How It Really Happened: "Phish & Ships"
Phish & Ships
Security Topic: Reporting Suspicious Emails
NINJIO Season 11: Episode 08
Data Dave’s (Jon Lovitz) vacation unravels when a phishing-driven breach drains his long-saved loyalty points, all because a cruise line employee deleted a suspicious email instead of reporting it. With the help of intern, Lorna, he traces the attack to the SparkleChasers hacking group and realizes the breach – and the stolen data – could have been prevented. The incident becomes his rallying cry: deleting suspicious emails hides the danger, but reporting them stops attacks before they spread.
Teachable Takeaways
- Report suspicious emails before deleting them to increase protection for other people who could receive the same attack.
- If you think you may have clicked a suspicious link, report it immediately. Fast reporting can limit the damage.
- Knowing your company’s process for reporting suspicious emails is important and can help protect everyone.
Additional Reading
- They don’t care’: ShinyHunters strike again as hackers claim to have pinched 7.5 million Carnival cruise emails – TechRadar
- Carnival confirms ShinyHunters cruised off with 6M customer records after April breach – The Register
- Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise – Microsoft
- Phishing and MFA exploitation: Targeting the keys to the kingdom – CISCO Talos
- Gmail fraud: A new cyber fraud email which bypasses Google’s security protocols; Know how it works and safeguard your money – The Economic Times
- What to do when you click on a suspicious link – CISCO Talos
- How do I report a suspicious email, Teams message, or file to Microsoft? – Microsoft
- Carnival Corporation Data Breach Exposes Millions of Passenger Records – Orion Policy Institute
About NINJIO
NINJIO reduces human-based cybersecurity risk through engaging training, personalized testing, and insightful reporting. Our multi-pronged approach to training focuses on the latest attack vectors to build employee knowledge and the behavioral science behind human engineering to sharpen users’ intuition. The proprietary NINJIO Risk Algorithm™ identifies users’ social engineering vulnerabilities based on NINJIO Phish3D phishing simulation data and informs content delivery to provide a personalized experience that changes individual behavior.