We all like to think we are smart, independent, in full control of our lives, and there is no way any of us would fall for a financial scam, like those lonely old seniors do, because “that happens to them, not to me, because I am smart.”

But the truth is, even smart people fall for it, people with master degrees, people who work in academia, people running large business… Even I could fall for this.

And how did you learn to recognize it?

  • Eq0@literature.cafe
    link
    fedilink
    arrow-up
    5
    ·
    1 day ago

    I was “scammed”: my company sent a phishing email to warn people about scams. I learned never to click links in emails unless you know the sender and that your stored passwords are inserted only when the url is 100% correct. If you don’t get the autocomplete option, the URL might be wrong and it’s a trap

    • BorgDrone@feddit.nl
      link
      fedilink
      arrow-up
      6
      ·
      1 day ago

      My company does random phishing trials to keep people alert. They collect statistics on how many people click the link and how many report it as a scam.

      Fortunately the test mails they send out include a specific header indicating it’s a phishing test, so I just set up a rule in my mail app to automatically move those to a specific mailbox and alert me they’re running another test.

      • Eq0@literature.cafe
        link
        fedilink
        arrow-up
        2
        ·
        20 hours ago

        Your rule does kind of defeat the purpose. The goal is to see if you can detect phishing attempts “in the wild”. We all want to claim we never fail at detecting stuff, but we do, so training against it is good practice, even if annoying

      • folekaule@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        23 hours ago

        We had this, and I created the same rule, but they have since switched to AI generated phishing emails that use information about you (your manager etc) to make a fairly convincing email. If someone gets a lot of email from outside sources, I can totally see them clicking on a link if they’re in a hurry.

        The main things that raise my suspicion are:

        • telling me it’s urgent
        • telling me there will be dire consequences if I fail to comply
        • asking me to log in (with a direct link)
        • it’s from an external source
        • it’s not related to my job (eg, asking me to sign off on a PO)
        • telling me to download a file
        • including an attachment

        I usually just err on the side of reporting it. I’ve only had one false positive so far.

        • BorgDrone@feddit.nl
          link
          fedilink
          arrow-up
          1
          ·
          21 hours ago

          Then there’s also legitimate mail that contain all those red flags.

          The same people that made us go through anti-phishimg training sent me an e-mail that read exactly like a phishing attempt net even a week later, which turned out to be totally legit. Like, WTF.

          • folekaule@lemmy.world
            link
            fedilink
            arrow-up
            3
            ·
            21 hours ago

            Yep lol. They have a second system that rewrites all links in emails to go through a scanner, but as a side effect that obfuscates them as well.

            • Eq0@literature.cafe
              link
              fedilink
              arrow-up
              1
              ·
              20 hours ago

              I got some of those! If ai hadn’t personally known the sender, I would have reported them…