Do you ever feel like your employer is trying to set you up? Catch you in the act? Put you on a watch list?
Employees at the University of Pittsburgh, meet Sean Sweeney, your company-sanctioned scammer.
Over the past six months, Mr. Sweeney, Pitt’s chief information security officer, has perpetrated four email scams aimed at the university’s 11,000 staff and faculty. The scams are meant to simulate actual phishing schemes that bombard Pitt employees at a rate of five a week.
A phishing scam usually involves fake emails that appear to come from legitimate sources, like a vendor or an employer. They tend to either ask for sensitive information, such as passwords or account numbers, or they have a link or an attachment that, when opened, gives hackers access to information on your computer.
Phishing scams are up by 55 percent this year, Mr. Sweeney said, and 91 percent of all cyber security breaches start with a phish.
So in an effort to educate its employees about these attacks, Pitt started launching its own.
First, a warning: “If you fail, we’re going to wait a few weeks and we’re going to retest you with that same message,” Mr. Sweeney said.
So, yes. There is a list.
But it’s not punitive.
While Mr. Sweeney knows exactly which employees have fallen for the scam and which ones fell again during retesting — some 30 percent during a past campaign — he doesn’t disseminate that information to supervisors.
“We never want to shame them,” he said. “We all make mistakes.”
There are organizations that follow a punitive model — where falling for a phishing scam three times is grounds for termination. Some banks do that, he’s heard.
For Pitt, it’s not the way to go, Mr. Sweeney said.
“Phishing is social engineering. It’s playing on all of our instincts,” he said. “You’re not going to change behavior through fear.”
During Pitt’s most recent simulated phishing attack, about 14 percent fell for it. Another 8 percent reported the fishy emails to IT, which Mr. Sweeney said was great. “That’s plenty of actionable intelligence for our team to work on.”
When Pitt employees fall for a simulated phishing attack, they get an instant notification. Its main message is: Be suspicious.
Casey Canfield, a recent Carnegie Mellon University graduate who published a study on phishing scams this month in a journal called Human Factors, would add another missive: Be less confident.
Her study, done at CMU’s CyLab, tested participants’ ability to discern legitimate emails from scams and their confidence level at knowing the difference.
“People who were less confident were more cautious,” Ms. Canfield said.
That has implications for how to design anti-phishing strategies. “When you just give people information about phishing, you’re focused on getting people to tell the difference,” she said. “But this study shows the degree of caution is also important and may be easier to manipulate.”
So-called embedded training campaigns, such as the ones being conducted at Pitt, can help chip away at that confidence, Ms. Canfield said. That’s a good thing.
“It’s also kind of embarrassing. People don’t like that to happen to them,” she said.
It’s usually difficult for victims of phishing scams to see the consequences of a wrong click. Some are invisible — the click allows scammers to scrape information from the infected computer and disseminate it elsewhere. Some can show up in the shape of identity theft months later.
But a simulated phishing attack, with its immediate feedback, packs a punch.
Mr. Sweeney put it diplomatically: “When someone falls for a phishing message, they’re presented with a teachable moment.”
The oodles of data that Pitt collects from its simulations includes how much time people who fall for an attack spend reading the material they’re redirected to — 20 seconds or less.
Mr. Sweeney isn’t discouraged by that. That just means his team must design an education campaign that can be digested in 20 seconds — something like an image of a phishing email with arrows pointing to three or four suspicious elements and the reasons why they should raise alarm.
So far, Pitt has targeted faculty and staff with its simulations, but it may extend the efforts to the student population in the future, Mr. Sweeney said.
So be suspicious. Be very suspicious.
Anya Litvak: alitvak@post-gazette.com or 412-263-1455.
