Hacker News new | ask | show | jobs
by jameshart 811 days ago
I received an internal simulated phishing email to my work address, masquerading as a fake Google Play invoice - which happened to show up thirty minutes after I had adjusted payment details on a Google play subscription under my personal email.

It was obviously fake, but the timing was so suspicious, and it came in to the wrong email address - so my first thought was not ‘ah, here’s my Google play invoice’; nor was it ‘ah, a phishing test, let me report it and feel smug’. It was ‘oh crap, my phone must be compromised’ - if someone knows I just updated a Google play subscription, and they cross-associated it with my work email, the only place those come together is on my phone.

Then when I got confirmation that it was a simulated phishing email, my second thought was ‘wait, did the corporate endpoint security system monitor that I was just on the Google play store and send me a targeted phishing attack?’ - which is a significant hit to the degree of trust I place in my employer.

Turns out no, it really was just a randomly selected phishing template and a wild coincidence. But for me it says it is a very bad idea to send out phishing emails that masquerade as real services your employees might use in their private life.