Train operator phlunks phishing test by teasing employees with non-existent COVID bonus
- Reference: 1620719892
- News link: https://www.theregister.co.uk/2021/05/11/west_midlands_trains_phishing_drill_goes_off/
- Source link:
The deliberately inauthentic email first thanked staff for their hard work, then added: "We realise that a huge strain was placed upon a large number of our workforce as a result of COVID-19 ... and we would like to offer you a one-off payment to say thank you for all of your hard work over the past 12 months or so."
Readers were told to click on a link to register for their bonus, but those who followed instructions were sent news of their infosec failings and offered handy tips for the future like "be vigilant with all links and attachments" and "never click on a link that looks suspicious."
[1]
[2]
[3]
The email to employees from West Midland Trains rationalised the test with the following text:
This test was purposefully designed to closely mimic the tactics that, sadly, are being used on a daily basis by expert criminal organisations to try to gain access to company data and systems.
The Transport Salaried Staffs' Association (TSSA) [4]issued a statement in which general secretary Manuel Cortes called the cybersecurity-drill-gone-wrong a "cynical and shocking stunt." The union described the behaviour as "totally crass and reprehensible" and cited the many COVID cases and one death among the company's essential workers as evidence of management's insensitivity.
The event may end up costing the UK train operating company as Cortes has demanded the company make good and provide the promised bonuses.
Furthermore, while the "test" may have made it easy for the IT team to find security flaws, it looks like making plenty of work for West Midland Trains' crisis public relations team, although it appears they have not yet seemed to catch on.
Some of the jobs at at West Midlands Railway pay half the national average, a fraction of the pay of a senior director.
It's lazy & unethical to exploit low paid staff risking their lives in a pandemic with false promises of a bonus to check if your IT training is up to scratch. — Iain Collins (@iaincollins) [5]May 10, 2021
West Midlands Railway suggested if you are not happy with their response to date, or lack thereof, you can make a formal complaint online.
Hello. sorry you are not happy. I can see that you have read our reply as to why the email was sent out, however if you would like to make a formal complaint then please use the live feedback form as above or to receive an official reply, use [6]https://t.co/KzsifNQEtz — West Midlands Railway (@WestMidRailway) [7]May 10, 2021
The phishing test email claimed to come from the desk of recently appointed West Midland Trains managing director Julian Edwards.
Which just goes to prove the old saying that the phish rots from the head. ®
Get our [8]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJpVvXDtn2LhjHQ3amYXFgAAAFA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJpVvXDtn2LhjHQ3amYXFgAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJpVvXDtn2LhjHQ3amYXFgAAAFA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.tssa.org.uk/en/whats-new/news/index.cfm/anger-over-shocking-covid-bonus-stunt-at-west-midlands-trains
[5] https://twitter.com/iaincollins/status/1391777760364933121?ref_src=twsrc%5Etfw
[6] https://t.co/KzsifNQEtz
[7] https://twitter.com/WestMidRailway/status/1391764205968281602?ref_src=twsrc%5Etfw
[8] https://whitepapers.theregister.com/
"live feedback form"?
What's the betting that the link is actually another phishing test? They do say, “never click on a link that looks suspicious.”, what could be more suspicious than a link on a social media site?
Next test
Next security test will be an email saying "New staff competition - 10 lucky winners will get the chance to punch one of the management team in the gob. Click here to enter."
But isn't this what (real) criminals would do?
So are the unions seriously expecting IT Security to send an email out with a disclaimer at the end (in small print of course) so that the potential victims have a clue? That's not what phishing is about, surely, or am I missing the point?
Conversely, I would have thought that any email alleging to have come from train company management praising employees and offering money was suspicious in itself?
Re: But isn't this what (real) criminals would do?
I've never had to register for a bonus - I would hope that they haven't been asked to register before.
Exploiting current world events is a common tool, so this seems like a reasonable phish test to me.
Re: But isn't this what (real) criminals would do?
Yes, they would. I'm torn on this one... shitty trick to play, but well played in the theater of security. I'm sure the Lads from Lagos are taking notes...
What a dick move
Here is some money.. haha just kidding.
For phishing to be any use it has to look dodgy; contain spelling mistakes, a really obviously bad url. Should staff have known a bonus was beyond reality and that was the clue?
Re: What a dick move
...and a dodgy but plausible looking domain name.
E.g. the one my old man received recently...
vodafone.billing-center.com
This "phishing test" done by these cretins proved nothing other than their employees are underpaid enough to click a link to a fake bonus.
Re: spelling mistakes, a really obviously bad url
A good phishing email won't contain mistakes, and the link URL will be convincingly plausible.
Re: spelling mistakes, a really obviously bad url
Then there is nothing for staff to recognise and identify it as phishing. All you will get are lots of people failing the test.
Remember during phishing training they show a 'bad' email with an obviously bad URL and it came from an obviously fake domain? Well if staff don't see that then why would they suspect it?
An email that came from the director, from a valid looking domain, with a valid looking url and spelt correctly with legit content - why wouldn't staff click it?
Are you suggesting staff should report every email from senior management as suspicious?
Re: spelling mistakes, a really obviously bad url
Are you suggesting staff should report every email from senior management as suspicious?
Sounds reasonable to me!
Re: spelling mistakes, a really obviously bad url
A good phishing email balances on a knife edge. It needs to be sufficiently crap that someone trained to pick them out will automatically discard it without a second thought (perhaps not even open it) but plausible enough that an untrained individual will think it is legit.
This is why phishing emails always have typos or grammatical errors. It's a way of filtering down the targets without having to specifically target anyone.
Someone that can't easily spot the typos or grammatical mistakes is unlikely to spot that an email is a phishing attempt.
Lessons learned
If you're a phisher, offer anything that's related to Covid.
Re: Lessons learned
If you're a phisher, offer anything that's related to money.
FTFY
Don't click external links...unless they're ours
Our IT Security guys recently decided it would be a good idea to implement a new external domain to put all the security training on. They anounced this by sending an email from said unknown external domain, inviting us to click on a link to register using our internal domain credentials before taking part in the training. Many people reported it as a phishing attack, cue stroppy mail from IT Security berating us for being so stupid as to not believe their email that ticked all the boxes of being a phishing attack....
And the result of this test will be........
Email arrives in inboxes : "Dear team, please prepare full progress report of your work on big important railway project for meeting next week, The Boss"
Meeting starts.
"OK, let's start with progress reports - how is the track maintenance going?"
"Oh, I haven't done the report because I assumed it was a phishing email".
"Safety audit team?"
"Nope, we ignored the email too...."
Unfortunately,
Management have de-trained their employees. In pre-email times, you would not have expected to get any direct messages from the management, now they are spamming you every day, asking you to welcome new managers etc (don't think new managers appreciate getting their brand spanking new mailbox stuffed with 10,000 'welcome' messages from the grunts, so I've never seen the point of these).
Like the banks - "Oh, do be careful of spammers, you silly people" when most of them spent most of the last two decades (and some of them haven't stopped) phoning you up and asking you to "go through security" exactly normalising the behaviour they want you to avoid when anyone but them phones you up. All the time with the vast majority never coming up with any mechanism for proving that its actually them ...
If I get an email from management, and it exhorts me to click a link, and the email's not auto-flagged by our mail system, and the link is internal, I'm not going to click it. Not because I suspect it's a phish, and not because I suspect it's a trick, but because I'm already bored out of my mind doing my own job and don't want to be even more bored doing something that doesn't even help me get my job done.
What do they expect, phishers to send a nice header that says "THIS IS A PHISH!!!"
If they were using this as a screen to take disciplinary action against staff then it might be a bit rich but to identify areas for education tough, suck it up buttercup.
I've done the same exercises internally and had the same kickback, Unions insisting that we were "entrapping staff" despite there being nothing at the end of failed test except awareness training. Interestingly those who pushed back hardest against training were usually the worst at spotting them.
I'm aware of one organisation that was forced to alert staff that a test was being carried out.
Context missing
So, if the email and/or the link was obviously external I have less sympathy for the recipients. Well, I have sympathy on a personal level, obviously, but I don't think they have been treated unfairly. That is even more the case if the email was flagged by the mail system as a possible phish and they still persisted ... then even my personal sympathy starts to wane.
However, if the link is on the intranet that is, IMHO, a completely different story. You don't know the thought process the user goes through. "Hah, hah, this can't be true! *hovers link* Wow, what do you know? Maybe my company is following the example of Aldi, etc! *clicks*"
In the latter case, I think the recipient is completely justified in considering themself to have been mistreated by management. I think management would have to prove they had never, ever sent an email with a link to even have a chance of getting away with this, and I'll eat my riding hat if they can do that.
Also, any sensible management would have paid a small bonus anyway. "You're all getting an extra 20 quid, but you should have realised you wouldn't have to register for it - we know who's on the payroll ;-) Be careful not to click links! Love, management xx" - PR success instead of disaster and a phishing test that might actually get remembered.
More a test of critical thinking skills
I leave it to other commentards as to what it proved.
they had a cunning original (not) plan...
https://medium.datadriveninvestor.com/the-lesson-of-godaddys-fake-christmas-bonus-email-phishing-test-ede2d171f266