Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Clinton Campaign Tested Staffers With Fake Phishing Emails
Newest First  |  Oldest First  |  Threaded View
ChispaTD
50%
50%
ChispaTD,
User Rank: Apprentice
2/21/2017 | 3:45:12 PM
Re: What a Surprise!
I'm not surprised. The fastest way to get someone to do something, especially an exec, is to tell the person not to do it. 
ChispaTD
50%
50%
ChispaTD,
User Rank: Apprentice
2/21/2017 | 3:29:26 PM
Re: What a Surprise!
I'd like to know that as well. How effective is it to run these tests if it's not rolled out across the entire organization?
mikeroch
50%
50%
mikeroch,
User Rank: Apprentice
2/20/2017 | 9:59:30 AM
Email phishing for 192.168 0l 1
Email phishing is hell, it should not be executed at any cost.
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
2/20/2017 | 5:30:13 AM
Re: What a Surprise!
@Terry: I'm aware of at least one situation in which fake phishing emails were sent within a major organization explicitly warning users "DO NOT CLICK ON THIS LINK" and explaining that it was an example of a phishing email.

10% of the users still clicked -- including one C-suiter.

The C-suiter's justification for clicking?  "I wanted to see what would happen."
tompendergast
100%
0%
tompendergast,
User Rank: Author
2/17/2017 | 10:48:51 AM
Re: What a Surprise!
Good article, thanks. I'm convinced that it's the combination of simulated phishing, relevant training, and persistent reinforcement that is the key to building up human capacity. It sounds like this group did it right. 
kasstri
100%
0%
kasstri,
User Rank: Strategist
2/16/2017 | 5:43:48 PM
keyboard
This is really a nice post. Thanks for sharing this us.
T Sweeney
100%
0%
T Sweeney,
User Rank: Moderator
2/16/2017 | 1:44:01 PM
Re: What a Surprise!
I understand wanting to protect the egos of execs, but at the expense of the organization's security?

Is the assumption, then, that your execs open all their email (unlikely) and click on all links (very unlikely)?

Separately, I'd love to know how common this practice is of sending fake phishing emails to test training effectiveness, and what other conditions get used in the exercise.
jries921
50%
50%
jries921,
User Rank: Ninja
2/16/2017 | 11:55:42 AM
Re: What a Surprise!
If the practice really does have management support, then senior managers won't be exempted.  If John Podesta was exempted, I'm sure he regrets it now.
ClarenceR927
50%
50%
ClarenceR927,
User Rank: Strategist
2/16/2017 | 9:35:32 AM
What a Surprise!
We test too. Naturally we are not allowed to send our test phish upstream in the coproration as it would be embarassing for the executives to get caught.  I wonder if Podesta as also skipped on the tests.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.