Phishing Theatre

Phishing Theatre

A fun skit on how to S.T.O.P. phishing!

Phishing Theatre

“IT just said my account was compromised and I’m having to change my password AGAIN. All I did was log into Microsoft’s site to try and view a file someone sent me! It was all legit! I looked at the grammar and everything and it looked fine! Nobody asking for gift cards, no overseas prince promising me money, it was just a normal login page!”

Has this ever happened to you? Don’t worry, you’re not alone. According to a statistic that I totally just Google’d and let AI summarize for me, 3.4 BILLION phishing emails are sent every day. Compromises happen, so don’t beat yourself up over it.

Now, I’m not going to sugarcoat it, it’s a big deal when it happens, and fortunately, you’ve got a super awesome IT team to help you get it sorted out when it does, but… wouldn’t it be nice not to have your password reset all the time or have annoying rules created that send all your emails to the trash (heh, well, this one is kind of nice sometimes, but for work purposes, no it’s not good).

Introducing S.T.O.P.! That’s right, the brand new, totally original and not AI assisted acronym that all of IT is raving about!

What is S.T.O.P.? Hopefully not AI SLOP am I right?? Think again!

S. – Sender

T. – Tone

O. – Objective

P. – Pause

Ok cool. So..?

Think of S.T.O.P. when you’re checking your emails, who is the S.ender? What is the T.one of the email? What is its O.bjective? And, I really should P.ause before I click anything!

 

Alright, let’s do a 5-minute breakdown or it’s free. (don’t worry, you’re not actually being charged for this) Here we go!

 Sender:

Looks legit, Gabe works here, and g.star@dacc.edu is his email address.

That’s S.! Next page!

 Tone:

Nothing looks urgent, seems like it’s just telling me I’m invited to something.. not that it’s going to shut my account off or anything like that. It’s definitely not asking me to send any gift cards, nor requiring my credit card.. yet.

That’s T.! Keep up the pace!

 Objective:

Looks like it’s pretty cut and dry, it’s a self service portal invitation, and I’m invited (..yay). Should be good to click right? Right….?

 

NO!!! We’re only at S.T.O. … what about the P.??

Pause:

Who is this Gabe guy anyway? Why is he sending me a link to click?? Oh wait..

(10 minutes earlier) “Hey Gabe, can you invite me to the help desk portal, I need to work on an article about phishing and upload it.”

 

Ok sure.. but where is the link actually taking me? Let me HOVER over “ACCEPT THE INVITIATION” (NOT CLICK!!) and see if it shows me at the bottom.

 

Hmm.. this is definitely our help desk portal’s web address.. I’m about 95% sure that this is legitimate now.

 

 

Given all the context of this email, I would personally proceed to click this, but because I want to be absolutely sure, ... and because I want to bug Gabe a bit, I’m going to send a help desk ticket:

(I’m not actually sending it, but you get the idea)

(don’t hate me Gabe)

 

 

Let’s summarize for just a moment. Context is super important! I expected an email from Gabe because I asked him to send me something, so no mystery on why I’m getting it. I checked his sender’s name and address, and that looked good. I checked the contents of the email, everything looked fine, nothing urgent and nothing poorly worded. I hovered over the link and checked its address, which looked legitimate.

Now, what if only ONE of the following were true, what would I do differently?

1.   I didn’t expect an email like this from Gabe.

2.   His sender’s address looked weird!

3.  The contents were urgent, threatening me with losing my account!

4.    Hovering over the link shows a strange address!

---

1.  Call Gabe! “Hey, did you send this??” No? Mark as phishing!

2.   Sender’s address is off? Gabe didn’t send it! Mark as phishing!

3.   Urgent content? Check with Gabe! “Is this meant to be urgent?” “I didn’t send you anything” Mark as phishing!

4.   I don’t recognize that link address, check with Gabe before clicking! “I didn’t send you a link..” Mark as phishing!

 

And that’s it! Oh wow, would you look at the time! Hopefully you made it through to the end and maybe learned a thing or two along the way.

Remember, whenever you read an email, S.T.O.P.!

  

 

 

 

 

 

(this message brought to you by the blood, sweat, and tears of the DACC IT department)