Go phish your own staff: Dev builds open-source fool-testing tool


An ex employer sent me a snotty email once when I reported one of their phishing test emails as abuse to Google and told them I had. I very much doubt that Google did anything with the report but some wannabe-bigwig emailed me telling me my action had been "escalated" as it might have effected the success of the education campaign. Of course nothing further happened to me, but it did leave a sour taste in my mouth for doing the right thing.

I think ignoring phishing emails, legit or otherwise, is the best policy.

