According to a recent phishing attack, hackers trick employees with training notifications nowadays. The attack was carried out using social engineering. So, the hackers took their first steps by sending phishing emails to employees about cybersecurity training.
How did hackers trick employees with training notifications?
In the phishing email, the hackers sent a notification encouraging employees to complete their cybersecurity awareness training. Hackers said in the email that they could easily complete the training by clicking the embedded link. However, if employees clicked the link in the e-mail, they were directed to a fake site. On this site, hackers were asking employees for passwords and personal information linked to their e-mail addresses.
Another remarkable detail in the e-mail is that the hackers highlighted the urgency of the situation. The hackers emphasized in the e-mail that employees only have one day to complete the training and that they should complete the training urgently by clicking the link. This emphasis on urgency, one of the most used methods in social engineering attacks, is the common point of all phishing attacks we have seen recently. So, this is very helpful to hackers. Because it leads many users to make decisions without thinking.
Also, in the e-mail, the hackers stated that the training could only be completed through this e-mail and that it was not available on other sites. That’s why employees clicked on the link.
Hackers Trick Employees With Training Notifications: What to Do Next?
With this development, the coverage area of phishing emails seems to have expanded considerably. Now, hackers can even use anti-phishing measures in their phishing attacks while planning their scams. Therefore, no company or organization can protect itself 100% against phishing attacks, no matter how many measures it takes. Phishing campaigns can catch you anywhere, in any condition. Therefore, organizations that conduct their business over the internet are highly vulnerable to these phishing attacks.
Research shows that you can still find the links hosting the attack on frequently used websites. Through these websites, hackers get the opportunity to upload attack links and edit the information they capture. So, companies now need to be much more careful to protect against phishing attacks. They should take many new measures for this. Adding the subject of fake education notifications to cyber awareness training is one of them.
Measures You Can Take Against Hackers Tricking Employees With Training Notifications
1. Use phishing simulations to make sure your employees know what to do in case of an attack.
There is a substantial increase in phishing attacks. Therefore, phishing has become a significant issue to customers and organizations around the globe. So, monitoring your workers with simulated phishing exercises is crucial. Our phishing simulation tool helps you to easily and intelligently measure and monitor human activities by sending your employees phishing threats, tracking their behaviors, and gathering data. The results help you take precautions.
2. Scan the web for anything suspicious with cyber threat intelligence tools.
The Threat Intelligence tool searches the websites to look for signs and information that could be a violation of your data and a danger to your company. Also, the Threat Intelligence tool provides you with continuous monitoring of a system. This way, you can shorten the time between the actual violation of data and the protective reaction. This helps minimize the risk of malicious activities. The tool regularly searches well-known hacking and breach pages. If there is financial records, credit card information, personally identifiable information (PII), IP/Domain addresses, contacts, passwords, usernames, and information relevant to your company, we immediately report it to you.
“This post is originally published at www.phishing.org.uk”

Teknoloji Haberleri
- Google'ın son adımları, önemli sitelerin batmasına mı neden oluyor?ABD'de hizmet veren online ödev sitesi Chegg, Google'ın arama sonuçlarındaki bilgi gösterimlerinin site trafiğini ve gelirlerini düşürdüğünü iddia ediyor. Eğer mahkeme aynı fikirde olursa, teknoloji devlerine milyarlarca dolar tazminat cezası yağabilir.
- Razer Viper V3 Pro İncelemeRekabetçi oyunlarda hızlı hareket eden, hafif ve yüksek DPI değerlerine sahip özel oyuncu fareleri büyük avantaj sağlıyor. Peki Razer’ın yeni oyuncu faresi Viper V3 Pro oyunculara bu imkanı ne kadar tanıyor?
- PlayStation 5 Pro satışları, beklentilerin gerisinde kaldıSony, Microsoft ve Nintendo konsol satışlarında büyük düşüşler yaşıyor. Yeni PlayStation 5 Pro ve diğer konsolların son durumu haberimizde...
- Bir devrin sonu: Microsoft, Skype'ı kapatma kararı aldıBaşarılarla dolu koca bir 22 yılın ardından, Microsoft’ın popüler yazılımı Skype sahneyi tamamen terk etmeye hazırlanıyor. Peki, yazılım devi neden böyle bir karar aldı? Skype’ın sonunu hazırlayan sebepler neler?
- Yapay zeka ve Radyo Erişim Ağı simbiyotik ilişkisi telekomünikasyon sektörünü nasıl değiştirecek?Telekomünikasyon dünyası, yapay zeka (AI) ile Radyo Erişim Ağları’nın (RAN) birleşimi sayesinde büyük bir dönüşüm sürecine giriyor. Peki, bu nasıl olacak?