This attack may have “looked more professional” than others, but there was a big red flag, too.
Here’s a good, albeit unfortunate, example from the Green Mountain State that demonstrates why it’s important to have refreshers in basic IT security protocols.
About 500 Vermont state employees were victims of a well-disguised phishing attack on Thursday that took the form of a fake Department of Human Resources website and asked them to fill-in sensitive W-2 tax form information like their names, addresses, Social Security numbers plus bank account information.
VTDigger.org reported Friday that the tax records of as many as 50 state employees were compromised in the phishing attack.
As DataBreaches.net points out, there was at least one big red flag that the employees should have seen as a potential problem:
Had the employees checked the From address, they might have been suspicious that it wasn’t from a .gov address, and the fact that so many employees fell for this one suggests the state needs a re-training session on phishing …
Richard Boes, commissioner of the Department of Information and Innovation, told VTDigger.org that the attack was “a little better than the other ones—it looked more professional.”
