Your company is participating in a Cyber Security Education Program.
This Vaccine Registry Phishing Attack included the following social engineering techniques:
- Topical subject to catch your attention (example: Vaccine Registry).
- "Employer" in <subject> associated with topical subject
- Fake "cc" for social proofing (example: approved by company "hr").
- Urgency to act (example: before their first visit).
- Most phishing attack emails have a sense of urgency.
- User name, employer name and address to personalize email.
- Spoofed domain which appears legitimate (example: gov.bc-en.ca).
- English and French included to appear government official communication.
- Logo to appear legitimate.
How to spot this was a phishing email:
- Was this an email you expected to receive? No - Be cautious
- Did your HR department advise this needed to happen?
- You should reach out to HR department to confirm.
- The sender named email address was suspicious (domain is not associated with the official government agency.)
- Brining up browser and typing in domain used isn't government agency (example: bc-en.ca)
- The link provided used suspicious domain similar to above.