all you can expect
I think the lesson here is that an adequately researched spear phishing attack is good enough to fool even rocket scientists. Presumably this is not a "all your base are belong to us" email, but something sophisticated. Hey, the fact that not every employee opened the highly targeted email bomb is pretty good.
It's easy to laugh at the victims here and act all superior, but really, if somebody that appeared to be a colleague sent you email on your work account that appeared to be about the specific work that you do, and said "look at the attached info", how smart are you? Are you that smart every time? Even in the morning when you're not revved up? Even right before a meeting when you're in a hurry?
The spear phishers got to take seven shots at 3k employees. The odds of catching one guy not paying enough attention are up there in the "inevitable" range.
I just hope we're doing it to "them".


