Your company is participating in a Cyber Security Education Program.


This Survey Phishing Attack included the following social engineering techniques:


  1. Corporate all hands email: (subject: "<Company> ... Survey.")
  2. Timing critical (example: by <date>.)
  3. From email name and fake email address using a service your company uses ("<service survey> (info@<service.com>).")
  4. Limited information provided to make you curious and entice you to click the malicious link.


How to spot this was a phishing email:


  1. Was this an email you expected to receive? No - Be cautious
  2. Confirm with management or human resources.
  3. Always review sender email and determine if suspicious (example: 2 email addresses exists)
  4. The primary domain (example: diopbox.com) is not associated with the survey company.
  5. This email was/may have been filtered and in your junk mail folder.


“An employee is either an asset to your cyber security or a risk.”