I cannot concur…
It’s not realistic to ask people to *never* click a link in email. We’ve got 30+ years of experience with that advice not working because MUA developers have never stopped making links active & aggressively looking for anything in email that might be a link, regardless of URL conformance. That’s why SpamAssassin treats so many non-URLs as if they are URLs. Users will click clickable things. Telling them not to do so is unreasonable.
1/2
#InfoSec @AAKL https://infosec.exchange/@AAKL/116398057284422776
AA (@[email protected])
Never, never, never, never, never click on a link in your email. Contact the provider directly and not through the suspect email. "Approval phishing is a technique whereby victims are tricked into providing full access to their cryptocurrency wallets. Often, they are persuaded to click on a fake alert or popup spoofed to appear as if sent from a trusted app or service." Infosecurity-Magazine: Operation Atlantic Seizes $12m in Crypto Losses https://www.infosecurity-magazine.com/news/operation-atlantic-seizes-12m/ #infosec #phishing