A fun skit on how to S.T.O.P. phishing!
Phishing Theatre
“IT just said my account was compromised and I’m having to
change my password AGAIN. All I did was log into Microsoft’s site to try and
view a file someone sent me! It was all legit! I looked at the grammar and
everything and it looked fine! Nobody asking for gift cards, no overseas prince
promising me money, it was just a normal login page!”
Has this ever happened to you? Don’t worry, you’re not
alone. According to a statistic that I totally just Google’d and let AI
summarize for me, 3.4 BILLION phishing emails are sent every day. Compromises
happen, so don’t beat yourself up over it.
Now, I’m not going to sugarcoat it, it’s a big deal when it
happens, and fortunately, you’ve got a super awesome IT team to help you get it
sorted out when it does, but… wouldn’t it be nice not to have your password
reset all the time or have annoying rules created that send all your emails to
the trash (heh, well, this one is kind of nice sometimes, but for work
purposes, no it’s not good).
Introducing S.T.O.P.! That’s right, the brand new, totally
original and not AI assisted acronym that all of IT is raving about!
What is S.T.O.P.? Hopefully not AI SLOP am I right?? Think
again!
S. – Sender
T. – Tone
O. – Objective
P. – Pause
Ok cool. So..?
Think of S.T.O.P. when you’re checking your emails, who is
the S.ender? What is the T.one of the email? What is its O.bjective? And, I
really should P.ause before I click anything!
Alright, let’s do a 5-minute breakdown or it’s free. (don’t
worry, you’re not actually being charged for this) Here we go!
Sender:
That’s S.! Next page!
Tone:
Nothing looks urgent, seems like it’s just telling me I’m
invited to something.. not that it’s going to shut my account off or anything
like that. It’s definitely not asking me to send any gift cards, nor requiring
my credit card.. yet.
That’s T.! Keep up the pace!
Objective:
Looks like it’s pretty cut and dry, it’s a self service
portal invitation, and I’m invited (..yay). Should be good to click right?
Right….?
NO!!! We’re
only at S.T.O. … what about the P.??
Pause:
Who is this Gabe guy anyway? Why is he sending me a link to
click?? Oh wait..
(10 minutes earlier) “Hey Gabe, can you invite me to the
help desk portal, I need to work on an article about phishing and upload it.”
Ok sure.. but where is the link actually taking me? Let me
HOVER over “ACCEPT THE INVITIATION” (NOT CLICK!!) and see if it shows me at the
bottom.
Hmm.. this is definitely our help desk portal’s web
address.. I’m about 95% sure that this is legitimate now.
Given all the context of this email, I would personally
proceed to click this, but because I want to be absolutely sure, ... and
because I want to bug Gabe a bit, I’m going to send a help desk ticket:
(I’m not actually sending it, but you get the idea)
(don’t hate me Gabe)
Let’s summarize for just a moment. Context is super
important! I expected an email from Gabe because I asked him to send me
something, so no mystery on why I’m getting it. I checked his sender’s name and
address, and that looked good. I checked the contents of the email, everything
looked fine, nothing urgent and nothing poorly worded. I hovered over the link
and checked its address, which looked legitimate.
Now, what if only ONE of the following were true, what would
I do differently?
1. I didn’t expect an email like this from Gabe.
2. His sender’s address looked weird!
3. The contents were urgent, threatening me with
losing my account!
4. Hovering over the link shows a strange address!
---
1. Call Gabe! “Hey, did you send this??” No? Mark
as phishing!
2. Sender’s address is off? Gabe didn’t send it! Mark
as phishing!
3. Urgent content? Check with Gabe! “Is this meant
to be urgent?” “I didn’t send you anything” Mark as phishing!
4. I don’t recognize that link address, check with
Gabe before clicking! “I didn’t send you a link..” Mark as phishing!
And that’s it! Oh wow, would you look at the time! Hopefully
you made it through to the end and maybe learned a thing or two along the way.
Remember, whenever you read an email, S.T.O.P.!
(this message brought to you by the
blood, sweat, and tears of the DACC IT department)