Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

GoDaddy Demonstrated How Not to Educate Users About Phishing

GoDaddy Demonstrated How Not to Educate Users About Phishing

While phishing awareness is an important practice to teach to a business’ employees, some methods are better than others, as GoDaddy—the domain registrar and web-hosting company notorious for its run of risqué ads—is learning the hard way. On December 14, GoDaddy’s employees received an email that seemed to be a holiday bonus from the company… only to find out (the hard way) that it was a phishing test that their employer had run.

Let’s review the chain of events:

The Message GoDaddy’s Employees Received

When the employees GoDaddy involved in their phishing test opened their email on December 14, a message from the address “Happyholiday@Godaddy-dot-com” awaited them. Below, we have replicated the message it contained, under a large, branded announcement of a “Holiday Party.”

I hope you’re sitting down:

---

Happy Holiday GoDaddy!

2020 has been a record year for GoDaddy, thanks to you!

Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus! To ensure that you receive your one-time Bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th.

US

EMEA

Any submittals after the cutoff will not be accepted and you will not receive the one-time bonus of $650 (free money, claim it now!)

We look forward to celebrating with you again, in person next year!

---

I don’t know about you, but if that showed up in my email—just before the holiday season, during a year marred by a terrible pandemic, no less—I would be pretty excited.

However, no bonus was in store for the company’s 500 employees who clicked through the links. All they got was another email, two days later, from the company’s security chief. This was how these employees were informed that the email was nothing but a phishing test, and since they had failed, they would need to retake the company’s Security Awareness Social Engineering training.

Of course, this message did not land very well amongst many of these employees… and it certainly wasn’t helped, considering the “record year” that the email bragged about came after hundreds of employees were reassigned or completely laid off, and a data breach had exposed 28,000 GoDaddy customers’ data earlier in the year.

GoDaddy has since released a statement, apologizing for the poorly-thought-out phishing test. As a spokesperson for the company said:

“GoDaddy takes the security of our platform extremely seriously. We understand some employees were upset by the phishing attempt and felt it was insensitive, for which we have apologized.”

Companies Other Than GoDaddy Have Made Similar Errors

GoDaddy is not the only company to stumble during their phishing evaluations. In September, Tribune Publishing sent out an internal phishing email offering targeted bonuses worth anywhere between $5,000 and $10,000. As with GoDaddy, this attempt saw backlash from employees, one reporter tweeting that the cruelty of it was “stunning.” As happened with GoDaddy, the company apologized for its “misleading and insensitive” email.

In Fairness, Phishing Should Be Highlighted…Just Not This Way

While these examples prove that there is definitely a wrong way to educate users about phishing, it must be said that phishing is a very real threat for businesses of all sizes today.

However, when you try to educate your users, we suggest using different tactics. Seminars and training sessions are great options, and practical evaluations are very effective (as long as you do it differently than GoDaddy). The main issue in GoDaddy’s case was that they took advantage of their employees, during a time when many were already under financial strain, running a test that offered them a sizable bonus when they seemed to have no intention of actually distributing it.

Naturally, nobody should hope that their organization offends its workforce, and nobody should hope that their organization falls victim to a phishing attack. Fortunately, Voyage Technology can at least help you with the latter. Call our team at 800.618.9844 to find out how we can help you address the complicated issue of phishing attacks.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 02 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Hardware Internet Efficiency IT Support Malware Privacy Email Google Phishing Workplace Tips Computer Collaboration Hosted Solutions IT Services Users Mobile Device Ransomware Quick Tips Small Business Workplace Strategy Cybersecurity Microsoft Passwords Data Backup Communication Smartphone Backup Saving Money Business Management VoIP Smartphones Android Mobile Devices communications Upgrade Disaster Recovery Browser Data Recovery Managed Service Social Media Managed IT Services Microsoft Office Windows Network Remote Tech Term Internet of Things Facebook Current Events Productivity Automation Artificial Intelligence Covid-19 Cloud Computing Miscellaneous Gadgets Remote Work Server Managed Service Provider Outsourced IT Information Holiday Spam Encryption AI Employee/Employer Relationship Windows 10 Business Continuity Compliance Government Office Training Data Management Virtualization Blockchain Wi-Fi Business Technology Windows 10 Bandwidth Apps Data Security Mobile Office Two-factor Authentication Apple Networking Employer-Employee Relationship App Vendor Mobile Device Management Gmail Chrome Managed Services Voice over Internet Protocol Budget WiFi How To BDR BYOD Hacker Computing Applications Avoiding Downtime Information Technology Marketing Access Control Office 365 Tip of the week Conferencing Storage Password Big Data Bring Your Own Device Managed IT Services HIPAA Router Operating System Computers Virtual Private Network Risk Management Website Health Help Desk Office Tips Analytics IT Support Augmented Reality Healthcare Retail The Internet of Things Scam Data loss Social Cooperation Free Resource Project Management Windows 7 Microsoft 365 Going Green Patch Management Save Money Solutions Customer Service Remote Monitoring Vulnerability End of Support Vendor Management Cybercrime Display Windows 11 Printer 2FA Paperless Office Monitoring Infrastructure Excel Firewall Document Management Remote Workers Telephone iPhone Maintenance Antivirus Sports Licensing Mouse Vulnerabilities Entertainment Data Privacy Administration Images 101 Mobility Telephone System Multi-Factor Authentication Cost Management Customer Relationship Management Robot Settings Hacking Printing Wireless Presentation Employees Content Filtering Integration IT Management VPN YouTube Meetings Modem Wireless Technology User Tip Physical Security Cryptocurrency Processor Mobile Security Computer Repair Holidays Virtual Desktop Data Storage Smart Technology Supply Chain Data storage Word LiFi Video Conferencing Managed Services Provider Virtual Machines Professional Services Outlook Saving Time Machine Learning Money Managed IT Service Humor Safety Downloads Twitter Connectivity IT Break Fix Scams Deep Learning Browsers Smartwatch Error Upload Procurement Azure Hybrid Work Multi-Factor Security Tech Human Resources Education Social Network Telework Social Engineering Cyber security Remote Computing IoT Communitications Dark Web Cables CES Application Mobile Computing Trends Supply Chain Management Google Calendar Term Google Apps Tablet Customer Resource management FinTech Search Regulations Alert Star Wars IT Assessment Microsoft Excel IT Maintenance IBM Best Practice Data Analysis Managed IT Buisness File Sharing Gamification Flexibility Dark Data Staff Value Business Intelligence Legislation Shortcuts Legal IT solutions Organization How To Social Networking Notifications Smart Devices Ransmoware Business Growth Fileless Malware Digital Security Cameras Travel Content Remote Working Wearable Technology Memory Vendors Comparison Google Play Be Proactive Competition Techology Google Maps Health IT Cortana Motherboard Data Breach Directions Videos Assessment Electronic Health Records Permissions Workforce Alt Codes Downtime Unified Threat Management Wasting Time Threats Trend Micro Specifications Security Cameras Workplace Strategies Unified Threat Management Hosted Solution Microchip Internet Exlporer Software as a Service Fraud Meta User Typing Username Network Congestion Managing Costs Amazon eCommerce Black Friday SSID Google Drive User Error Knowledge Database Surveillance Virtual Assistant Outsource IT IP Address Media Point of Sale 5G IT Technicians Virtual Machine Environment Experience Cookies Cyber Monday Medical IT Google Docs Unified Communications Proxy Server Reviews Bitcoin Network Management Running Cable Tech Support Tactics Development Hotspot Transportation Small Businesses Recovery Hard Drives Google Wallet Monitors Mirgation Hypervisor Displays Nanotechnology Optimization PowerPoint Domains Shopping Windows 8 Laptop Websites Addiction Language Employer/Employee Relationships Outsourcing Navigation Refrigeration Drones Management PCI DSS Chatbots Electronic Medical Records Screen Reader Distributed Denial of Service Workplace Public Speaking SharePoint Gig Economy Halloween Service Level Agreement Internet Service Provider Computing Infrastructure Teamwork Hiring/Firing Lithium-ion battery Evernote Paperless Lenovo Entrepreneur Regulations Compliance Writing Identity Virtual Reality Smart Tech Memes Co-managed IT Bookmark Hacks Server Management Scary Stories Private Cloud Download Net Neutrality Alerts SQL Server Technology Care Business Communications Undo Superfish Identity Theft Financial Data Fun History

Blog Archive