People are still — even after all these years — really stupendously bad at recognizing even to me very obvious and rudimentary phishing attacks. Today, I had to run around the office like a fire demon warning people not to click on on email “from” someone we do business with after their computer was hijacked and started sending out links to an offshore hijacked site with some nice malware on the other end.
Sure, yeah, we do business with this person — but were you expecting a document from this person? And one that was a nearly-blank PDF that contained a link to another site? And is claiming to be sent to you by “Adobe” in the PDF?
Sure, that sounds likely. Just go ahead and click right on that as that seems totally legit. Luckily I was paying attention to my email and not a single person got infected before I got to them. (One woman was literally starting her click on the bad link when I stopped her. Another 200 milliseconds, we would’ve been jacked.)
That was a close one. Probably saved myself and others about 20 hours of work (at least) with my fleet feet today.
