View Single Post
  #7 (permalink)  
Old 04-09-2009, 02:18 AM
phoenix phoenix is offline
Zimbra Consultant & Moderator
 
Posts: 11,508
Default

Quote:
Originally Posted by su_A_ve View Post
We get phishing scams approx. once a week and of course, usually on weekends. This is a brief rundown on how we deal with it:

* Notices on the front webmail page that we never ask for a password
* Routine email announcements reminding users we never ask for a password
* As soon as we get details of a possible phishing scam, we get the reply-to address (always different than the sender address)
* We add it to a list of blacklist recipients (we have a small patch for amavis to add a high score to a recipient address)
* We then search the logs for users that replied to the email
* Then we look in their Sent folders for the reply and verify they indeed sent the information
* If they password was sent out, we lock the accounts and change their passwords
Just for my own interest, if you don't mind. How many users actually fall for it (out of what userbase) and how much time do you spend rectifying the problem?
__________________
Regards


Bill
Reply With Quote