We all like to think we are smart, independent, in full control of our lives, and there is no way any of us would fall for a financial scam, like those lonely old seniors do, because “that happens to them, not to me, because I am smart.”

But the truth is, even smart people fall for it, people with master degrees, people who work in academia, people running large business… Even I could fall for this.

And how did you learn to recognize it?

  • BorgDrone@feddit.nl
    link
    fedilink
    arrow-up
    6
    ·
    21 hours ago

    My company does random phishing trials to keep people alert. They collect statistics on how many people click the link and how many report it as a scam.

    Fortunately the test mails they send out include a specific header indicating it’s a phishing test, so I just set up a rule in my mail app to automatically move those to a specific mailbox and alert me they’re running another test.

    • Eq0@literature.cafe
      link
      fedilink
      arrow-up
      2
      ·
      17 hours ago

      Your rule does kind of defeat the purpose. The goal is to see if you can detect phishing attempts “in the wild”. We all want to claim we never fail at detecting stuff, but we do, so training against it is good practice, even if annoying

    • folekaule@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      20 hours ago

      We had this, and I created the same rule, but they have since switched to AI generated phishing emails that use information about you (your manager etc) to make a fairly convincing email. If someone gets a lot of email from outside sources, I can totally see them clicking on a link if they’re in a hurry.

      The main things that raise my suspicion are:

      • telling me it’s urgent
      • telling me there will be dire consequences if I fail to comply
      • asking me to log in (with a direct link)
      • it’s from an external source
      • it’s not related to my job (eg, asking me to sign off on a PO)
      • telling me to download a file
      • including an attachment

      I usually just err on the side of reporting it. I’ve only had one false positive so far.

      • BorgDrone@feddit.nl
        link
        fedilink
        arrow-up
        1
        ·
        18 hours ago

        Then there’s also legitimate mail that contain all those red flags.

        The same people that made us go through anti-phishimg training sent me an e-mail that read exactly like a phishing attempt net even a week later, which turned out to be totally legit. Like, WTF.

        • folekaule@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          18 hours ago

          Yep lol. They have a second system that rewrites all links in emails to go through a scanner, but as a side effect that obfuscates them as well.

          • Eq0@literature.cafe
            link
            fedilink
            arrow-up
            1
            ·
            17 hours ago

            I got some of those! If ai hadn’t personally known the sender, I would have reported them…