Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

GoDaddy Demonstrated How Not to Educate Users About Phishing

GoDaddy Demonstrated How Not to Educate Users About Phishing

While phishing awareness is an important practice to teach to a business’ employees, some methods are better than others, as GoDaddy—the domain registrar and web-hosting company notorious for its run of risqué ads—is learning the hard way. On December 14, GoDaddy’s employees received an email that seemed to be a holiday bonus from the company… only to find out (the hard way) that it was a phishing test that their employer had run.

Let’s review the chain of events:

The Message GoDaddy’s Employees Received

When the employees GoDaddy involved in their phishing test opened their email on December 14, a message from the address “Happyholiday@Godaddy-dot-com” awaited them. Below, we have replicated the message it contained, under a large, branded announcement of a “Holiday Party.”

I hope you’re sitting down:

---

Happy Holiday GoDaddy!

2020 has been a record year for GoDaddy, thanks to you!

Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus! To ensure that you receive your one-time Bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th.

US

EMEA

Any submittals after the cutoff will not be accepted and you will not receive the one-time bonus of $650 (free money, claim it now!)

We look forward to celebrating with you again, in person next year!

---

I don’t know about you, but if that showed up in my email—just before the holiday season, during a year marred by a terrible pandemic, no less—I would be pretty excited.

However, no bonus was in store for the company’s 500 employees who clicked through the links. All they got was another email, two days later, from the company’s security chief. This was how these employees were informed that the email was nothing but a phishing test, and since they had failed, they would need to retake the company’s Security Awareness Social Engineering training.

Of course, this message did not land very well amongst many of these employees… and it certainly wasn’t helped, considering the “record year” that the email bragged about came after hundreds of employees were reassigned or completely laid off, and a data breach had exposed 28,000 GoDaddy customers’ data earlier in the year.

GoDaddy has since released a statement, apologizing for the poorly-thought-out phishing test. As a spokesperson for the company said:

“GoDaddy takes the security of our platform extremely seriously. We understand some employees were upset by the phishing attempt and felt it was insensitive, for which we have apologized.”

Companies Other Than GoDaddy Have Made Similar Errors

GoDaddy is not the only company to stumble during their phishing evaluations. In September, Tribune Publishing sent out an internal phishing email offering targeted bonuses worth anywhere between $5,000 and $10,000. As with GoDaddy, this attempt saw backlash from employees, one reporter tweeting that the cruelty of it was “stunning.” As happened with GoDaddy, the company apologized for its “misleading and insensitive” email.

In Fairness, Phishing Should Be Highlighted…Just Not This Way

While these examples prove that there is definitely a wrong way to educate users about phishing, it must be said that phishing is a very real threat for businesses of all sizes today.

However, when you try to educate your users, we suggest using different tactics. Seminars and training sessions are great options, and practical evaluations are very effective (as long as you do it differently than GoDaddy). The main issue in GoDaddy’s case was that they took advantage of their employees, during a time when many were already under financial strain, running a test that offered them a sizable bonus when they seemed to have no intention of actually distributing it.

Naturally, nobody should hope that their organization offends its workforce, and nobody should hope that their organization falls victim to a phishing attack. Fortunately, Voyage Technology can at least help you with the latter. Call our team at 800.618.9844 to find out how we can help you address the complicated issue of phishing attacks.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 21 December 2024

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security Hardware Internet Efficiency IT Support User Tips Malware Privacy Email Phishing Workplace Tips Google Computer IT Services Users Collaboration Hosted Solutions Mobile Device Quick Tips Ransomware Cybersecurity Microsoft Workplace Strategy Small Business Data Backup Communication Smartphone VoIP Smartphones Android Saving Money Business Management Mobile Devices communications Data Recovery Passwords Backup Managed IT Services Managed Service Social Media Microsoft Office Upgrade Browser Disaster Recovery Network Tech Term Remote Internet of Things Artificial Intelligence Facebook Automation Cloud Computing Covid-19 Miscellaneous Gadgets Server Managed Service Provider Windows Remote Work Current Events Outsourced IT Productivity Information Encryption Spam Employee/Employer Relationship AI Holiday Windows 10 Compliance Office Government Data Management Business Continuity Wi-Fi Blockchain Windows 10 Training Business Technology Virtualization Apps Data Security Two-factor Authentication Mobile Office Bandwidth Managed Services Voice over Internet Protocol App Employer-Employee Relationship Networking Mobile Device Management Vendor Chrome Gmail Budget Apple Conferencing Computing How To Hacker BDR Information Technology Avoiding Downtime Office 365 BYOD Applications Access Control WiFi Tip of the week Retail Healthcare Operating System Managed IT Services Computers Risk Management Website Marketing HIPAA Router Analytics Office Tips Augmented Reality Virtual Private Network Storage Health Password Bring Your Own Device Help Desk Big Data Document Management Social Remote Workers Going Green Telephone Scam Data loss Customer Service Cybercrime Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions IT Support Firewall Display Printer Paperless Office Windows 11 Infrastructure 2FA The Internet of Things Monitoring Excel Virtual Machines Professional Services Saving Time Managed IT Service Maintenance Downloads Customer Relationship Management Antivirus Settings iPhone Printing Wireless Licensing Content Filtering Vulnerabilities Hacking Entertainment Presentation YouTube Data Privacy Cryptocurrency Images 101 Wireless Technology Robot Mobility Telephone System Multi-Factor Authentication Cost Management Virtual Desktop Data storage LiFi Word IT Management Meetings Outlook VPN Employees Physical Security Integration Money Modem Humor User Tip Processor Computer Repair Mobile Security Holidays Safety Sports Mouse Data Storage Smart Technology Supply Chain Video Conferencing Administration Machine Learning Managed Services Provider Screen Reader Writing Distributed Denial of Service Workplace Application Best Practice Lenovo Gig Economy Buisness Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Evernote Paperless IBM Legal IT solutions Server Management Regulations Compliance Private Cloud Identity Identity Theft Smart Tech Memes Co-managed IT Business Growth Superfish Bookmark Download Net Neutrality Twitter Alerts SQL Server Technology Care Business Communications Financial Data Cortana Error History Connectivity IT Social Engineering Break Fix Scams Alt Codes Browsers Smartwatch Competition Downtime Upload Procurement Remote Computing Azure Hybrid Work Multi-Factor Security Tech Human Resources Hosted Solution Social Network Telework Cyber security Tablet IoT Communitications Dark Web Cables Typing CES Trends Supply Chain Management Alert Dark Data Google Calendar Term Google Apps Google Drive User Managed IT Customer Resource management FinTech Knowledge File Sharing Regulations Star Wars IT Assessment How To Microsoft Excel IT Maintenance Data Analysis Gamification Flexibility 5G Notifications Staff Value Business Intelligence Legislation Shortcuts IP Address Google Docs Unified Communications Organization Experience Travel Social Networking Running Cable Google Maps Smart Devices Ransmoware Bitcoin Techology Fileless Malware Digital Security Cameras Google Wallet Content Remote Working Wearable Technology Memory Vendors Comparison Google Play Be Proactive Recovery Health IT Unified Threat Management Motherboard Data Breach Unified Threat Management Directions Videos Laptop Assessment Electronic Health Records Permissions Workforce Hard Drives Windows 8 Domains Drones Wasting Time Threats Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies User Error Microchip Halloween Internet Exlporer Software as a Service Fraud Meta Refrigeration Public Speaking Username Managing Costs Amazon Point of Sale eCommerce Black Friday SSID Lithium-ion battery Entrepreneur Scary Stories Database Surveillance Virtual Assistant Outsource IT Hacks Media Network Management Fun Tech Support IT Technicians Virtual Machine Environment Cookies Monitors Cyber Monday Medical IT Deep Learning Proxy Server Reviews Tactics Development Hotspot Transportation Small Businesses Undo Education Websites Mirgation Hypervisor Displays Nanotechnology Optimization PowerPoint Shopping SharePoint Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing Mobile Computing Navigation Management PCI DSS Search Chatbots

Blog Archive