communities on other Lemmy servers are not moderated by this team or associated with the website.


Moderation Rules:

  1. We prefer posting about open-source software whenever possible.
  2. This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
  3. No soliciting engagement: Don't ask for upvotes, follows, etc.
  4. Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
  5. Be civil, no violence, hate speech. Assume people here are posting in good faith.
  6. Don't repost topics which have already been covered here.
  7. News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
  8. Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
  9. No help vampires: This is not a tech support subreddit, don't abuse our community's willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
  10. No misinformation: Extraordinary claims must be matched with evidence.
  11. Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
  12. General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.

Additional Resources:

founded 2 years ago
MODERATORS