Exactly Why Is Replying to Phishing Attacks A Really Bad Idea?

Stu Sjouwerman | Nov 7, 2019

phishing-mcsharkPhishLabs warns that replying to a phishing email, even if you know it’s a scam, can lead to further attacks. Most phishing campaigns are automated and replying to them puts you on a scammer’s radar. PhishLabs stresses that these people are criminals, and that they can be vindictive or even dangerous. There are several operational security-related reasons why replying to these emails is a bad idea.

First, replying to a phishing email provides the scammer with a copy of your company’s email signature, which might include phone numbers and other information. This signature could enable them to craft more convincing spearphishing templates, as well as giving them more potential targets.

Second, replying to an email notifies the scammer that your email address is active. This makes you a high priority for additional attacks. Scammers can also sell your email to other attackers.

Finally, your email headers can provide the attackers with your location data, which can help them figure out your physical location.

The best course of action is to report these emails to your IT department, or simply delete them. There are many amusing stories about people wasting scammers’ time, but unless you know what you’re doing and you have precautions in place, you could be putting yourself or your organization in danger. We appreciate the amusing stories, but better to be safe than funny. New-school security awareness training can teach your employees how to identify and deal with phishing attacks. PhishLabs has the story: https://info.phishlabs.com/blog/dont-respond-suspicious-emails

Topics: Phishing

Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-reply-test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.