Hacker News new | ask | show | jobs
by thewebguyd 248 days ago
> If somebody gets access to internal documentation, HR lists, etc,

It's hard to be resistant to phishing at that point and you have bigger problems.

What if Susan in HR falls victim to token theft (let's say conditional access/MDM policies don't catch it or aren't configured, which many businesses don't bother with). Her email account is now pwned, and the company gets an email from her, it passes all verification checks because it's actually from her account.

It's still phishing, but the users have no way to know that. They don't know Susan just got compromised and the email they got from her isn't real. If this is a human attacker and not just bots, they can really target the attack based on the info in her inbox/past emails and anything else she has access to.

So there's no way for the organization to be resistant at that point until IT/security can see thea account compromise and stop it. Ideally, it's real-time and there's an SOC ready to respond. In practice, most companies don't invest that much into security, or they are too small and don't have the budget for a huge security operation like that.

It's a really hard problem to solve

2 comments

HR shouldn’t be sending links anyway. They should send instructions: go to the portal (on your corporate controlled laptop, so this could be your new tab page) click on the paystubs link, blah blah.

Somebody in every big company is compromised already.

We got hit in a similar way. They didn't use HR's account to email but they grabbed the mobile phone numbers of everyone in the directory. They then started a text message campaign, pretending to be our CEO, demanding that employees go to Target and buy gift cards on behalf of a client.

One person actually did fall for it but decided to physically bring the cards to the CEOs office. Thankfully that exposed the attack and effectively halted any damage done.

These criminals are relatively clever.

i've noticed the gift card stands at Target and other stores around here now have a sign stating "If you received a text from your boss telling you to buy gift cards, you are being scammed" or similar