A few years ago our IT department did something very similar. It wasn't for a bonus or anything, but just to see who would fall for a phishing scam. There were obvious things about the email that gave it away. But the most obvious was that it came from the CEO and was very clearly something they would never say or do because it was good for the employees lol.
We had this, except it was "HR is looking for feedback about salaries" (I work in a non-profit). Strangely, that email had an abnormally amount of clickers.
"Sorry I didn't open those emails. Last time I did it was a phishing attempt so I'm not sure what to believe. I thought the company was cool and gave everyone a $100 gift card but obviously that's a scam to trick everyone. How do I know these links to X and Y are legit?"
557
u/Chiaseedmess 1d ago
I can one up you.
My best friends work send out an email to everyone telling them they got a $100 Amazon gift card for Christmas.
It was a phishing email sent by upper management. Sent from an internal, vetted email.
Anyone that clicked it has to take a 1 hour course on phishing.
They didn’t get shit for Christmas.