|
|
|
|
|
by jimsparkman
2002 days ago
|
|
My company ran something similar recently. The cyber security team opted for “an important change to your available PTO.” It was from an internal address but from a made up name. The company is large enough (1,300 people) that you wouldn’t know if the name was actually an employee in HR or not. Because IT runs software that proxies and mangles all the links in an email, it’s super hard to evaluate the legitimacy of a URL anyways. Of course, most people clicked the link. |
|
My company used to mandate all emails are signed with AD-registered certificates to lend credibility, but they've moved away from that. (I think the reasoning was that webmail clients don't have robust support for S/MIME certs, but I'm not sure.)