Boss: Why haven't you done any of the work I gave you?

Me: What work?

Boss: From my emails!

Me: Oh, I deleted those.

Boss: WHAT?!

Me: I thought they were phishing attempts.

Boss: Why?

Me: The IT security training said typos and unexpected requests were clues to spot phishing.

#infosec #email #phishing

@maxleibman I want to laugh more but yea, that IS what the IT people keep telling us.
@maxleibman Hah! Literally just did my annual mandatory #itsec training at work today. Must remember this get-out-of-jail-free card for the future πŸ™‚
@maxleibman πŸ€£πŸ€£πŸ€£πŸ‘Œ
@maxleibman I learned from infosec that expense reports formatted like our company's expense reports are scams.

@maxleibman I have not done our halfyearly phishing training for 2 or 3 years because it comes from an external address and asks me to click on a link. So I report it (and the 3 or 4 reminders) as phishing and go on with my life.

My manager caught flak for this from his manager. My manager is fine with what I'm doing.

@IIVQ @maxleibman If the trainers are okay with that email then it's not worth doing the training.

@maxleibman

Edit: added alt text. Sorry for not doing it in the first place

@maxleibman unintended consequences, table turns, the true high cost of #phishing ?

@maxleibman

Besides Boss, I have been working on real problems.

@maxleibman god, my sides are orbiting Pluto
@maxleibman Don't forget the email being sent from a non-company email! πŸ˜‚πŸ˜‚πŸ˜‚
@maxleibman πŸ”₯ πŸ”₯ πŸ”₯
@maxleibman πŸ˜­πŸ˜­πŸ˜‚πŸ˜‚
@maxleibman Nice! I'm 'so going to use that.
@maxleibman Our IT security sent out an invite for courses on corporate security that were developed and hosted by Kevin Mitnick. I'm like "yeah, right, this is a crafty tiger team ploy to see if we're dumb enough to click on anything with the name of one of the most notorious hackers in history". I flagged it as phising and commented "most amusing". No. Turns out it was a real course they wanted us to take.
__________
#KevinMitnick