Hacker News new | ask | show | jobs
by frost_knight 4071 days ago
For 4 years I was the systems security officer for a college. At least 2 students per week fell for a phishing scam. It didn't matter how much we warned about it; emails, orientation lectures for firstyears, one-on-one talks, big alerts on the Blackboard system, you name it.

They'd get an email claiming to be from the help desk and BAM owned. My sensors would pick it up and cut their access off and they'd have to come to my desk for restoration. I was unfailingly polite and respectful. Didn't make anyone feel dumb, no berating, just a calm explanation of exactly what happened and how to avoid it in the future. No student ever had it happen to them a second time.

One staff member fell for phishes at least 5 times, though. The president of the college had to talk to that individual eventually.