Your company is participating in a Cyber Security Education Program.


This Customer Complaint Phishing Attack included the following social engineering techniques:


  1. Legal/Urgent subject (Customer Complaint against you).
  2. Threatening language ("seriousness of the complaint").
  3. Directive of next steps ("read the allegations").
  4. Executive cc'ed to add authority to request.
  5. Company (Lawyer) logo to appear legitimate.
  6. Temporary link created (ex: ...law...) to appear correct.


How to spot this was a phishing email:


  1. Was this an email you expected to receive? No - Be cautious.
  2. The sender named email address was suspicious (signature block email does not match "from" email).
  3. You were not informed of complaint by your company's human resources department.


“An employee is either an asset to your cyber security or a risk.”