About Us | Contact Us
View Cart

“Reply-All” Email Incident Hits Microsoft

By Vigilize | Monday, January 28, 2019 - Leave a Comment

At its peak over 11,500 employees were ensnared in the email chain…


An article review.


When it comes to email awareness we usually focus on threats coming into our mailboxes from the outside world, like phishing scams. A recent incident at Microsoft, however, serves as a reminder that there’s more than phishing to be aware of when it comes to email.

The incident, detailed in an article sent to us by our friend Wes Pollard, involved 11,543 employees at its peak and reportedly “caused chaos” for an entire day. What began as a single message sent to all Microsoft employees registered to the organization’s GitHub account soon spiraled out of control, as other employees made the mistake of replying to everyone in the chain asking to be unsubscribed, or to make jokes.

While this case resolved itself quickly and didn’t result in any lasting damage, it serves as a reminder to always be aware of who you are sending an email to! Auto-completion of addresses in Outlook can make it easy to accidentally fill in the name of a mailing list, or a coworker who was not the intended recipient of the email.

Such incidents can simply be embarrassing, or they could result in confidential information going to one (or more!) incorrect addresses. If all that weren’t bad enough, the article notes how a similar incident in 1997 managed to generate enough traffic to bring down Microsoft’s own Exchange servers, effectively launching a Distributed Denial-of-Service attack on themselves!

Considering how dry awareness training can sometimes be, we think this serves as a humorous way to help show your employees how email related risks can originate from within their own group…as well as from the outside world.


Original article by Matt Weinberger reporting for Business Insider.


same_strip_012513


 

Latest News
    A Webinar-Movie In 2018 the NCUA started reviewing credit unions with $1 billion or more in assets using a tool known as the Automated Cybersecurity Examination Tool, or ACET. The expansion to smaller credit unions is inevitable. In the new year, credit unions should now think about how they can come into compliance with the […]
    What are the top seven risks your board should know about in 2021? Since his first board presentation in 2000, when Dan presents audit reports to boards of directors, he also talks to the board about the top risks the institution is facing. Since 2006, Dan has been compiling a list of the “top seven […]
     A Timeline Update as of 02/22/21 An update to our Newest Employee’s FIRST Technical Article Another interim post-mortem review . . . . A Note About Updates: We have decided to leave the original article as it was originally posted and to update this post with any changes that have been made. You can see […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office.  
    A Webinar-Movie The 2020 annual webinar update on the subject will include a review of the previous years’ movies that are already available, and a discussion about alternative tactics that have arisen from recent virtual conferences and regulator panels.
    The cybersecurity industry faces challenges, and some of them may involve your business… An article review. In a world where threats to your organization’s electronic assets are constantly emerging and evolving a cybersecurity insurance policy can help mitigate risk…but what kind of risk does the cybersecurity insurance industry face?  A new article in the Harvard […]
    A Timeline as of 01/24/2021 Our Newest Employee’s FIRST Technical Article Another interim post-mortem review . . . . A Note About Updates: We are leaving this article as is, but for any updates to the timeline, check the Autopsy of the SolarWinds Hack Timeline Update article!      – Vigilize Introduction: As the managing […]
    PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS FORUM AND CONFERENCE NEWS infotex is proud to announce that Dan Hadaway will be moderating a series of IT Forums for the Ohio Bankers League. “We are excited to continue fostering the relationship with the OBL to help educate and keep Risk Management at the forefront of […]
    Top 7 Trend Articles of 2021. . .  . . .For ISOs of Small Financial Institutions. Welcome to our annual T7 article:  a list of our favorite trend articles from the past year.  Our intent: help you organize your thoughts as your work through your strategic planning process.  We hope reviewing these articles will help you […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office.