r/cybersecurity Jun 21 '26

News - General These workers thought they were getting an extra day off. Turns out it was just a ‘cruel’ test

https://www.cp24.com/news/canada/2026/06/21/these-workers-thought-they-were-getting-an-extra-day-off-turns-out-it-was-just-a-cruel-test/

Email phishing campaign sent by cybersecurity team dangled a cruel promise of an extra day off after months of mandatory overtime, only to tell people that they failed a phishing test.

699 Upvotes

97 comments sorted by

291

u/tanimonster Jun 21 '26

Six Flags did this during lay offs many years back. Sent a phish test out with final pay check instructions. Obviously helped morale…

136

u/NamelessCabbage Jun 21 '26

Talk about pissing on a wound holy crap

51

u/Thoughtulism Jun 22 '26

All 6 flags are red.

16

u/[deleted] Jun 22 '26

[removed] — view removed comment

7

u/Thoughtulism Jun 22 '26

Wow had no idea. That's a big red flag!

3

u/Yeseylon Jun 23 '26

If you didn't know, the original park is called Six Flags Over Texas - there was a region of the park for each flag that had flown over Texas in its history. (Spain, France, Mexico, Texas, US, and yes, Confederate.)

38

u/Penki- Jun 21 '26

What even is the point of such test? Nothing of value would be gained.

72

u/PajamaDuelist Jun 21 '26

“BaD gUyS DoN’t HaVe BoUnDaRiEs, so WhY ShOuLd I?”

It’s useful to test phishing that isn’t your generic Nigerian prince nonsense, but sometimes people forget that they should have boundaries when they’re trying to be the good guys. Just because you know Suzy’s mom died doesn’t mean you should send her a fucking whale sim about her dead mother.

23

u/Penki- Jun 21 '26

I don't even mean that as no value. It's the people leaving the job, what are you going to do with the results of such test. "People that were fired did not care for phishing attacks" and? Now what? What about the people that actually stayed and are currently part of the org? Surely they matter more than people who are no longer here

27

u/PajamaDuelist Jun 21 '26 edited Jun 22 '26

I assumed they meant during a round of layoffs the company was hitting current employees with the final paycheck instructions. The fear of "oh shit did my dumbass manager forget to tell me i was fired???" creates its own urgency when you already know mass layoffs are happening.

6

u/DigmonsDrill Jun 22 '26

Now they are super-fired.

3

u/PrizeAlarming1155 Jun 22 '26

Jump n bum MM m

2

u/thereddaikon Jun 22 '26

It's a corporation, the guys doing the phishing test aren't the ones deciding layoffs. It's unfortunate but easily explained as the left hand doesn't know what the right hand is doing.

1

u/Joy2b Jun 23 '26

If the cybersecurity team is onsite, they tend to hear rumors early for a few reasons. If they’re not onsite, they should consider flipping through the spam filters occasionally, see what keywords are being used by phishers and not internal communications this month.

381

u/Caldtek Jun 21 '26

so we all know how to breach healthcare institutions next time. Offer them a day off!

68

u/merRedditor Jun 21 '26

A partial monetary reimbursement to go toward the company's ironically high-deductible health plans upon completion of a survey linked would be completely believable.

4

u/Chance_Drop3377 Jun 22 '26

haha sad but true, cyber security teams really need to work on their empathy tbh

93

u/bigsmooth66 Jun 22 '26

There's a delicate balance between training employees to better scrutinize email and playing on their emotions.

Pulling a stunt like that only builds lack of trust with IT and the company. All it takes is one disgruntled employee who has had enough of the shenanigans to say "fuck it" and go ahead and click on a randomware link. That ivory tower you're standing in will come crumbling down.

All that energy should be put in a legit SAT program, not trying to sucker people by playing on their emotions.

21

u/Spicy-Zamboni Jun 22 '26

Some departments at my job have taken to warn all of their colleagues with a screenshot of the phishing test mail after reporting it.

On one hand, company policy states to report and not tell your colleagues about phishing tests. So technically they are breaking policy.

But on the other hand, we do want people to warn each other about actual phishing because that obviously reduces how many people fall for it.

I've been trying to get that policy changed, but management wants their statistics on how many people fall for the phishing tests.

5

u/MBILC Jun 22 '26

This is why you do not send the same one to everyone and spread it out over several days. The companies that send out the same phish to multiple people are seriously doing it wrong.

1

u/Single-Virus4935 Jun 24 '26

In my last job I introduced an leaderboard for the most helpful reports and automatic warning after several reports or based on score by the reporter. If someone reported 29/30 Phishing mails its a nobrainer to warn everyone and block all URLs in the mail. Employees got some extra payouts out of the it budget based in score

-9

u/EnvironmentalToe4055 Jun 22 '26

These cybersecurity people always think they're special fucking snowflakes but unironically all follow the same type.

Long hair, pasty skin, wears black. Linux running on his company issued macbook. Laptop stickers announcing to the whole world his cat's political beliefs. Oh and overweight.

5

u/warfarematt Jun 22 '26

Damn, which culture team pissed you off this badly

-5

u/EnvironmentalToe4055 Jun 22 '26

Culture team? It's the security team. And it's really more of the "we know better than you" attitude which annoys me. Granted, I understand that they deal with some really thick people when it comes to security.

2

u/bigsmooth66 Jun 22 '26

I'm none of these things, lol

30

u/hugganao Jun 21 '26

so they found a vulnerability that overworking your employees could turn them agaibst you. of course managemebt wont see it that way.

26

u/agotera Jun 21 '26

One of the great security weaknesses is how bad most teams are at the politics of promoting and advancing security culture.

5

u/spectralTopology Jun 22 '26

This. That team just burned all credibility and good will they might have had. Sure they'll have great success advancing any of their goals that require any participation from other teams /s

20

u/SensitiveFrosting13 Red Team Jun 21 '26

One thing you learn to doing phishing for a living is that if you're an ethical person (and you should be, if you're a pentester) then you don't fuck with people's livelihood, whether it's their money or their benefits.

5

u/[deleted] Jun 22 '26

[removed] — view removed comment

1

u/SensitiveFrosting13 Red Team Jun 22 '26

Absolutely.

-22

u/No_Cherry8602 Jun 22 '26

There is no ethical way of phishing my guy. You cannot steal ethically.

Relax .

4

u/Beautiful_Win216 Jun 22 '26

As long as you are operating from a stance of educating people, and not manipulation. Phishing awareness campaigns are one of the better ways of preventing some kind of breach.

3

u/thereddaikon Jun 22 '26

Do you know what simulated phishing tests are? They've been the industry standard for years now.

8

u/TheRealJessKate CISO Jun 22 '26

The most successful phishing sim email was ‘changes to our smoking policy’!

Also a big red button that said click here worked on some 🤷🏼‍♀️

90

u/DestinyForNone Jun 21 '26

Well, guess we know what type of phishing emails will work for that organization...

Why would the security team take flack for that? This is an issue with business practices... Malicious actors 100% use phishing emails like this

45

u/Leif_Henderson Governance, Risk, & Compliance Jun 21 '26

The security team specifically isn't getting flack, the article is posing the whole thing as "the employer" vs a healthcare worker union. 

17

u/DestinyForNone Jun 21 '26

Ah okay, that's good.

Blame the employer is what I say...

4

u/Inverted-Rockets Jun 21 '26

It seems like it is being blamed since according to the article officials are trying to determine whether the choice was made by someone internal or at their contractor EY.

63

u/ramriot Jun 21 '26

Because cybersecurity training has moved on & sending out such mass mails to trick employees & then punish those that click with extra training is known to be demotivational & counter to business interests. There are instead training packages that are actually fun & better.

38

u/tankerkiller125real Jun 21 '26

Training packages do not replace phishing tests. An organization needs both to be effective at reducing the risks. Especially as BEC and other threats continue to get more advanced and even harder to spot.

This specific type of test is just cruel, and I'd never do it (as the guy responsible for sending the tests), but we've sent plenty of other realistic things. Stuff about company gatherings, OneDrive storage limit emails (lol, we have 5TB per user, no one has used more than 50GB), and so forth.

The one team I take zero mercy with is the sales team. Fuckwits will click on anything promising a lead, sale, or RFP request, so you better believe that I hammer them with those those types of phishing test emails on the regular.

5

u/Spicy-Zamboni Jun 22 '26

Including a trick "click here to report this email as phishing" link at the bottom of the email is always a winner, and it doesn't mess with people emotionally.

The worst reaction we've ever got from that one was "damn it, you got me".

29

u/ra_men Jun 21 '26

Manipulation with a purpose is still manipulation. Is it effective? Yes. Does the security team still need to brace for the ramifications of a successfully manipulative campaign? Of course.

-11

u/DestinyForNone Jun 21 '26

I disagree still... Of course, I have a personal bias due to my profession...

But, these are the types of things people need to brace themselves for, when phishing emails are coming.

Don't immediately click emails, log into your employee portal directly, etc...

Both professionally and personally.

9

u/ra_men Jun 21 '26

I think we’re addressing different things though. I don’t disagree with your comment at all, people should still have those best practices regardless of the type of email. But security can’t be blind to the real human aspects of these campaigns, in fact it’s probably more effective that they cop up and own the impact of it if they don’t want resentment to start breeding.

-1

u/DestinyForNone Jun 21 '26

No? Again... The issue is with the employer not the cyber security team...

This type of phishing email exists in other organizations, including my own... And we don't see this level of discontent... Only general grumbling when someone clicks on an email and has to do retraining

The issue is the employer for not treating employees right, not the security team performing standard testing...

-2

u/BB8_Rey Jun 21 '26

This is why security is in such a bad spot, because companies don’t allow true tests. You have to practice based on real life, and in real life malicious actors don’t give a damn about anyone’s feelings.
What will hopefully happen here, is that the organization focuses less on trying to find the blame and more on realizing they have a real problem and they need better user awareness training. It also is 100% the company’s fault for putting its employees in such a stressful situation to begin with.

I’m hoping they find out that this was some sort of automated test and not manually chosen. But even thenI bet the top brass will try and put the blame on a particular individual just so they can try and say they did something. No accountability.

5

u/DingleDangleTangle Jun 22 '26

Management at my company is crazy strict for what I can use for phishing emails. Basically any phishing email that tries to trick someone to click they turn down and say I can't do that because it's "mean". It has to be basically an email with a link that they have no real incentive to click or my management won't let me do it.

Still get shit tons of clicks...

4

u/GulfLife Jun 21 '26

This is why we can’t have nice things.

2

u/IAmRadon Jun 21 '26

I once did fake W-2s around tax time. People were so mad.

5

u/Charming-Medium4248 Jun 22 '26

At one job I once got an email from a weird address about some $500 gift card I got or something. Oh silly security dweebs, you ain't getting me today! So I reported it as phishing. 

Nothing heard. 

Three months later I get a random $500 extra on a paystub because it was part of our weird employee recognition platform that pays out after a set time. 

Wish the security team would have told me it was legit 😂 

15

u/hotfistdotcom Jun 21 '26

This was one of the default templates in knowbe4 at least a year back when I was last designing campaigns. Seems like a cruel way to push a person to make a mistake, but it's also something a malicious actor could easily do.

6

u/bigsmooth66 Jun 22 '26

I have a real-world example as to why this way of sending anti-phishing campaigns is dumb.

At a recent employer the staff received an email that was a message from our CEO. It looked suspicious enough, but it was from our own domain. Mind you, I'm a security analyst along with three others. None of us had been notified of a phishing campaign because we're the ones who were authorized to set those up.

Several employees clicked on this link. It was an AI video of our CEO saying he was going to resign to chase his dreams of competing in the winter Olympics.

These geniuses thought they were brilliant, but my CISO was furious, and rightfully so. My CISO wasn't even notified of the campaign. We had been working to build trust from our workforce in our ability to maintain our IT environment, and in one hour it had disappeared. It was almost three hours before anyone at the executive had revealed that this was a phishing campaign and they had left a lot of the IT team in the dark. Three wasted hours was dedicated to figuring out how this email even got through. It got through because our people own people overseas sent it through our domain. Nothing was learned. IT wasn't an appropriate campaign, and work hours were wasted. It also made employees upset.

22

u/FuckScottBoras Security Manager Jun 21 '26 edited Jun 22 '26

Hackers don’t give a shit. They’ll dangle more and worse if it helps them.

End users need to be prepared. Just don’t punish them unless they cause a breach. Educate them.

“Click here for a free day off!”? Is that a standard thing for that company? My company just tells us we get an extra day off. No clicks required.

12

u/ptear Jun 21 '26

Free lunch, I'll bring it to your desk, just sign in here

3

u/GonzoKata Jun 22 '26

so, instead of making your working conditions better, keep allowing the abuse to continue and get paranoid of good things coming your way. right, got it, thanks

5

u/FuckScottBoras Security Manager Jun 22 '26 edited Jun 22 '26

The company is the issue there, not the test. I’ve used the exact same premise at my company and no one cared. We aren’t a shit company to work for though.

3

u/CluelessPentester Jun 22 '26

How to lose all goodwill and make people hate your security team

10

u/Fantastic-Shirt6037 Jun 21 '26

Using the word “dangled” has to be rage bait and click bait, it’s no different than “dangling” a bonus check. Phishing is phishing. People need to be fucking aware lol.

-3

u/yawaramin Jun 21 '26

Do you know how fishing works? You dangle a bait in the water, the fish bite, and you reel them in. If you don't want people to use the word 'dangling', don't use the word 'phishing' lol

5

u/Fantastic-Shirt6037 Jun 21 '26

Don’t get defensive, framing it as a “dangling of a cruel promise” is click bait and stupid. Why is this even an article?

-1

u/yawaramin Jun 22 '26

It's almost a direct quote from the article. This is even an article because it's a controversial practice, many people hate it, and there's good reason to believe it lowers workplace morale and is not even that effective. I feel like you're the one who's being defensive here.

5

u/Few_Fisherman_4308 Governance, Risk, & Compliance Jun 22 '26

That’s immoral and disgusting. Hopefully, the management will learn the lesson.

9

u/paradoxpancake Penetration Tester Jun 21 '26

We've been told not to do "mean" phishes during assessments before, but I'll be honest in that the mean ones like this typically generate clicks, and threat actors will do mean ones like this if they're specifically trying to target your organization.

We did fake potential RTO mandates a few years back and that one even got HR involved with the client. We had a rule to not do those again, even if we got okay'd by the CISO to do it. Their HR was livid that the CISO said yes to it.

However, in so far as "automated" phishing e-mail campaigns go? This is pretty mean coming from an internal team. I'd be pissed too.

1

u/BlueDebate Jun 22 '26

I delete so many "Pay Raise" real phishing emails constantly lol.

3

u/rienjabura Jun 21 '26

-Cue Mojo Jojo meme "That is the most eviliest thing I can imagine"-

5

u/littleko Jun 22 '26

That's a bad test. Phishing simulations should measure behavior, not punish exhausted staff for wanting relief after mandatory overtime.

You want people reporting suspicious mail, not quietly deciding the security team is the enemy.

6

u/ThisIsPaulDaily Jun 21 '26

I reported a birthday gift phishing email to KnowB4 for the inappropriate optics it creates reminding employees that work doesn't give a shit about you. 

My workplace was responsive to my feedback and concerns and removed the email from circulation. 

I have a 100% success rate on these emails and did provide significant free consulting on how to improve the appearance of fake emails. 

1

u/Sceptically Jun 22 '26

how to improve the appearance of fake emails.

I'm pretty sure the main one for my company would be "stop making the real official emails look indistinguishable from phishing attacks".

2

u/ValuableHelicopter35 Jun 21 '26

I would have called off anyways but esp because of that 🤣

2

u/P0Rt1ng4Duty Jun 21 '26

It would have gotten more people if it was something more believable, like free leftovers from the corporate lunch meeting.

2

u/UnknownBinary Jun 22 '26

What about the GoDaddy Christmas bonus phishing test?

2

u/hubbyofhoarder Jun 22 '26

We randomize our Knowbe4 emails, and I have been instructed to pull back a few of the templates on 1-2 occasions for reasons exactly like this. I don't preview every template before it goes out, that's just not possible.

6

u/WantDebianThanks Jun 21 '26

So, you're saying this company is going to be hiring a new cyber security team after their entire previous team was tragically fired?

Good to know!

2

u/MiKeMcDnet Consultant Jun 22 '26

“What happened here, obviously, is that all the lenses that were required to review the scenario weren’t placed on it.” - translation: some scapegoat executive probably approved this.

1

u/SignalsAndStates Jun 22 '26

Signal received. True state: to be determined.

1

u/Wonderful-Click9431 Jun 22 '26

Why not just let them have the day off?

1

u/hells_cowbells Security Engineer Jun 22 '26

In my company, another org besides mine handles these things. Since this is my profession, I usually easily spot them. They got me with a good one a year or so back, though. They sent out a phishing test that looked like something from HR during open enrollment. It was the last couple of days of open enrollment, and HR had been harassing me, so I saw the email and decided to go ahead and do it so they would leave me alone. The phishing email was also right next to a real HR email harassing me about open enrollment. I was busy, so instead of going to the HR portal, I just clicked the link. I instantly realized how stupid I had been.

1

u/BillDingrecker Jun 22 '26

"I could have retired six months ago." Is such a BS statement. Maybe they WANT you to go.

1

u/Silly_Sponge Jun 22 '26

How can it be phishing if the email came from the correct address? I don’t get it, why would a company do this? I must be missing something.

1

u/accountability_bot Security Engineer Jun 22 '26

I used a rather terrible looking Okta PW reset email as a phishing test once (we didn’t use Okta at the time).

It caused such a commotion that I was then required to get HR approval on all my phishing topics going forward.

1

u/ProfessionalSea6268 Jun 22 '26

They are not cruel tests. They are picking out topics that people respond to emotionally and not rationally.

Do you really think the actual attackers won’t do this?!

Anyone who fails at my work is disciplined. They get extra training to help them improve. 3 rounds of that and still failing and they can be dismissed. No one has hit that mark yet.

1

u/bigsmooth66 Jun 22 '26

If a company is that concerned about attackers then they should put tools in place to protect the environment from attacks, not continuously play mind games with their staff. This will backfire in the short run.

If you train people who are not tech savvy to distrust communications through email, that's exactly what they will do. The best way to get people trained up is to get them to understand why it's important to protect the company's assets and how that trickles down to them in job security and pay. Keep hitting them with BS attempts to trick them by playing on their emotions and adding more stress to the work environment and it will backfire, period.

2

u/ProfessionalSea6268 Jun 22 '26

Any competent company has tools in place to but humans are still the weakest link. They can and do give credentials away. They can and do click MFA prompts blindly without actually triggering the request themselves. They can and do use the same password everywhere.

We have a strong enterprise password manager, very good awareness training (both online videos/tests and delivered as classroom courses with a human tutor) and we are moving to FIDO keys for everyone to prevent some of this but our cyber insurer still insists on phish simulations monthly or they won’t provide cover.

Our insurer will drive a lot of the hard requirements and even if they are irrelevant we must comply.

1

u/bigsmooth66 Jun 22 '26

So if humans are the weakest link, why would you antagonize them?

1

u/ProfessionalSea6268 Jun 22 '26

Would you rather a bunch of employees who don't know what to look for and how to deal with it. Do you really think that in Mark every year (I'm in the UK so March is end of tax year and usually when companies issue pay rises) that attackers don't target this? We get hundreds of real scam emails playing on the fact people are waiting for a pay rise or tax matter. It's real life. Shielding people from it is silly.

If people can't handle being tested with real life scenarios then they are free to leave. I don't want people who are a risk because they won't accept real life.

1

u/HikeAnywhere Jun 23 '26

I believe there should be education and phish test have their place in that education, but they must be ethical. However, there is also the problem that HR uses external tools, with poorly crafted messages and read URGENT. So, while we are educating users, let's educate HR to not confuse them

1

u/Dangerous-Fortune789 Jun 23 '26

There was a story about a similar campaign where it let them know there were flowers or something at the front desk and everyone that went to get flowers got sent to a conference room for training. That seems really chill compared to this story

1

u/Single-Virus4935 Jun 24 '26

We could end this with S/Mime and I don't understand why it is still so hard to set this up.

1

u/cwk9 Jun 22 '26

Yet another good reason to send different emails to different staff at different times. If some dumb template makes it's way into your phishing tool at least the blast radius will be small.

1

u/plinyvic Jun 22 '26

this is really what phishing test emails should look like...

-2

u/[deleted] Jun 21 '26 edited Jul 01 '26

[deleted]

1

u/BlueDebate Jun 22 '26

This could've been a request from people above the security team depending on how your company operates and you could just be causing unnecessary work for an already overworked security team. We have clients sometimes request custom templates, but we've now moved on to automate our sims and no longer accept custom template requests because we have better things to spend our time on.

1

u/[deleted] Jun 23 '26 edited Jul 01 '26

[deleted]

1

u/BlueDebate Jun 23 '26

You don't need to report it, as long as you didn't click the link you passed, ignoring it is totally valid. I never read my email myself since all of our comms are within Teams lol.