詳細検索

What is an effective part of phishing email training? Explanation of themes with high success rates

Avatar
by 菊池
3 min read

What is an effective part of phishing email training? Explanation of themes with high success rates
Translated from 日本語 • View original
菊池
菊池

Hello, I'm Kikuchi, an analyst at Colorkrew Security. Phishing emails are still the most common cyberattacks targeting businesses.


Especially in recent years, the spread of generative AI has improved the quality of writing, and it is no longer the era of "notice because Japanese is unnatural" as in the past.
In this article,

  • What kind of phishing emails are actually common?
  • What should the training email be about?
  • How companies using Microsoft 365 can easily conduct training

I will introduce them together.


Why HR-related phishing is the most common

What many security vendor reports have in common is that
"Human resources (HR)-related phishing is the most clickable"
This is the trend.

The reason is simple,

  • Salary
  • Rating
  • Attendance
  • Benefits
  • Internal Transfers

This is because there are many topics that employees are of high interest to.

In particular, the following subject lines have reported a high success rate in real-world attacks.

  • "I need to check my pay slip"
  • "We have received feedback on personnel evaluations."
  • "Request for attendance correction"
  • "Welfare points are expiring soon"

Because there are many attacks that take advantage of the mentality of employees "just opening up",
It can be said that HR scenarios are essential even in training.


Sample Phishing Emails That Can Be Used for Training

Below is a training sample based on actual attack trends.
You can use it as it is or arrange it a little.


(1) Human Resources (HR): Payslip Notification (Highest Success Rate) Subject: [Important] This month's payslip has been published


Example text:

This month's payslip has been published in the HR system.
After reviewing the contents, please contact Human Resources within 3 days if there are any issues.

▼Check your pay stub
hxxps://example[.]com/payroll/secure-login


(2) Attendance and shift system: Correction request subject: [Attendance system] There is a possibility of missing a clock


Example text:

The system detected a missed clock.
Please make corrections from the link below.

▼Attendance correction screen
hxxps://example[.]com/attendance/fix


(3) Accounting: Invoices and payment notices Subject: [Urgent] I have an unprocessed invoice


Example text:

There is one open invoice in the accounting system.
Please confirm as the payment deadline is approaching.

▼Check the invoice
hxxps://example[.]com/invoice/view


(4) IT Support: Password Expired Notification Subject: [System Notification] Password Expired


Example text:

Your account password will expire within 24 hours.
Please update from the link below.

▼ Update your password
hxxps://example[.]com/account/reset


(5) In-house tools: Questionnaire/survey request subject: [In-house questionnaire] Request for a survey on work style


Example text:

We conduct an internal questionnaire on work styles.
It will take about 3 minutes to answer, so we ask for your cooperation.

▼Answer the questionnaire
hxxps://example[.]com/survey


If you're using Microsoft 365, Defender for Office 365 is the easiest way to train

If you're a Microsoft 365 company, you can use the
Defender for Office 365's Attack Simulation Training is by far the easiest.

Features

  • Detailed reports such as click-through rate and input rate are automatically generated
  • Lots of real attack templates available
  • Visualize the risk score for each employee
  • Educational content after training can also be automatically delivered

In particular, templates are

  • Pay stubs
  • Password Reset
  • Invoice notifications

Since there are themes used in actual attacks,
A big advantage is that you can start training immediately without having to create your own email text.


Summary: Realism and Continuity are the Keys to Training

There are three key points for effective phishing training:

  1. Focus on the theme of attacks that are actually common (especially in the human resources industry)
  2. Rotate multiple patterns and implement them continuously
  3. Leverage Microsoft 365 attack simulation to be more efficient

To develop employees' "awareness skills",
It is most effective to have them experience realistic scenarios regularly.

Related Articles