51
Shooting Phish in a Barrel and other terrible fish related puns...

Shooting phish in a barrel

Embed Size (px)

Citation preview

Page 1: Shooting phish in a barrel

Shooting Phish in a Barrel

and other terrible fish related

puns...

Page 2: Shooting phish in a barrel

Amanda Berlin@InfoSystir

Page 3: Shooting phish in a barrel

Stuff I do

@InfoSystir

Page 4: Shooting phish in a barrel

CompanyX Metrics

• +/- 2,000 employees

• +/- 30 sites

• Decent structure and security already

• Some c-level buy in

• No user education on security

• $1,000 budget

@InfoSystir

Page 5: Shooting phish in a barrel

First Phish

@InfoSystir

Page 6: Shooting phish in a barrel

First Results

• No warning

• Gathered with theharvester.py

• SET bombed out on me

• 50 emails sent

• 16 usernames/passwords = 32%

• 4 reports = 8%

@InfoSystir

Page 7: Shooting phish in a barrel

Second Phish

@InfoSystir

Page 8: Shooting phish in a barrel

Second Results

• 250 emails sent

• 54 usernames/passwords = 22%

• 4 reports = 2%

@InfoSystir

Page 9: Shooting phish in a barrel

Program

@InfoSystir

Page 10: Shooting phish in a barrel

Something Smells Phishy

@InfoSystir

Page 11: Shooting phish in a barrel

Phishing:

• is the act of attempting to acquire

information such as

usernames, passwords, and credit card

details (and sometimes, indirectly, money)

by masquerading as a trustworthy entity in

an electronic communication.

@InfoSystir

Page 12: Shooting phish in a barrel

CompanyX Hackers

• We’ll be putting on our hacker hats and trying to get you

to fall for our security tests.

• While we won’t be trying to gather your credit card

details, there are currently real hackers out in the world

trying to get every bit of information they can.

• They are the real bad guys and the whole point behind

this campaign

@InfoSystir

Page 13: Shooting phish in a barrel

Key Points to remember

• Don’t click on links in email.

• Don’t open attachments that you aren’t

expecting.

• Never give your username/password to

anyone.

• If it smells phishy REPORT IT!

@InfoSystir

Page 14: Shooting phish in a barrel

Things that should be reported

• Suspicious emails trying to get your

information (usernames, passwords, what

software we use, banking info, etc.).

• Suspicious emails with attachments that

you didn’t expect.

• People attempting to access your

computer that you haven’t authorized

@InfoSystir

Page 15: Shooting phish in a barrel

Contest Rules

• Phishing emails must be forwarded to the

helpdesk along with calling about

suspicious activity.

• Both internal (COMPANYX IT) and

external (real hacker) emails count.

• It is up to the COMPANYX hackers to

determine if the email is a true phishing

attempt or just spam.

@InfoSystir

Page 16: Shooting phish in a barrel

Contest Rules

• Other suspicious electronic activity may

count on a case by case basis.

• All COMPANYX email users except IS

department employees are eligible to win.

• Pseudo-random COMPANYX staff members

will be selected to draw winners.

• A person may not win twice for the same

drawing but is eligible to win in all other

drawings.

@InfoSystir

Page 17: Shooting phish in a barrel

Awards!

• Winners drawn from our “Phish Bowl” will win these phishy prizes!

• Monthly – Two winners drawn– Each unique phishing report results in one entry

– Drawings are held first regular business day of month for preceding month

– Both monthly winners will receive $10 Java City gift cards

@InfoSystir

Page 18: Shooting phish in a barrel

Awards!

• Quarterly – Two winners drawn

– First quarterly winner drawn will receive a $50

Bass Pro gift card

– Second quarterly winner drawn will receive a

$50 Red Lobster gift card.

@InfoSystir

Page 19: Shooting phish in a barrel

Awards!

• End of Year Grand Prize– One winner

drawn

– $300 Amazon gift card

@InfoSystir

Page 20: Shooting phish in a barrel

The Phish

@InfoSystir

Page 21: Shooting phish in a barrel

The most important part

@InfoSystir

Page 22: Shooting phish in a barrel

9 months of spreadsheets

@InfoSystir

Page 23: Shooting phish in a barrel

January Phish

@InfoSystir

Page 24: Shooting phish in a barrel

January Results

• 934 emails sent

• 322 usernames/passwords = 34%

• 103 reports = 11%

@InfoSystir

Page 25: Shooting phish in a barrel

February Phish

@InfoSystir

Page 26: Shooting phish in a barrel

February Results

• 567 emails sent

• 89 usernames/passwords = 16%

• 49 reports = 9%

@InfoSystir

Page 27: Shooting phish in a barrel

March Phish

@InfoSystir

Page 28: Shooting phish in a barrel

March Results

• 1095 emails sent

• 4 usernames/passwords = 0.4%

• 37 reports = 3%

@InfoSystir

Page 29: Shooting phish in a barrel

March Results, cont.

• First real phish caught and reported!

@InfoSystir

Page 30: Shooting phish in a barrel

April Phish

@InfoSystir

Page 31: Shooting phish in a barrel

April Results

• 1159 emails sent

• Goal was to look for reporting only

• 261 reports = 23%

@InfoSystir

Page 32: Shooting phish in a barrel

May/June Phish

@InfoSystir

Page 33: Shooting phish in a barrel

May/June Results

• Both external pentesting phishing attempts

• 41 emails sent

• 0 phished

• 6 reports

• 59 emails sent

• 1 phished (post test time period)@InfoSystir

Page 34: Shooting phish in a barrel

ZOMG IR

@InfoSystir

Page 35: Shooting phish in a barrel

May/June Results cont.

• 10:30 campaign begins

• 10:33 C-level dude forwarded email, and called

• 10:34 Regular user forwarded email

• 10:35 Regular user forwarded

• 10:41 I.T. dept was discussing null routing the IP address and blackholing the domain name

• 10:46 I.T. member forwarded the second version of the email

• 11:05 Director forwarded the email

• 11:20 Director forwarded the email@InfoSystir

Page 36: Shooting phish in a barrel

July Phish

@InfoSystir

Page 37: Shooting phish in a barrel

July Results

• 511 emails sent

• 15 people clicked through

• 8 reports

@InfoSystir

Page 38: Shooting phish in a barrel

August Phish

@InfoSystir

Page 39: Shooting phish in a barrel

August Results

• 402 emails sent

• 31 reports

@InfoSystir

Page 40: Shooting phish in a barrel

September Phish

@InfoSystir

Page 41: Shooting phish in a barrel

September Results

• 2264 emails sent

• 17 reports

@InfoSystir

Page 42: Shooting phish in a barrel

GRAPHS!!!!

0

200

400

600

800

1000

1200

1400

Jul-13 Aug-13 Sep-13 Oct-13 Nov-13 Dec-13 Jan-14 Feb-14 Mar-14 Apr-14 May-14 Jun-14 Jul-14 Aug-14 Sep-14

Hard Numbers

Emails Sent Phished Reported

@InfoSystir

Page 43: Shooting phish in a barrel

GRAPHS!!!!

0%

5%

10%

15%

20%

25%

30%

35%

40%

Jul-13 Aug-13 Sep-13 Oct-13 Nov-13 Dec-13 Jan-14 Feb-14 Mar-14 Apr-14 May-14 Jun-14 Jul-14 Aug-14 Sep-14

%

Phished % Reported %

@InfoSystir

Page 44: Shooting phish in a barrel

What I’ve learned

• Bi-directional positive response

@InfoSystir

Page 45: Shooting phish in a barrel

What I’ve learned

• Someone is always going to click

@InfoSystir

Page 46: Shooting phish in a barrel

What I’ve learned

• No one exempt

@InfoSystir

Page 47: Shooting phish in a barrel

What I’ve learned

• Getting the point across

@InfoSystir

Page 48: Shooting phish in a barrel

What I would change

• More formalized process for the

helpdesk/first line of defense

• More automation

• Add vishing/physical

• More measurements

@InfoSystir

Page 49: Shooting phish in a barrel

Stuff

• Infosystir.blogspot.com

– Email Templates

– Training Modules

– Meme posters

– “You’ve Been Hacked” phish response

– Awards program

@InfoSystir

Page 50: Shooting phish in a barrel

Other cool things

• https://www.trustedsec.com/march-2013/the-debate-on-security-education-and-awareness/

• http://ben0xa.com/security-awareness-education/

• http://www.csoonline.com/article/2134189/strategic-planning-erm/how-to-create-security-awareness-with-incentives.html

• http://www.irongeek.com/i.php?page=videos/derbycon2/2-2-7-benjamin-mauch-creating-a-powerful-user-defense-against-attackers

• Building an Information Security Awareness Program: Defending Against Social Engineering and Technical Threats – Bill Gardner & Valerie Thomas - http://amzn.com/0124199674

• Phishing Frenzy - http://www.phishingfrenzy.com/

@InfoSystir

Page 51: Shooting phish in a barrel

@InfoSystir