Unfortunate Learning Lessons from Clicking on a Suspicious Phishing Email

Stu Sjouwerman | Nov 5, 2020

Phishing Link Learning LessonsIsraeli news source YNet released a story about a woman who clicked on a suspicious phishing link, was fired from her job, and was accused of fraud with a criminal indictment.

Below is the example of the email the woman received: 

Screen Shot 2020-11-05 at 10.31.54 AM

From the email address to the body text, the email was already looking suspicious. While anyone could fall for a malicious attack, this woman made the unfortunate mistake of clicking on the link. She was then fired from her company right after the incident and was arrested by The Israel Police and the State Attorney's Office. Fortunately, thanks to a judge the outcome would not be negative, but the situation itself could have easily been avoided. 

When asked how often is it that an employee who clicked on a phishing link was fired and charged, Ido Naor, a cyber expert and CEO of Security Joes, explains: "Very rare. I was very surprised by the arrogance of the company, to blame an employee for a cyber operation. The responsibility falls on the company and the computer people in the company. If they had run two-stage authentication it would not have happened. And the activity of the burglars. "

With that said, it's important to have the following takeaways when you receive a suspicious email

  • Double Check the Sender: It's important to make sure any email you receive is from a reliable source or a someone that you know. 
  • Don't Click on any Unknown Attachments: Be mindful of any attachments that are sent to you, especially if the attachment is from someone you do not know. 
  • Utilize Multi-Factor Authentication (MFA): It's not the only measure you should take and you could still potentially get hacked with MFA. However, implementing MFA and a password management system can make it more difficult for the bad guys to infiltrate your network. 

Frequent phishing security tests could have this situation from occurring. That's why new-school security awareness training can ensure your users are always prepared with the tools needed to report any suspicious activity to your security team. 

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.