My coworker clicked a link about a fake package delivery and now our whole office is locked out of email
Last Tuesday a guy I sit near at work in Columbus got a text saying his package needed a $2.99 redelivery fee. He clicked it, typed his work email and password into the page, and within 90 minutes our IT guy was running around telling everyone to change passwords. The link looked real too, it had the actual shipping company logo and a tracking number that looked normal. What bugs me is that he said he usually checks for weird sender addresses, but this came as a text from a number that looked local. Our IT guy said this kind of fake delivery text jumped way up over the past 6 months and most people click because they actually are waiting on a package. So my question is, what does everyone here do to spot these fast before you tap the link? I want a simple rule I can share with my team that does not take a security class to remember.
Oh man, that fake shipping text thing is brutal because everyone really is waiting on something. My simple rule for my team is this: never click a link in a text about a package, ever, no matter how real it looks. If you think it might be true, close the text and go to the shipping company's site yourself by typing the address, or check the tracking number straight from the store you ordered from. Same goes for email, if it asks you to log in somewhere, just don't, go to the site on your own and log in there. And honestly the local number thing fools people because we all trust a number that looks like it's from around here, but scammers can fake that easy. Tell your coworker not to feel too bad, it happens to smart people every single day.
Man, that rule about never clicking a link in a text sounds good until you ask how many people actually follow it when they are stressed. Here is my real question though: if your team gets a text from a local number saying a package is stuck, do they even stop to think, or do they just tap because they are expecting something? I ask because the part that got your office was not the link itself, it was him typing his work email and password into that page, and that is the step I want to block. So what do you tell people to do in the ten seconds after they already tapped, since that is the moment that actually costs you?