Chris Matyszczyk wrote: "Apple sends me so many invoices every week that I scarcely know what I've gone and bought. This appears to have also crossed the minds of researchers at the UK's University of Plymouth.
The wise wonderers at the university's Center for Security, Communications and Network Research thought they'd try and become phishers themselves.
So they grabbed some sample email formulations from phishing attacks of the past and sent them to specific email addresses. The results were truly painful. A fulsome 75% of the linkless messages wafted straight through to inboxes. A hearty 64% of the ones enjoying links also sailed in without so much as a passport check.
Professor Steven Furnell, the Center's leader, offered a dim view of email providers.
He said: "The poor performance of most providers implies they either do not employ filtering based on language content or that it is inadequate to protect users. Given users' tendency to perform poorly at identifying malicious messages, this is a worrying outcome."
As my colleague Danny Palmer recently reported, the most common form of phishing threat in your inbox is the personal impersonation. Of course, users should have become more adept at noticing when an email is an evil fake.
You might think, though, that tech companies would have used their sophisticated systems to learn the clumsy wordings of so many of these scammers and made sure that none of these fakes ever reaches their customers' eyes."
Stepping your users through new-school security awareness training is still a must.
ZDNet has the story: https://www.zdnet.com/article/3-out-of-4-phishing-scams-get-to-your-inbox-untouched/
Will your users respond to phishing emails?
KnowBe4's new Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!
Here's how it works:
- Immediately start your test with your choice of three phishing email reply scenarios
- Spoof a Sender’s name and email address your users know and trust
- Phishes for user replies and returns the results to you within minutes
- Get a PDF emailed to you within 24 hours with the percentage of users that replied
PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser: