This is a scourge. And of course most employees who get a call from someone purporting to be part of the company have a reasonable fear of creating problems at work and so often seem to err on the side of giving out more information.
The sad thing is that as we open up more and more ways to "do" things remotely (like move all your checking account funds from your account) the more danger involved. In many ways this makes the whole requirement that you authorize at a specific terminal in a secure space make much more sense.
For 4 years I was the systems security officer for a college. At least 2 students per week fell for a phishing scam. It didn't matter how much we warned about it; emails, orientation lectures for firstyears, one-on-one talks, big alerts on the Blackboard system, you name it.
They'd get an email claiming to be from the help desk and BAM owned. My sensors would pick it up and cut their access off and they'd have to come to my desk for restoration. I was unfailingly polite and respectful. Didn't make anyone feel dumb, no berating, just a calm explanation of exactly what happened and how to avoid it in the future. No student ever had it happen to them a second time.
One staff member fell for phishes at least 5 times, though. The president of the college had to talk to that individual eventually.
Comments
This is a scourge. And of course most employees who get a call from someone purporting to be part of the company have a reasonable fear of creating problems at work and so often seem to err on the side of giving out more information.
The sad thing is that as we open up more and more ways to "do" things remotely (like move all your checking account funds from your account) the more danger involved. In many ways this makes the whole requirement that you authorize at a specific terminal in a secure space make much more sense.
For 4 years I was the systems security officer for a college. At least 2 students per week fell for a phishing scam. It didn't matter how much we warned about it; emails, orientation lectures for firstyears, one-on-one talks, big alerts on the Blackboard system, you name it.
They'd get an email claiming to be from the help desk and BAM owned. My sensors would pick it up and cut their access off and they'd have to come to my desk for restoration. I was unfailingly polite and respectful. Didn't make anyone feel dumb, no berating, just a calm explanation of exactly what happened and how to avoid it in the future. No student ever had it happen to them a second time.
One staff member fell for phishes at least 5 times, though. The president of the college had to talk to that individual eventually.