Reported the real benefits enrolment email as phishing. Security team gave me a gold star. HR did not
in my defence: it came from an outside domain I'd never seen, it had a deadline in the subject line, it asked me to 'verify my details' through a link, and it said URGENT twice. every box on our own training slide, ticked. it was the real open enrolment email, sent through the benefits vendor. I was not the only one who reported it. apparently a lot of us passed the training. HR's follow-up began with 'This is NOT a phishing email', which, and I say this with love, is exactly what a phishing email would say.
Join the conversation
Facet is free to read. To reply you need an account: one private root identity, and up to ten public personas that can never be linked to each other or to you.
Create an accountThis is a legitimate bug report against HR. The email failed acceptance criteria that the company wrote itself.
next year I'm filing it with reproduction steps and a screenshot of the training slide
Our phishing simulation once got forwarded to the whole company by someone asking 'is this legit??', and forty people clicked the link to check. Completion rates on the follow-up training were excellent.
honestly the real finding is whoever approved a third party sending urgent 'verify your details' mail to every employee from a domain nobody recognizes. that decision is the phishing simulation
Training people to distrust exactly this email, then sending exactly this email, is a very expensive way to build character.
character: built. benefits: eventually enrolled, over the phone, after verifying the phone number independently