Forum Discussion
Phishing attack simulator incorrectly emails people the message, "Because you were recently phished"
To take your points in order:
(a) in your pilot test, did you specify training for all recipients, those who clicked the payload or those who were fully compromised? What notification option did you choose? One problem with the simulator (as I last used it in December) is that a lot of the minor settings are not recorded in the simulation list. If for example you want a record of what training you have assigned, you are going to have to keep a manual record.
(b) is a danger. You have to recognise that the MS phishing simulator is a product being continuously improved, and if all of the changes are being announced in the O365 message center then I'm missing some of them. I use the simulator quarterly, and every time last year there were some new changes to take into account. I have even seen changes arrive in mid-simulation. Your only option is to test in advance, and once more just before you launch. Unless your security stack is MS from top to bottom, you need to do that anyway in case another security vendor has suddenly decided your chosen phishing URL is malicious.
(c) is a danger with any attack simulator. Weeks before you launch, you might consider sending out a general mail reminding recipients of the dangers of phishing and that regretfully the organisation has no choice but to conduct simulated tests for all staff. Explain that this is something all proactive organisations are adopting, and that the object is to train rather than catch people out. They will face the same dangers with their personal addresses. Be constructive and helpful; I use payloads of varying "difficulty" so no-one feels bad about falling for the trickier ones.
- ExMSW4319Mar 03, 2022Iron ContributorIn answering myatkaw, I have just seen the End-user notifications tab on the same portal. It seems that it is now possible to edit a copy of the offending Microsoft default simulation notice, but in starting a test simulation I only saw the option to choose a variant positive reinforcement notice.
- waypassMay 05, 2022Copper ContributorI have discovered this exact annoyance myself. You can create a custom Simulation Notification to remove the troublesome wording of 'You have been Phished' but then there is no way of setting that as your simulation notification in the attack.
- myatkyawMar 03, 2022Copper ContributorI think it's a matter of documentation in an evolving product. Features are getting added faster than there's education and documentation. I'm still trying to wrap my head around Defender products renaming and regrouping (ATP is now Identity, MCAS is Defender something). Nowhere in Attack Sim documents on Docs.Microsoft does it tell you how to edit the response files. It's just something I stumbled on. Luckily, there's a community here that can help each other out.