Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training

Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training

Security biz Proofpoint and its subsidiary Wombat Security Technologies have sued Facebook and its Instagram subsidiary to prevent the seizure of internet domain names used for security testing.


Proofpoint conducts cybersecurity training for organizations, part of which includes phishing awareness testing. This involves sending participating employees simulated phishing messages with deceptive domain names to entice them to click on links or visit web pages that in a real threat scenario would be trying to trick visitors into submitting sensitive personal information like login credentials.

To do so, the firm follows the cybercrime playbook. It sets up domain names that incorporate trademarked terms, like Facebook and Instagram, or fragments of those terms that have similar looking domain names. In the context of this case, th security biz registered: facbook-login.com, facbook-login.net, instagrarn.ai, instagrarn.net, and instagrarn.org.


The company's
Support the originator by clicking the read the rest link below.