Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One of my former employers used a security company to regularly send out very well designed phishing emails with personalized links. Clicking a link or opening an attachment got you a call with IT plus a mandatory class in how to avoid phishing.

The success rate of those simulated attacks dropped drastically after the first few tries. Maybe if more companies did this it would also help fewer people to fall for it outside of work.




The sad thing is that people probably stopped clicking them because they think "Its another dumb IT trick". I guess it works well enough though.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: