Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

How Not to Teach Your Team About Phishing, Courtesy of GoDaddy

How Not to Teach Your Team About Phishing, Courtesy of GoDaddy

GoDaddy—the domain registrar and web-hosting company once famed for its risqué advertisements—is facing some significant backlash for a much different reason. On December 14th, GoDaddy’s employees received an email that appeared to be from the company, promising a holiday bonus. However, while the email was from the company as it appeared to be, it was actually a phishing test that the hosting provider decided to run.

Let’s consider the situation:

GoDaddy’s Phishing Message:

When they checked their email on December 14th, GoDaddy’s employees found an email waiting for them in their inboxes, sent from “Happyholiday@Godaddy-dot-com”. Upon opening it, they found the following message, under a large picture of a snowflake emblazoned with the company’s name and “Holiday Party.” Get ready, it’s a doozy:

---

Happy Holiday GoDaddy!

2020 has been a record year for GoDaddy, thanks to you!

Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus! To ensure that you receive your one-time Bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th.

US

EMEA

Any submittals after the cutoff will not be accepted and you will not receive the one-time bonus of $650 (free money, claim it now!)

We look forward to celebrating with you again, in person next year!

---

However, no bonus reportedly awaited the approximately 500 employees who excitedly clicked through the links. Instead, they received an email from the company’s security chief two days later, informing them that they had failed the phishing test and would therefore need to retake the company’s Security Awareness Social Engineering training.

As you can imagine, this did not sit well for many of these employees… especially considering that the “record year” GoDaddy experienced came only after hundreds of employees were either reassigned or laid off entirely. Combining that with the fact that a data breach ultimately exposed 28,000 of GoDaddy customers’ credentials earlier this year, and the comments seem especially ill-advised.

GoDaddy has since released an apology for their mean-spirited bait-and-switch phishing test, releasing a statement. According to a spokesperson, “GoDaddy takes the security of our platform extremely seriously. We understand some employees were upset by the phishing attempt and felt it was insensitive, for which we have apologized.” While the company felt that the lesson was an important one to impart to their team members, there has been some acknowledgement that this was an insensitive means of doing so.

GoDaddy Isn’t the Only Company to Do This

Other companies and organizations have used similar tactics as they have worked to evaluate their internal phishing preparedness. One example came in September, when Tribune Publishing sent out a company email trying to phish employees with the promise of a targeted bonus ranging somewhere between $5,000 and $10,000. The Tribune’s attempt was also derided by the employees affected by it, one reporter tweeting that the level of cruelty was “stunning.” That company also apologized for its use of a “misleading and insensitive” email.

However, Phishing Can’t Just Be Ignored

While these companies certainly took the wrong approach to educating their users, the point still stands that phishing is a very serious risk for businesses today to contend with.

Instead of taking this approach, there are other ways to help educate your team, through seminars or even other internal evaluations. The primary issue really came from the fact that GoDaddy took advantage of a monetary promise to their employees during a time when many people are already financially strapped, with seemingly no intention of giving them this bonus.

Obviously, this is a situation that nobody wants to find their organization in, just as nobody wants their organization to be phished. However, with Total Tech Care, there are ways to prevent the latter. Give our team a call at 866-348-2602 to learn more about how we can help you fight back against phishing, without alienating your employees.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 19 April 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Software Efficiency Network Security Business Google Internet Microsoft Email Malware Backup Workplace Tips Innovation User Tips Data Computer Mobile Devices IT Services Hardware Android VoIP Disaster Recovery communications Smartphones Communication IT Support Business Continuity Miscellaneous Smartphone Mobile Device Browser Small Business Network Collaboration Productivity Cybersecurity Quick Tips Users Business Management Phishing Managed IT Services Windows Upgrade Outsourced IT Ransomware Data Backup Windows 10 Cloud Computing Office Data Recovery Server Save Money Passwords Windows 10 Chrome Tech Term Virtualization Social Media Saving Money Holiday Gadgets Managed Service Microsoft Office Automation Managed IT Services Operating System Artificial Intelligence Facebook Computers Cybercrime Hacking Wi-Fi Health BYOD Mobile Device Management Networking Internet of Things IT Support Information Telephone Systems Information Technology Remote Spam Managed Service Provider Alert Covid-19 Office 365 Social Engineering Mobility Recovery Employer-Employee Relationship Router Bandwidth BDR Big Data App Password History Money Encryption Mobile Computing Applications Data Breach Human Resources Application Law Enforcement Remote Monitoring Managed IT Office Tips Apps Training Data Storage Patch Management VPN Remote Computing Government Mobile Office Blockchain Private Cloud Paperless Office How To Bring Your Own Device Data Management Work/Life Balance Infrastructure Wireless Voice over Internet Protocol Flexibility Marketing Gmail Vulnerability WiFi Windows 7 Word Settings IT solutions Google Drive Entertainment Website Budget Servers Two-factor Authentication Avoiding Downtime Mouse HaaS Data Security Remote Work Connectivity Risk Management Hacker Employee/Employer Relationship Cleaning RMM The Internet of Things Lithium-ion battery Conferencing End of Support Education Physical Security Scam Safety Firewall Data Protection Sports HIPAA Redundancy USB Virtual Reality Vendor Management Keyboard Apple Social User Error Vendor Managed Services Meetings Telephone System Staff Software as a Service Display Save Time Machine Learning Robot Data storage Excel Update Electronic Medical Records Automobile Spam Blocking Biometrics Hard Drive Virtual Desktop Google Docs Hiring/Firing Identity Theft Computing Infrastructure Virus Going Green DDoS Computing Unified Threat Management Computer Accessories SharePoint Battery Augmented Reality Shadow IT Fraud Legal Business Intelligence Remote Worker Customer Service Digital Signage Internet Exlporer Worker Audit Environment IT Management Cryptocurrency Printer Bluetooth Fax Server Botnet PDF IT Plan Procurement SaaS Workplace Strategy Comparison Net Neutrality Proactive IT Unsupported Software CES Help Desk Best Practice IT Consultant Printing YouTube Charger Network Congestion eWaste Business Technology Black Market Content Management Compliance Humor Access Control OneNote Computer Care Managed Services Provider Virtual Assistant Current Events Database Document Management Telephony Authentication Solid State Drive Wireless Technology Samsung Wearable Technology How to Downtime Remote Workers Retail Hard Drives Instant Messaging Value Processor Running Cable WIndows 7 Outlook Computer Tips Leadership Digital Signature Managed IT Service Troubleshooting Security Cameras Uninterrupted Power Supply Biometric Security Start Menu Warranty Virtual CIO Colocation OneDrive Memory Screen Mirroring HVAC Peripheral Loyalty Google Apps Frequently Asked Questions Digital Security Cameras Monitor Analysis Using Data Books 5G Mobile Administrator Windows 10s Devices Copiers Cast Enterprise Content Management Quick Tip User Tip of the week MSP Ergonomics PowerPoint Reputation webinar Accountants Science Windows Media Player Streaming Media Emergency Smartwatch Tech Support Employer Employee Relationship Credit Cards OLED Content Professional Services Microchip Public Cloud Thought Leadership Development Techology Password Management PCI DSS Laptop Assessment Password Manager Virtual Machine Distributed Denial of Service Managing Stress Windows Server 2008 2FA Customer Relationship Management Customers Fiber Optics Multi-Factor Security Employee Cabling Audiobook Tools Search Engine Twitter Messaging Analyitcs NIST Policy Programming Cameras Touchpad Television Business Mangement Hypervisor Dark mode Smart Tech Trend Micro Trending Amazon Default App Politics Advertising Addiction SMS Antivirus Procedure Public Computer Recycling Saving Time Regulations Wiring dark theme Practices Shopping Windows 8 Notifications Transportation Google Search Rootkit Amazon Web Services IT Infrastructure IT service Computer Fan Cache AI Safe Mode FinTech Printer Server Criminal Bing GDPR Relocation Workers Hosted Computing Social Network Tablet Benefits FENG Wireless Internet Online Shopping Investment Domains Video Games File Sharing Employees IBM Employee/Employer Relationships Smart Technology Specifications ISP IaaS Worker Commute Flash Camera Windows 365 Maintenance Inventory Wire Video Conferencing Bloatware Evernote ROI Experience Scalability Software Tips Sales Supercomputer Bitcoin Travel Shortcuts Millennials Cryptomining Business Owner Sync Printers Point of Sale Emails Personal Tablets Smart Office Supply Chain Management Entrepreneur NarrowBand Wireless Charging Search Monitoring Batteries Two Factor Authentication Workforce Virtual Private Network Windows 8.1 Shortcut iPhone Netflix Digitize Consultant Root Cause Analysis Cost Management Cables Windows Server 2008 R2 HBO Customer relationships Social Networking Analytics Knowledge Music Telecommuting Manufacturing Skype Project Management Email Best Practices Files Nanotechnology IT Assessment Best Available Data loss Chromecast Cortana

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code