Slashdot Mirror


1 in 3 Michigan Workers Tested Opened A Password-Phishing Email (go.com)

An anonymous reader quotes the AP: Michigan auditors who conducted a fake "phishing" attack on 5,000 randomly selected state employees said Friday that nearly one-third opened the email, a quarter clicked on the link and almost one-fifth entered their user ID and password. The covert operation was done as part of an audit that uncovered weaknesses in the state government's computer network, including that not all workers are required to participate in cybersecurity awareness training... Auditors made 14 findings, including five that are "material" -- the most serious. They range from inadequate management of firewalls to insufficient processes to confirm if only authorized devices are connected to the network. "Unauthorized devices may not meet the state's requirements, increasing the risk of compromise or infection of the network," the audit said.

119 comments

  1. Headline? by Anonymous Coward · · Score: 0

    "1 in 3 Michigan Workers Tested Opened A Password-Phishing Email"

    What the hell kind of headline is that? English please.

    1. Re:Headline? by Anonymous Coward · · Score: 2, Informative

      It's a grammatically correct headline. Learn to read: "1 in 3 Michigan Workers Tested" is the noun phrase (containing a participle form of verb used adjectivally) serving as the subject of the verb "Opened," which takes "A Password-Phishing Email", which is the noun phrase in the role of object for the transitive verb.

      If it's to be nitpicked, one might nitpick that it should read "Password-Phishing Emails" or just "Password-Phishing Email" (no "a" which should be omitted in the headline for brevity reasons anyway).

      But just because you can't read doesn't mean other people shouldn't write like educated people.

    2. Re:Headline? by v1 · · Score: 2

      OPENED the email, or actually pursued it? (clicked a link, replied to the email) Depending on the subject line, it may be totally innocuous looking until you OPEN the email and read the content.

      --
      I work for the Department of Redundancy Department.
    3. Re:Headline? by ShanghaiBill · · Score: 2

      OPENED the email, or actually pursued it?

      Opening an email in a modern mail client or web app should be harmless. Some old apps would automatically load html-linked images, but if that is still a problem, it is not the user's fault.

    4. Re:Headline? by arth1 · · Score: 1

      Some old apps would automatically load html-linked images, but if that is still a problem, it is not the user's fault.

      If it's configurable, in a way that A Reasonable Person would understand how to, they get some blame too.
      It's not like if IT doesn't do their job, that absolves workers. Security is something that needs to be thought about by everyone, from janitor to CFO.

    5. Re:Headline? by ls671 · · Score: 1

      hehe, I still use pine just to make sure, so it isn't only "modern mail client or web app" :)

      --
      Everything I write is lies, read between the lines.
    6. Re:Headline? by jandrese · · Score: 4, Insightful
      From Line 1 of the summary:

      nearly one-third opened the email, a quarter clicked on the link and almost one-fifth entered their user ID and password

      The 1/5 entering their password into the website is the buried lead IMHO. That's absolutely ridiculous.

      --

      I read the internet for the articles.
    7. Re: Headline? by Anonymous Coward · · Score: 0

      I use mutt for some of my email addresses.

    8. Re:Headline? by Anonymous Coward · · Score: 0

      Learn to read you idiot.

    9. Re:Headline? by iamhassi · · Score: 2

      And would encourage someone techie to start sending out phishing emails if they weren't doing it already. 20% success rate is pretty good, much higher than I thought it would be.

      --
      my karma will be here long after I'm gone
    10. Re:Headline? by Bert64 · · Score: 2

      Opening an email should be a safe action, until you've opened it you have no idea what it contains and it might be a perfectly legitimate mail. The IT department should ensure that opening mails and reading their contents is safe.
      Visiting a site linked from an email should also be safe, and that's also the responsibility of the IT department to ensure that browsers and plugins are kept up to date and appropriately hardened against attack.

      Actually entering passwords into a site is the only thing users shouldn't be doing, and this is often partly the companies fault too - in many companies there are legitimate emails which ask you to visit a site and enter creds, so users learn these poor practices and are more likely to fall for the scams, especially highly targeted scams done by someone who has actually researched the target organisation.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    11. Re: Headline? by mmcleod · · Score: 1

      Is it 20% of all people who got the email, or 20% of the people who opened the message and clicked on the link?

    12. Re:Headline? by Anonymous Coward · · Score: 0

      I do consider myself educated, however, I still had to read the headline twice before I managed to "parse" it.
      Surely the headline could have been "1 out of 3 Michigan workers tested ..." or "A third of the Michigan ... " making it much more readable.

    13. Re: Headline? by Anonymous Coward · · Score: 0

      It's of the total tested population.

      If they had said "1/4 of them" or "1/5 of that" it would be smaller and smaller populations.

  2. Sounds about right by Anonymous Coward · · Score: 5, Informative

    We have similar results during my companies initial phishing test so I suspect that this result is not uncommon. Sending out training and multiple rounds of phishing test emails (which then require more training if you click) is the ONLY way to bring this number down. The users need to be made as paranoid as possible before clicking ANY links. After a year and a 1/2 we still have a few repeat offenders who still click on the links or enter username/passwords so Multi factor authentication was implemented, but its far far less then we previously had. Posting as AC for obvious reasons.

    1. Re: Sounds about right by Anonymous Coward · · Score: 1

      We get those at work too. I use them as a convenient excuse to not participate in charity fund raisers that the social committee promotes by email. ("Oh I thought this was phishing")

    2. Re:Sounds about right by arth1 · · Score: 1

      Sending out training and multiple rounds of phishing test emails (which then require more training if you click) is the ONLY way to bring this number down.

      No, firing and hiring people with a healthier level of suspicion should work too.
      Testing gullibility should be part of applicant screening. If the applicant has given an e-mail address, that's one way of testing. During job interviews is another.
      Bonuses for those who never fall for phishing could also be a good idea, helping retain those who Get It.

      That said, dinging people for "opening" an e-mail is probably not correct. Looking at the e-mail context as plain text is harmless. There's a huge difference between someone using a default web browser as a mail client and someone using a restricted viewer/previewer that neither runs scripts, fetches anything, nor expands embedded content.

    3. Re:Sounds about right by ShanghaiBill · · Score: 0

      No, firing and hiring people with a healthier level of suspicion should work too.

      These are state employees, so firing them for incompetence is not an option.

    4. Re:Sounds about right by arth1 · · Score: 1

      These are state employees, so firing them for incompetence is not an option.

      Not hiring gullible people might, though.
      People leaving might be slow, but certain. And if bonuses to those who don't fall for such things might help speed attrition.

    5. Re: Sounds about right by mikael · · Score: 2

      Did the same to the debt collection department of my credit card bank who called me up; Indian accent - check, city with high social deprivation - check, telephone number with no SMART id (don't know what SMART is, but if the number doesn't have it, it must be a phishing attempt - check). Just make up some names and numbers and drop the call when they asked for my debit card number. Wouldn't they know that if they were from the bank? Tell them the cheques in the post.

      --
      Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
    6. Re: Sounds about right by Anonymous Coward · · Score: 0

      It IS phishing.

  3. Opening the email is bad? by Snotnose · · Score: 5, Insightful

    I've got the sender and subject visible to me, if they look legit of course I'm gonna open it. I don't click links unless it's something like a new website setup or lost password reset or somesuch where I'm expecting a message. I never enter logins nor passwords to links I get in email.

    In other words, opening the email isn't (err, shouldn't be) the problem. It's what you do after that that's the problem.

    Then again, I don't use Outlook so opening the email isn't all that hazardous to me.

    1. Re:Opening the email is bad? by Anonymous Coward · · Score: 0

      Well obviously, you're supposed to ssh into the mail server, navigate to the maildir files and view them in vi. Duh.

    2. Re:Opening the email is bad? by novakyu · · Score: 5, Insightful

      From TFS: "almost one-fifth entered their user ID and password."

      The headline probably should have led with that.

  4. Bad metrics by lgftsa · · Score: 4, Insightful

    1/3 opened the email? That means that 2/3 don't read their email.

    You can't tell if it's a phish just by the subject line and the displayed sender name, you have to at least check the sender email address, path headers and link html to make an informed decision.

    1. Re:Bad metrics by Anonymous Coward · · Score: 2, Informative

      2/3 of slashdot users don't read the article summary.

    2. Re:Bad metrics by arth1 · · Score: 2

      I hope they mean that 1/3 opened it in a client that fetched external content or ran a script that connected remotely.

    3. Re:Bad metrics by sheramil · · Score: 3, Interesting

      You can't tell if it's a phish just by the subject line and the displayed sender name, you have to at least check the sender email address, path headers and link html to make an informed decision.

      You'd think so. I got an email from someone claiming to work for the Taxation Office. It looked suspicious so I ignored it. Then I got a phone call from someone with an Indian accent, following up on the email. I hung up on them and checked the number; a couple of websites claimed the number belonged to a group of spammers, and some posts said it was a legitimate number from the Taxation Office - as you might expect. I searched the ATO website and couldn't find the number... I spent a couple of days chasing it up; it turned out it was from the Taxation Office, and they wanted to do a phone audit. When I mentioned the problems I had determining the legitimacy of their inquiry, they didn't seem to care.

    4. Re:Bad metrics by Anonymous Coward · · Score: 0

      Taxation Office

      That would be my first clue that it's a fishing attempt. There is no such thing as a Taxation Office on the left side of the pond.

    5. Re:Bad metrics by Anonymous Coward · · Score: 0

      Same thing happened to me at work except from Microsoft. A guy that barely spoke English except for obscenities called me, and he said he wanted me to die and wanted to rape my daughter. I don't have a daughter so I thought it was a scam call. I found-out later it was a real audit from Microsoft, and they were pissed that I hung up on them. That cost us about a quarter of a million even though we don't use any of their garbage. My boss was pissed at me, and I almost got fired for not taking a Microsoft employee seriously that said he wanted to rape my daughter.

    6. Re:Bad metrics by sheramil · · Score: 1

      It was the Australian Tax Office, and my point was, it sure as hell looked like a phishing attempt, but it wasn't.

    7. Re:Bad metrics by Bert64 · · Score: 1

      Most email clients don't make it especially simple to show where links are actually pointing, you used to get a statusbar which showed the actual target (in browsers too) but thats uncommon now too. And most users wouldn't know what this meant anyway.

      Most mail clients only show you the From: header field, while most mail servers only perform filtering on the envelope from, so its quite easy for someone malicious to bypass filtering and still make it look like the mail came from someone you know. It's not hard to work out email addresses of employees at a company, and work out the job roles of people...If someone receives an email purporting to be from someone senior in the company they're going to open it and probably follow any links within.
      Even more so if the company routinely sends out emails with links, users will be used to opening links and potentially entering data into the resulting sites. Many companies get all kinds of employee surveys sent around for instance.

      A little research into the target organisation can yield a very high success rate with phishing emails. Even a blatantly obvious scam will usually net some results.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    8. Re:Bad metrics by thegarbz · · Score: 1

      they didn't seem to care.

      And yet they corrected that problem anyway. You don't get emails from the Taxation Office anymore. Or rather they moved it. The only correspondence you should get now are via messages posted to you online through the my.gov portal.

    9. Re:Bad metrics by gtall · · Score: 1

      There are two additional problems. Most users wouldn't know how to read the entire email header even were it visible. And checking up on all the dodgy emails? C'mon, who has time to do that?

    10. Re:Bad metrics by arth1 · · Score: 1

      And yet they corrected that problem anyway. You don't get emails from the Taxation Office anymore. Or rather they moved it. The only correspondence you should get now are via messages posted to you online through the my.gov portal.

      Wot, an arm of the Australian government has hacked my.gov to use it for communicating with their citizens?

    11. Re:Bad metrics by thegarbz · · Score: 1

      Hacked? Wtf are you talking about? My.gov is the official communications portal for government services including tax.

    12. Re:Bad metrics by arth1 · · Score: 1

      My.gov is the official communications portal for government services including tax.

      I repeat: The GP is in Australia.
       

    13. Re:Bad metrics by thegarbz · · Score: 1

      I repeat: The GP is in Australia.

      ... and you're repeating yourself why? : http://my.gov.au/

    14. Re:Bad metrics by arth1 · · Score: 1

      ... and you're repeating yourself why?

      Because you do?

      my.gov.au != my.gov, and my.gov is what you said. Twice.

    15. Re:Bad metrics by thegarbz · · Score: 1

      I invite you to click on the link and see what they call themselves.

      I also invite you to go to www.my.gov and realise why you won't get an email from that site either.

  5. Do away with links in emails already! by EzInKy · · Score: 1

    Seriously, these phishing scams have been going on for far too long now and cost billions. If there is information that can not be disseminated people should be directed to go to a well vetted website.

    --
    Time is what keeps everything from happening all at once.
    1. Re: Do away with links in emails already! by Anonymous Coward · · Score: 1

      What is your solution for replies. There will always be risk with 2 way communication

    2. Re: Do away with links in emails already! by Anonymous Coward · · Score: 0

      If only there were some way to exchange keys with known contacts and then sign emails to prove authenticity.

    3. Re: Do away with links in emails already! by Anonymous Coward · · Score: 0

      Sure, you just got about 6 and a half billion more people to teach about PGP.

      Otherwise all your doing is confusing everyone with gibberish emails.

    4. Re: Do away with links in emails already! by Anonymous Coward · · Score: 0

      Nowadays PKE is a basic computer literacy skill, needed to stay safe on the internet. If you do not have it you have no business using an internet connected device.

      In other news, most people have no business using an internet connected device.

    5. Re:Do away with links in emails already! by Anonymous Coward · · Score: 0

      That is about as likely to happen as people stop eating. I do not think you have worked in any companies where all work is processed through that medium. "just send them a text message" you realize that is the exact same problem. Just a different medium. E-Mail is just long form text messages. Most people treat it as such.

      If there is information that can not be disseminated people should be directed to go to a well vetted website
      Ah the block everything until our crack team of web surfers has vetted it. How exactly would that work with a company that has say 2000 developers and are scouring the web all the time for information?

      I would propose that perhaps you have not thought this problem through thoroughly. You have just advocated that the working world throws out one of its main communication mediums with no real replacement or policies that say why and how. Here is a lesson from an 'old fart' (I have learned it many times the hard way), do not just throw out ultimatums and expect any traction. You look the fool for doing so. Then if you double down you good ideas will get no traction as you will be seen as someone 'just making things up again'.

      In this case the proper action is teaching. Which sucks as always. You show people what bad emails look like and how to spot them. You then periodically test them. If they fail you train again. Sorry there is no 'good solution'.

      Here, fill this out in your spare time. https://craphound.com/spamsolu...

    6. Re:Do away with links in emails already! by HiThere · · Score: 1

      When email was text there wasn't this much of a problem. The merger between email and browsers with javascript enabled, however, has been horrendous. And incomprehensible links just makes things worse. Link shorteners are totally untrustworthy, but so are links that push you to a php page, and there are all sorts of links full of various kinds of gibberish so you never know where they're going to link you to. It's not too bad if you don't have javascript enabled, but just try to convince people to avoid it. I've got to admit that even I have javascript enabled, though I do have an ad blocker running. But this causes me to be a bit paranoid about what links I click.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    7. Re: Do away with links in emails already! by ShanghaiBill · · Score: 1

      Sure, you just got about 6 and a half billion more people to teach about PGP.

      People didn't have to learn about cryptographic algorithms to use HTTPS. Thee is no reason they need to learn it for secure email either. All that is needed is for Google, Facebook, Microsoft, and Apple to agree on a standard. Everyone else will be forced to follow or be left behind.

    8. Re:Do away with links in emails already! by Dutch+Gun · · Score: 1

      Don't worry. Microsoft is working on making links in e-mail useless.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    9. Re:Do away with links in emails already! by ShanghaiBill · · Score: 1

      The merger between email and browsers with javascript enabled ...

      Citation please. Can you name a single email client or app, less than a decade old, that executes JavaScript inside a received email?

    10. Re: Do away with links in emails already! by Anonymous Coward · · Score: 0

      But do the big three want end-to-end encrypted email? Google and Microsoft are built on reading your email.

    11. Re: Do away with links in emails already! by Anonymous Coward · · Score: 0

      All of them. Try using gmail without javascript enabled in your browser. Modern web apps, including every e-mail site I use, simply assumes that the browser eill run their scripts for their basic operation.

    12. Re: Do away with links in emails already! by Bert64 · · Score: 1

      There is a standard - S/MIME, OSX/iOS mail and Outlook all support it by default, not sure about Gmail...
      The problem is it takes effort to configure, so noone does.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    13. Re:Do away with links in emails already! by Bert64 · · Score: 1

      Use an isolated and hardened system for accessing the web, keep business systems airgapped from the public internet, what limited data needs to pass back and forth is easier to check. Your developer only needs to read, not usually copy large amounts of data.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    14. Re: Do away with links in emails already! by Bert64 · · Score: 1

      Thats the UI for the webmail system, not javascript embedded in the content of received messages.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    15. Re: Do away with links in emails already! by Aighearach · · Score: 1

      You do know that if there is js in an email, and you use the gmail web client, it doesn't pass that shit through?

      No, you didn't. And yet! lol

      I don't even think you were just leaning on an inappropriate pedanticism that isn't relevant. I think it is a worse problem.

    16. Re:Do away with links in emails already! by HiThere · · Score: 1

      Read what you quoted again!
      Try it as grouping it as "The merger between email and [browsers with javascript enabled]"

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    17. Re: Do away with links in emails already! by david_thornley · · Score: 1

      People didn't have to learn about cryptographic algorithms to use HTTPS.

      Of course not. All technical details are handled by the software. The user doesn't have to have a clue that something called a "key" is involved. A random key can be generated and discarded, since it's of no use after the session, and doesn't have to be used on any other browser.

      This won't work for email. To use PGP effectively, the user must generate a key pair and publicize the public key. This means that the user has to be aware of a multi-kilobit persistent key, and safeguard it and transfer it to any mail client the user reads email on. If the user loses the key, all future email is unreadable. If the private key gets known to others, the others can pose as the original user and there's no reliable way to tell the difference. All of the other details can be handled in software, but key management is vital.

      Lots of us here know what's going on, and know how to handle this situation. Very few people in the general population do.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  6. Re:Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    Michigan turned red in 2016.

    Conservatives like you are really a stupid bunch, but we knew that already.

  7. secured ? by johnjones · · Score: 4, Interesting

    the email system never verified the URL nor where the email was from

    so your email system is so poor you have to rely on the end user not to click on a link ?

    simply block / rewrite URL's that have not been verified

    only accept mail from domains that have been verified and claim the email is from them
    (for example that have DNSSEC and DANE setup correctly as gov address's have this and can therefore prove that they sent the email)

    simple basics that are not the end users fault

    1. Re:secured ? by Sarten-X · · Score: 5, Insightful

      There is no technical solution for user awareness.

      Sure, you can verify senders... then you only get spam from compromised hosts, or free relays/mass-mailers, or any other way that attackers are increasingly using to get around such things.

      You can mangle unrecognized URLs... but then your users complain that their legitimate emails from partners and vendors aren't getting through properly (especially when they just signed the contract), and it still doesn't help when the attackers use bit.ly and other common services to hide.

      Once all that has failed, you're still relying on end users to not click links... but if you sold your boss on this "simple basics" security checkbox, you suddenly realize that you never got funding for a user-education course, and that targeted phishing campaign is now wildly successful and claiming victims across your enterprise.

      Sure, go ahead and include all of that technical wizardry, and it will indeed reduce your exposure, but please don't spread the myth that a technical barrier is a one-step fix for email security problems. Users are the last bastion of a defense-in-depth solution, which is also one of those "simple basic" concepts.

      --
      You do not have a moral or legal right to do absolutely anything you want.
    2. Re:secured ? by Anonymous Coward · · Score: 1

      Rewriting URL's is in theory good-- but in reality, try having a technical discussion with someone that involves web development or administration.

      Better yet, try following a vendor-supplied link to their support site. Or activating your account on a vendor site.

      URL rewriting makes email practically useless for my job.

    3. Re:secured ? by Anonymous Coward · · Score: 0

      Form a network security professional's perspective, it sounds as if you know as much about what you are talking about as you know about grammar.

      Of course this is Slashdot so anyone speaking with confidence and agreeing with group-think gets a +5.

      For anyone that honestly is interested, apply some critical thinking skills to the above poster's comment. Does ensuring email traffic coming from the domain it claims to prevent attacks? Does an email need to provide a domain? Do attackers own domains and can they pass the filter? Would being able to pass the filter give credence to their attacks? If so, why would they not put out more effort to conform than legitimate traffic? If an email is from a trusted domain, and came in on an encrypted channel with a valid certificate, does that mean the email is inherently trustworthy? What would your organization do if you, as the security guy, said no email will be accepted unless the other end has several technologies in place which are not often used at this time? Would you still have your job on Monday if you blocked all client emails containing RFP's because they don't have DANE, their own DNSSEC server, paid the money for the two necessary certs, and implemented the whole list correctly?

      Use your brain.

  8. Michican has a few Great Lakes by Mister+Liberty · · Score: 1, Funny

    They like their phishing up there.

    1. Re:Michican has a few Great Lakes by Anonymous Coward · · Score: 0

      4 out 5 even!
      Plus numerous inland lakes and other waterways.
      To say we "like" Fishing is an understatement. It is nearly a religion.
      Hell we even do it when the water is FROZEN!!
      But, your play on words is still appreciated.
      *clap, clap*

  9. Security best practices by Anonymous Coward · · Score: 0

    Best practice in computer security is not to open any emails or visit any websites. In fact, unplug from the Internet completely. Also put glue in all your USB slots and disable any optical drives. Require MFA and post an armed guard to stick a finger up your ass upon logon/logoff. In fact, forget using the computer, just get a room with the guard, curl up in a security blanket and jam your thumbs in each other's asses.

    Meanwhile, the rest of the world will keep getting stuff done in a world where risks exist.

  10. Re: Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    Michigan has been the home of communism since Henry Ford died.

    He was America's last stalwart fascist, but uneducated buffoons like you and GP would never know it.

  11. Yes by Anonymous Coward · · Score: 0

    But how many like me entered a username password combo of:

    Yourmom
    8====D

    Crack my account now Ivan!

  12. Small wonder by nospam007 · · Score: 0, Troll

    Around 20% of the population have an IQ under 85, that should be about it.

    I guess lots of them have a MAGA hat. GDARVF

    1. Re:Small wonder by iamhassi · · Score: 1

      You nailed it, everything that has ever happened is somehow related to Trump. Some worker opens an email? Trump did that

      --
      my karma will be here long after I'm gone
  13. Seems Simple by Anonymous Coward · · Score: 0

    Send out fake phishing email, collect logins to database, generate pink slips from that database. Automate away management jobs.

  14. Re:Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    Only because they voted against Hillary. Otherwise, they're strong blue.

  15. This is tough ... by CaptainDork · · Score: 4, Interesting

    ... and I dealt with it during my career. I'm a retired IT.

    I held seminars, talked to employees one-on-one, and damned if we didn't still get hit.

    It was a law firm and the staff never fell for phishing.

    My problem was the fucking lawyers, especially the managing partner!

    That bastard would click on anything.

    He got a goddam email that said his UPS package wasn't going anywhere unless he looked at the invoice and corrected the address.

    I asked him if he sent anything via UPS and he said, no.

    I asked him if he remembered signing an exclusive with FedEx that I negotiated and he did.

    I asked him if he, personally, ever sent a package anywhere or if he let his staff do that -- he said staff.

    He did that shit over and over again.

    --

    I'm waiting for AI to step in; predict the outcome of clicking on a link and forbidding forward progress until an IT person concurs.

    --
    It little behooves the best of us to comment on the rest of us.
    1. Re:This is tough ... by Freischutz · · Score: 1

      ... and I dealt with it during my career. I'm a retired IT.

      I held seminars, talked to employees one-on-one, and damned if we didn't still get hit.

      It was a law firm and the staff never fell for phishing.

      My problem was the fucking lawyers, especially the managing partner !

      That bastard would click on anything.

      He got a goddam email that said his UPS package wasn't going anywhere unless he looked at the invoice and corrected the address.

      I asked him if he sent anything via UPS and he said, no.

      I asked him if he remembered signing an exclusive with FedEx that I negotiated and he did.

      I asked him if he, personally, ever sent a package anywhere or if he let his staff do that -- he said staff.

      He did that shit over and over again.

      --

      I'm waiting for AI to step in; predict the outcome of clicking on a link and forbidding forward progress until an IT person concurs.

      Was his name Homer?

    2. Re:This is tough ... by cyn1c77 · · Score: 1

      ... and I dealt with it during my career. I'm a retired IT.

      I held seminars, talked to employees one-on-one, and damned if we didn't still get hit.

      It was a law firm and the staff never fell for phishing.

      My problem was the fucking lawyers, especially the managing partner !

      That bastard would click on anything.

      Obviously, he was looking for someone to sue!

    3. Re:This is tough ... by Anonymous Coward · · Score: 0

      Lawyers are trained to filter everything they hear. He likely just thought "He's going off on me again" and filtered your instructions out, because they didn't fit his view of how stuff is supposed to work. Couple that training with Dunning Kruger effect... it's what they do (and has been the bane of my existence for the past 20 years).

  16. Re:Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    strong blue

    Republican governor, republican legislature.... doesn't seem that "strong" to me.

  17. Re: Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    It's one of several states with Muslim Sharia law though.

  18. Re: Shows blue states are not tech savvy by Excelcia · · Score: 2

    Holy frak guys, just start the second civil war already. The rest of the world knows it's coming, might as well just get down to it.

  19. 1 in 3 are forced to use bad email software by Mozai · · Score: 4, Interesting
    "Opening" an email is tracked by whether an image in the HTML version of the email was fetched. Too many email clients will pre-fetch images so that it will look better or open faster when the human user finally does click on the item in their inbox. Knowing government employees, they aren't allowed to chose email software for work, and the config settings are locked-down. I expected that "opened the email" statistic to be way higher because government employees usually don't have a choice.

    The 20% is the important statistic and that's scary enough already; no need for ABC News to embellish the story.

    1. Re:1 in 3 are forced to use bad email software by Aighearach · · Score: 1

      Good idea, but you have some problems. If they're not in control of their clients and the clients were pre-fetching the images, wouldn't you expect it to be much higher than [some percent?] If the policy changes from team to team, you already gave up your whole "gubermint no choices" narrative.

      Also at the other end, there are people like me who don't let the client display images even when I "open" (read: read) the email. It seems pretty silly to me that I think I might be getting a targeted attack message, and I wouldn't even look at it! A lot of those messages can infer information about what type of attack you're under. It is definitely worthwhile to scrutinize them closely so that you can be aware in advance that there might be other types of social engineering attacks made against you or your company by the same actor. Don't click the links, but don't just ignore all attacks, either.

      So I did read the phishing email, but no, I didn't load a tracking image.

  20. Re: Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    A civil war in Russia?

  21. OK, I am an IT person in Michigan. Now... by Anonymous Coward · · Score: 0

    if you had read the audit, you would find that:
    1. They were auditing the telecom (read phones, routers and switches) area of the Michigan Department of Technology Management and Budget.
    2. Email is handled outside in a different group called messaging (still a part of DTMB but not being currently audited).
    3. There is nothing the telecom people can do to make users take computer security courses.
    4. There is very little the telecom people can do to prevent people from opening email short of blocking all communications to and from the email servers.

    So, the Auditors audited the telecom (wrong) group and found them at fault (for not teaching state employees to avoid phishing emails) and published it in the papers!

    Does this really sound correct?
    I think someone should call the auditors out on this and have them dismissed (not the state employees who opened the email as previous posts indicated).

    This isn't the only audit that they have executed where the wrong people/area were held responsible for things that they cannot control or influence.

    Just because their title is auditor, does not make them always correct.

  22. Re: Shows blue states are not tech savvy by arth1 · · Score: 1

    Michigan has been the home of communism since Henry Ford died.

    Back in the days when communists were red and conservatives were blue, i.e. before a TV channel employee got the two mixed up in a poll presentation and the wrong colours stuck in the minds of largely ignorant Americans.

    What we have in the US these days is brown.

  23. Re: Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    Yea, I always thought it should be the blue blood elites versus the red communists.

  24. Re: Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    It isn't a Civil War, it is a way of life.

  25. Security+(SY0-501) by Anonymous Coward · · Score: 0

    I'm taking the CompTIA SY0-501 Security+ exam next week - This news does not surprise me and is in fact consistent with what I have been learning in CompTIA's latest rendition of their Sec+ certification; Internal employees constitute the single largest security threat to a company.

  26. Those numbers are actually good! by hibiki_r · · Score: 4, Interesting

    I've been a part of aggressive, well crafted phishing tests in Silicon Valley companies. Some of those tests were secret enough that only 3 people were aware of the test in advance... and the results were terrifying. Thanks to HTML abuse, forged headers and very good copy, I've seen 70% of storied security teams fall for the phishing attempt, going as far as to enter their 2fa values for AWS. In a real world situation, just one person falling for it would have been a problem.

    In practice, what I have learned is that against a sophisticated opponent, any security system that relies on just usernames, passwords, and simple 2fa might as well not exist. The bare minimum is unique usernames and passwords just to double check that the right human is on the other side, attached to client certificates that are unique to each machine, and strong mechanisms to make sure that nobody generates user + certificate pairs for new computers without big flashing signs popping up. Anything weaker is just relying on being an uninteresting target, which is not a good thing to rely on.

    1. Re:Those numbers are actually good! by mikael · · Score: 2

      We had courses at my work place. Things to look for include mis-spelt words, links that didn't use https and/or moved to a different domain from the sender. Which makes me ask, why couldn't an email filter pick this up.

      --
      Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
    2. Re:Those numbers are actually good! by Anonymous Coward · · Score: 2, Insightful

      We had courses at my work place. Things to look for include mis-spelt words, links that didn't use https and/or moved to a different domain from the sender. Which makes me ask, why couldn't an email filter pick this up.

      That's also my question.
        How often do corporations of any size used spoofed headers for business emails? They do that for their newsletters, advertisements, and email surveys and crap, yes, but not for invoices and person to person communications.

      I wish our email client had a configuration to flag to the user "This email's sender does not match the actual origination." As well as "This email appears to have originated in Bulgaria". If we actually had a vendor in Bulgaria, the people who handled that account would already know who that was and could continue, but a clerk at the front desk would have gotten a clear warning.

    3. Re:Those numbers are actually good! by AHuxley · · Score: 1

      Great for contractors renting AV gov/mil solutions too.
      Think of the clean up contracting over time for every email opened and clicked.
      The renting of new tools after a criminal malware event that are then suggested.
      The US party political cyber news if the very average criminal malware is "Bear" or "Russia" related too.

      What would happen if workers did not click? Thats money off the table for contractors who have to have AV products to sell.

      --
      Domestic spying is now "Benign Information Gathering"
    4. Re:Those numbers are actually good! by Aighearach · · Score: 1

      I include, "asks me to do something that would be really non-secure and provides a link to make it convenient."

      Security and convenience are a trade-off, if you're distributing real information to technical workers that they would take actions based on, you don't want to even try to make it convenient with links. You want to just give them the data: "Foo has problem Bar, please log into your Secure BlahBlah and don't forget to wipe the cargo port with the rubber chicken." No link. If they don't know how to access Secure BlahBlah, then they shouldn't be accessing it.

      Here in the US, if the email was actually something important and I didn't respond, they'd have to notify me by registered mail instead. So things you'd actually have to respond to would all be for internal, company-controlled reasons where the technology can be matched with the use case.

  27. Our State IT department conducts these tests, too by Anonymous Coward · · Score: 1

    The problem is that they also use a number of 3rd party vendors (with non-State domains) to host various official systems. They conducted a mandatory survey of employees once (survey monkey, iirc) and had to send out a follow-up e-mail telling everyone that the first e-mail was real and was safe to click on. Apparently, a large percentage of people were reporting the e-mail as a phishing attack or simply ignoring it.

    It didn't help that the mandatory yearly cyber-security training came out shortly before the survey and how the survey e-mail was written and the type of questions asked in the survey ticked off a number of the "This is how you spot a phishing attack" pointers from the training.

  28. Re:You must be new here by Anonymous Coward · · Score: 0

    You must be new here. The whole point of /. is to let someone else RTF[AMS] for you! :P

    I've been a daily visitor for 18 years, and during that time I think I've read the linked article a few dozen times (e.g. cool NASA stuff with pretty pictures), and I only bother to read about 1-2 summaries per month.

  29. That's of State of Michigan workers, not "Michigan workers". (Before the coasties get too smug)

    (Then again, I wouldn't expect much better from a typical company. Anywhere.)

  30. Monthly phishes from security really help by raymorris · · Score: 4, Interesting

    I have found that when the security team sends out "phishing" emails about once a month, that helps. Opening the link takes the employee to a page reminding them about phishing. If instead they click the "report" button in Outlook, they get a happy message. It changes behavior after a few months.

    1. Re:Monthly phishes from security really help by Anonymous Coward · · Score: 0
  31. Re:Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    Michigan voted for Trump you conservative Republican idiot.

  32. Re:Shows blue states are not tech savvy by iamhassi · · Score: 1

    Michigan turned red in 2016. Conservatives like you are really a stupid bunch, but we knew that already.

    One election doesn't change the dozens of years of voting history

    --
    my karma will be here long after I'm gone
  33. Management's fault by iamhassi · · Score: 1

    Quick search revealed at least a dozen companies that offer phishing tests to employees, to send fake phishing emails to them to see if they open and click on links. If management isn't using these tools when so many are available they're as much responsible as if they chose not to use virus scanners or network firewalls. And why doesn't Google, Microsoft and the other email providers do more by sending fake phishing emails out to educate users more? All it takes is a few fake phishing emails to educate users. First time is 20% entering passwords, second might be 10%, by the time you get to fifth fake email you're probably at less than 1% and only a few percentage higher even opening the email.

    --
    my karma will be here long after I'm gone
  34. I got probed at work like this by WinstonWolfIT · · Score: 1

    I configure my mail clients to only put my inbound in my inbox if you're in my collected addresses. When the report came out, it was an email I simply never saw. But... about 1/3 of this high tech company got phished. On the downside I kinda sorta failed because I didn't report the suspicious email. Meh.

    1. Re:I got probed at work like this by Anonymous Coward · · Score: 0

      ... On the downside I kinda sorta failed because I didn't report the suspicious email. Meh.

      Not a problem anyway.
      With a likely 20% going all the way through the phishing process, someone reported the pwning of their computer to IT.

  35. Re: Shows blue states are not tech savvy by Anonymous Coward · · Score: 0

    I need my guns to fight the government. The constitution says so.

  36. Responsibilities by demon+driver · · Score: 1

    It's not like if IT doesn't do their job, that absolves workers. Security is something that needs to be thought about by everyone, from janitor to CFO.

    Simply declaring such a responsibility, whether rightfully or not, doesn't improve security an inch. That would be magical thinking.

    Obvious fact is, people who are no IT specialists tend to lack the awareness and knowledge to be able to fulfill such a responsibility. If employers, or, in case of public service, we as a society, want employees to care for security, employers have to make sure that they get proper training. Something that obvously has been neglected in the cases we're talking about here. It's as simple as that.

    1. Re:Responsibilities by Bert64 · · Score: 1

      Current operating systems are designed by and for IT specialists, they are not suitable for people without such knowledge. If you need to use something that can only be done on such a system then you should receive appropriate training on how to use it properly, and/or use a machine that is managed by someone who does have the appropriate knowledge.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    2. Re:Responsibilities by arth1 · · Score: 1

      Simply declaring such a responsibility, whether rightfully or not, doesn't improve security an inch. That would be magical thinking.

      True. Merit for those who do well, and demerit and eventually replacement for those who don't, on the other hand, should work.

      employers have to make sure that they get proper training

      The problem is not with knowledge, it is with attitude and aptitude. There are people who will never act in safe manners, no matter how much training they receive are hired by people who don't care.

      I have held computer security classes, and generally, they only help those who have an interest. People who are trusting, gullible or greedy by nature won't change due to mere knowledge transfer. They will always be a vector of attack, and no matter what safeguards are put into place, as long as people are allowed to communicate, the weak human links will be exploited.
      The only recourse I see is to avoid hiring weak links, and get them out before they break.

  37. Russians by Anonymous Coward · · Score: 0

    The entire state of Michigan shut down, Russian hackers to blame.

    (Not the idiots living in Michigan)

    1. Re:Russians by Anonymous Coward · · Score: 0

      And then the Russians were elated... but after a while realized Michigan had nothing of value.

  38. Re:Shows blue states are not tech savvy by Anonymous Coward · · Score: 1

    Michigan has a republican governor, state senate and state house, and has for the last 8 years. It's had a republican senate for the last 12 years. Currently, in the house and senate, they have a super-majority.

    We've got one of those fine cases of gerrymandering. Michigan isn't as extreme as some other places, but our districts have been drawn to "crack" and "pack" to pretty much hand the republicans the majority. My district is 9 houses wide at my section, and extends 6 miles in each direction where they expand to dilute our votes.

  39. Would they even notice? by Anonymous Coward · · Score: 0

    And nobody notices the shutdown because they were all at a juggalo gathering.

  40. No big deal by Bust0ut · · Score: 0

    Unless our police are using databases which connect to laptops to dictate how they behave, but get real, right..

    --
    He is crazy if you think about it; I am not.
  41. ANTHEM legit communication looks like phishing! by Anonymous Coward · · Score: 1

    AC for obvious reasons.

    Got a phone call from Anthem. They left a voice mail with a number of personal details (name of family members) and asked for a call back to some 1-800 number, The originating phone number was not listed on their web site. I called back the 1-800 number and it asked for personal details such as date of birth. "To make sure it's you, please enter your date of birth."

    Uh... No.

    I hung up and sent my HR department a note telling them that someone was conducting a phone phishing campaign on employees. Hey, they were using phone numbers that were not listed as Anthem's, so that was obvious, right? I expected that this was the end of it, but HR duly contacted Anthem.

    A few days later, I got an irate email from some Anthem customer communication guy that, in essence, tells me I am a fool and that this is not phishing but a business-as-usual communication, and can I please stop wasting his time and comply?

    I am flabbergasted. These Anthem guys have my email, a site on which they can send me personal notifications, and of course my mailing address. And they chose to sent automated phone calls from unverifiable origin? With personal detail requests that sound furiously like spear phishing? SERIOUSLY?

    Does anyone in that company have any bloody clue?

    Did anyone else get this type of legit-sounding-phony calls?

    1. Re:ANTHEM legit communication looks like phishing! by Anonymous Coward · · Score: 0

      ...Does anyone in that company have any bloody clue? ...

      Uh, NO.
      Have we already forgotten the HUGE breach at Anthem?

  42. Re: Shows blue states are not tech savvy by Aighearach · · Score: 1

    Holy frak guys, just start the second civil war already. The rest of the world knows it's coming, might as well just get down to it.

    In before Han shoots first!

  43. Re:OK, I am an IT person in Michigan. Now... by Aighearach · · Score: 1

    The part you missed is that the purpose of the audit is to find out what the state of the situation is. It is not the purpose of the audit to assign or restrict Virtue.

    So the whole, "Golly it isn't their fault but they look bad" angle is really weak. If you know better, simply refrain from thinking the wrong party is responsible, and take the message as, "there is no system, and the users aren't expert enough to do it right without a system." You don't hide that from ebil "papers" in order to protect people's Virtue, instead it is good for the People to know that there is no working system. Maybe some people later will react by putting a system in place?

    Your response is what I'd expect from a representative of the Neckbeard Union or something, just trying to white knight it and protect people not under any attack.

  44. Any design where people must do the right thing... by gestalt_n_pepper · · Score: 1

    ...all the time has already failed.

    --
    Please do not read this sig. Thank you.
  45. Re:OK, I am an IT person in Michigan. Now... by Anonymous Coward · · Score: 0

    Odd. I am not a neckbeard Union Rep. I am not in the Union. And I am not sure why you are attacking me.
    The Audit was to examine the security and configuration of switches and routers. That was the purpose of the Audit.
    The Audit was not to test the security of the State of Michigan. Email is not part of switches and routers. The training courses for internet security comes from a whole different Bureau. The State of Michigan has courses that all employees must take that covers phishing scams amongst other things. If they want to audit the group responsible for the training, that is cool. But the Auditors have assigned a finding to a group that has nothing to do with the internet security training. Individuals who configure routers and switches cannot re mediate the finding. Now they are stuck with an audit finding forever. The bureau that is responsible for the training should be assigned the finding. They would have the ability to fix things.
    btw, I am not part of either bureau. I am not trying to be a white knight and I am not trying to cover things up. There is a problem, but to get it fixed it needs to be assigned to the right group.

  46. Re:You must be new here by Anonymous Coward · · Score: 0

    Me too. I'm just here for the entertaining comments.