Jump to content

Recommended Posts

Posted

Hi all,

 

Having a super fun day back today, one of my users has signed into a phishing email to retrieve a file from someone they know and has now sent out the phishing email to everyone in there address book, I have seen this happen before, suspiciously on Google Apps as well.

 

The problem that I am facing is trying to cut down on this, I have attempted to block the website it goes to however it changes every time, I cant block the file type as that changes every time as well, I have told all staff not to open the link and sign in but some of them are foolish.

 

Anyone experienced this before or have any experience with tying it down?

 

Thanks

Posted

Google have an extension called Password Alert that should help...

 

https://chrome.google.com/webstore/detail/password-alert/noondiphcddnnabmjcihcjfbhfklnnep

 

Password Alert helps protect against phishing attacks.

If you enter your Gmail or Google for Work password into anywhere other than accounts.google.com, you’ll receive an alert, so you can change your password if needed.

 

Password Alert also tries to detect fake Google sign-in pages to alert you before you’ve typed in your password. To do so, Password Alert checks the HTML of each page you visit to see if it’s impersonating a Google sign-in page.

  • Thanks 1
Posted

I'd also look in mail reports and use GAM to remove the offending email from all users inboxes - helps stop it spreading. Also ensure you are using DMARC - then most of these scams fail.

I'd also suggest getting staff to use two-factor authentication which also prevents this scam. I did a free blog posts on these things:

https://wpsit.blogspot.co.uk/2016/03/securing-google-app-for-education-gmail.html

https://wpsit.blogspot.co.uk/2016/06/delete-specific-email-using-gam.html

  • Thanks 2
Posted
I'd also look in mail reports and use GAM to remove the offending email from all users inboxes - helps stop it spreading. Also ensure you are using DMARC - then most of these scams fail.

I'd also suggest getting staff to use two-factor authentication which also prevents this scam. I did a free blog posts on these things:

https://wpsit.blogspot.co.uk/2016/03/securing-google-app-for-education-gmail.html

https://wpsit.blogspot.co.uk/2016/06/delete-specific-email-using-gam.html

Great, thanks very much for this, nice details!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...