Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Monday, 14 June 2010

Social hacks and Fire Drills: I told you so edition

Last year, I suggested that it would be an awfully good idea for the University, and other folks, to run phishing drills. Send out an email to staff typical of a social hack phishing expedition looking for user name and password details, see who replies, commence the beatings, then repeat until nobody needs beatings anymore.

Shame nobody listens. In today's inbox:
Dear All,

Last night an external agency used a staff member’s username and password to set up a large spam broadcast using our Exchange email servers which has resulted in a backlog of messages on our email gateway.

The spamming process has now been disabled but it will take some time before our queues return to a normal state (by 3.00pm). Meanwhile, you may experience delays in delivery and receipt of external emails; this includes messages sent to and from UC student accounts. Moreover, it is possible that some of our emails will be rejected as our email exchange has been blacklisted.

Please note that this incident occurred because a staff member responded to an email asking for their username and password. The email looked as though it came from an official or trustworthy source such as ICT Services. Be assured that ICT Services would never request a username and password by email; nor do any other trustworthy source such as banks.

Although no emails have been lost; I would wish to apologise for any inconvenience that this spam attack has caused.
We run fire drills every semester. Why oh why aren't we running phishing drills?

Tuesday, 6 October 2009

Social hacks and fire drills

Bruce Schneier often points out that the biggest gap in any company's security is the employees themselves, who'll often give away the farm to phishers who email seeking company passwords.

We have fire drills here at Canterbury once per semester to make sure that folks know what to do when the buzzers ring. Very annoying, and it's pretty unclear to me that they do much to improve preparedness (what's so hard about walking down the stairs anyway?)

But it makes me wonder whether company IT departments, including our University's, oughtn't run phishing drills. The IT department could send a phishing message (from an external server, obviously) to all staff, making sure it gets through the spam filters straight to the inbox. Standard drill phish requesting user details. Watch then to see which staff respond. Then, go and fix those staff. Do it a few times a year. It imposes zero additional cost on sensible users, who'll just delete it with the 5 other spam messages that make it through the filters each morning. But it'll help to identify the geniuses who'd give the phishers a way into our intranet.

Best I'm aware, we're not doing this. Is anybody? Why not? About twice a year we get emails from IT warning about a phishing scam that's making the rounds, so they must think, and are probably right, that some folks are ripe for pwning. Best to identify them quickly and get 'em sorted, no?