logoalt Hacker News

LgWoodenBadgeryesterday at 11:26 PM1 replyview on HN

Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate.

Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).


Replies

voakbasdayesterday at 11:51 PM

FWIW, they put a header in the message that you can spot from a thousand miles away. That is how they get past the filters.

I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely.

It’s compliance theater. No real security is gained, but it checks all the boxes.