• A jetlagged Troy Hunt accidentally clicked a link and logged into an account only to realise he had been phished.
  • Despite reacting quickly, attackers were able to export a mailing list for Hunt’s personal blog.
  • Hunt has detailed the attack and warned his subscribers in a timely fashion.
  • dubyakay@lemmy.ca
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    2
    ·
    5 days ago

    I’ve clicked an obvious phishing link once in an isolated environment with a hardened browser on purpose. It had a tracking link and all and the URL was just ever so slightly off. Nothing happened on the target page though. No attempted script execution, no iframes, no cross site shenanigans, no weird popups or a fake login UI urging me to enter my credentials asap.

    Someone from my company’s security department called me shortly, telling me how I’ve failed the obvious phishing exercise and I had to undergo a half hour long mandatory awareness training. Wasn’t getting out of that one.

    • Jolteon@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      ·
      5 days ago

      If you look at the headers, you can tell which ones are fake phishing and real phishing.