Phishin’ For Trouble, Part 2
I answer a call from a coworker:
Coworker: “Could you come by my office here quick?”
I trudge around the corner towards the hallway and arrive at his office twenty seconds later. He takes me over to his computer and proceeds to show me his e-mail.
Coworker: “I had this e-mail show up, and I can’t get into it. It says something about spam or something, but when I go into it, it gave me a sign-in page, and it didn’t work.”
I gaze at the e-mail entitled “Payment for your services”, emblazoned with a bright yellow banner covering about a quarter of the page that has been helpfully provided by our e-mail provider, informing my user that this e-mail might be spam or a phishing scheme and that they should beware.
Me: “So, you saw the big banner—”
Coworker: *Cuts me off while clicking the link.* “So I clicked on the link here, and it brought me to this page.”
The computer opens up a spoof page requesting his e-mail and password.
Me: “Were you expecting anything like this in your e-mail?”
Coworker: *As he’s typing in his password into the spoof page.* “No.”
Me: “THEN WHAT ARE YOU DOING!?”
Coworker: “Trying to see what it’s about.” *Hits enter.*
Me: “…Well, we definitely need to change your password now.”
Coworker: “How do I do that? Can you do it for me?”
Sigh…
Related:
Phishin’ For Trouble

