Employees most often fall for phishing emails that appear to come from HR or IT - The EE

Employees most often fall for phishing emails that appear to come from HR or IT

Stu Sjouwerman of KnowBe4

London, United Kingdom – KnowBe4, security awareness training and simulated phishing platform provider, has released the most frequently clicked phishing methods. These include the top email subjects clicked on in phishing tests. Half of those that were clicked on had subject lines related to human resources, including vacation policy updates, dress code changes, and upcoming performance reviews. The other top category was IT requests, including password verifications needed immediately. Test results are available on KnowBe4.

By now most people know that if they receive a text message confirming a [£1,800 (€2134.53)] order they never placed, or telling them they’ve just won a new grill, they shouldn’t click on it. But what if it’s from their HR department about an upcoming performance review? Or, what if the attachment is a draft of a strategic plan that mentions their name?

Business phishing emails are particularly effective because, left unanswered, they could potentially affect the user’s daily work, enticing employees to react quickly before thinking logically about the email’s legitimacy. The email source may be hidden by a spoofed domain, making it even easier to miss, and may even have the company name and logo (sometimes even the employee’s name) in the email body. Most include a phishing hyperlink in the email or a supposed PDF attachment.

“We already know that more than 80% of company data breaches globally come from human error,” says Stu Sjouwerman, KnowBe4’s CEO. “New-school security awareness training your staff is one of the least costly and most effective methods to thwart social engineering attacks. Training gives employees the ability to rapidly recognise a suspicious email, even if it appears to come from an internal source, causing them to pause before clicking. That moment where they stop and question the email is a critical and often overlooked element of security culture that could significantly reduce your risk surface.”

To download a copy of the KnowBe4 phishing infographic, visit KnowBe4.

Follow us and Comment on Twitter @TheEE_io

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.