My favorite is urldefense, which replaces all links passing through exchange with links that look like phishing links
People report official HRemails and emails from our cybersec department all the time. No links or attachments in them, clearly internal email because it’s missing the “external” banner, and it’s just general notifications.
Most people don’t understand what makes an email suspicious. They just report anything (or nothing) without actually thinking
Once a manager asked my, why the link in the mail from his wife doesn’t work.
the mail was in english, he and his wife are from Germany.
“Do you usually speak english with your wife” I asked suspiciously. “No…why?” he said.
you can not relay on people using common sense… you can not fly with this superman costume
IT department: ”A clear telltale sign of phishing is the sense of urgency. Official IT department email will never panic you into clicking strange links”
Also IT department: ”YOUR PASSWORD IS EXPIRING IN 24 HOURS!!! CLICK THIS STRANGE LINK NOW TO RESET YOUR PASSWORD!!!”
We simply don’t expire passwords regularly. We have Entra require a reset if it sees something suspicious. Other than that and manual “reset because suspicious”, your password can last forever.
We did 30 days, 15 days, one week, and 24 hours. And still, we’d have users get locked out for not changing their password or calling us in a panic because they only saw the 24hr notif. We switched over to only requiring changes when entra saw something fishy, which definitely lowered stress levels.
24 hours, my IT department sends them out at 28 days!
It’s so stupid, and they still write the email as if it’s happening immediately.
Exactly right. And the reasoning here is that the IT department is in no rush because they don’t care if your password expires, so what.
At some point the password will fail to work and you’ll be prompted to pick a new one. Either you’ll update it and log in, or you won’t, IT doesn’t care.
Wait, IT was supposed to care at some point?
My most relevant experience: A colleague sent me a paypal link that allows me to accept money. Nowadays, I know that it was legit. But instead of paypal.com, it was something like py.pl?code=abcdef or p.pl?code=abcdef or whatever…
Thanks, Paypal!!. Clicking the shortened hyperlink did not save me any time, but it wasted multiple minutes for me to research whether the domain was a scam or not.
Meanwhile my IT department set up protocols that are flagging emails I sent to myself as scams. Mostly photos that failed to upload to the sharepoint from my work phone that is already authenticated and verified. Nice work, guys.


