Your email looks like phish

And it'll get deleted

I got an email last week from my college at Oxford.

Or, at least, it claimed to be from my college. It was a “hey, we want to make sure we keep in touch; update your data” type email.

And so I looked at the link and it went to some odd AI-looking chat form.

Which got me wondering.

The email was sent via mailchimp. The form was some random site I’d never heard of before and asking me for personal information (eg date of birth).

Yeah, that’s not good. There is no way that I could confirm this actually came from my college and not phish.

People are being trained to be cautious

Business Email Compromise is one of the main ways that attackers can scam a person. We’ve all seen fake invoices, fake FedEx notifications, fake PayPal receipts; they look like the real thing and even use elements (e.g. images) taken from the real websites but they’re total scams.

Because of this a lot of employers are performing cyber “training”. And, of course, in regulated industries (e.g. finance) there may be mandatory yearly training requirements. I’ve lost count of how many of these I’ve had to do over the past couple of decades. And then there’s “phishing tests” that companies do to see how many people will click on random links.

You can argue about how good the training is, and how useful these tests are, but the end result is that people are more aware that what you receive as an email isn’t necessarily what you think it is. Maybe not all of the people, but some :-)

So when I receive something dodgy like this I see a number of red flags and am disinclined to follow the link and participate.

Corporate departments make the same mistake

I’ve worked for megacorps and even they make the same mistake. Especially, it seems, the HR department. I’ve received a number of emails that claim to be from corporate HR that actually originated from outside of the company and that linked to forms that were outside of the company.

Again, there was no way of telling that this was a legitimate. Indeed a few times the automated email security tooling added a warning flag along the lines of “This email originated from outside the company; be careful when clicking any links”.

So, on the one hand, we have a lot of money being spent training people to be careful of emails and on the other hand we have money being spent sending exactly those emails we’re training people to be careful of!

Yeah, that’s a head-desk moment.

Don’t do this.

What I’ve seen some HR departments do is send out a pre-campaign email saying things like “we’re gonna do this survey, you’ll get an email from some random company name that you’ll forget straight after reading this; it’s OK you can trust it.”

Can you tell I’m sceptical about how well that works? Basically they’ve opened a window of vulnerability where people are being told to drop their guard and click on stuff.

What they could have done

In this case, I checked with my college via email and it turns out that this was legitimate. But how could I tell?

Now mailchimp is a well known company used for sending marketing email. And it also has a reputation for not really vetting their customers that well, so they also have a reputation as a spam source and have a bad reputation.

And the company handling the form looks legit, but that doesn’t mean their customers are.

What would have made things a lot clearer (and this will also work for corporations) would be to have the email linked to a static landing page hosted on a web site already associated with the company (so the official college web site, the internal HR website, the internal corporate home page website…).

This landing page doesn’t even need to be clever; just a static page saying something like “thank you for agreeing.. blahblah. This survey is being run by blahblahblah on our behalf. Click the big green button to start”.

This still isn’t perfect (a hacker could theoretically have hacked the site, or it could be a typo-squatted similar site, or a homoglyph site). But it doesn’t have to be perfect; it just needs to add a level of comfort that would have allayed my fears that this was phish. The same commercial mail sender, the same form submission site, all the same backend processes… nothing would change except for this one intermediate landing page. And it’d be a low cost, low effort solution.

This increase in confidence would increase participation in the survey.

And it may also increase engagement in the original web site; I might have been inclined to spend time clicking around the web page to see what has happened in the past 36 years. We didn’t even have a web page when I graduated; even email was at the university level, not the college level, and was limited to the few students who had a legitimate need.

Conclusion

Just because email and form handling is done via commercial entities does not mean it’s safe or trustworthy.

People are being trained to be cautious of such email.

So when doing a campaign like this you should try to include things that will increase confidence that the email is legitimate. That’s not to include a logo on the email (‘cos that can be copied) but to have the recipient go to a place they know is under your control.