this post was submitted on 29 Mar 2025
974 points (98.8% liked)

iiiiiiitttttttttttt

749 readers
115 users here now

you know the computer thing is it plugged in?

founded 2 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments

A company I used to work for used paycom(dot)com for their HR software. So we would frequently get notifications from there for work stuff. One day I got an external work email telling me to click a link to a paycom(dot)net site to sign up for a raffle to win a free ipad. I thought that looked sketchy as fuck so I did a quick whois on the .net and .com sites. They were completely different and the .net site was basically entirely anonymised. So obviously at that point I was like "damn this phisher managed to get the .net domain for paycom. That's kind of impressive. I should let our IS guy know so he knows we're being targeted." So I shot off an email to our basically only IS guy and he responded by telling me that the email was legit and everyone in the company got it because the company was giving away an extra ipad they had. But he also said now that I pointed it out it was the sketchiest looking email he had seen in a while.

I honestly should have known better considering this is the same company where at one point a different IS person had sent me an email basically just saying "Your computer has a virus. Open this attachment to remove it." Turns out that was also legit and the guy who used my desk on first shift managed to get a virus somewhere but rather than comming down to fix it themselves IS just sent me an email with a script to run.