Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Phishing

OHSU Apologizes After Phishing Test Draws Complaints

Officials at Oregon Health & Science University have apologized to employees after a fake phishing test drew complaints about raising false hopes.

Officials at Oregon Health & Science University have apologized to employees after a fake phishing test drew complaints about raising false hopes.

The university sent the phishing test email to employees on April 12 offering up to $7,500 in financial assistance, Portland television station KGW8 reported Thursday.

The email, from a “benefit(@)ohsu.edu” address, read in part: “In response to the current community hardship caused by the COVID-19 pandemic, Oregon Health & Science University has decided to assist all employees in getting through these difficult times.” It included a link where respondents could “register” for COVID-related benefits.

[ Read: Research: Simulated Phishing Tests Make Organizations Less Secure ]

But the offer was not real — it was a test intended to measure employees’ cybersecurity awareness and OHSU’s own technology systems. The test was sent several days after the university sent a message to employees warning them about suspicious emails.

The phishing test was met with frustration from some employees.

Advertisement. Scroll to continue reading.

In a prepared statement, OHSU apologized and said the university didn’t fully consider the harm the phishing test could cause.

“This week, as part of OHSU’s regular exercises to help members practice spotting suspicious e-mails, the language in the test e-mail was taken verbatim from an actual phishing e-mail to ensure no one else fell for the scam. That was a mistake,” the OHSU statement said. “The real scam was insensitive and exploitive of OHSU members — and the attempt to educate members felt the same way, causing confusion and concern.”

Related: Security Awareness Training Debate: Does it Make a Difference?

Related: Report: Security Awareness Training Top Priority for CISOs

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Daniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.

Allied Universal has named Jordan Avnaim Global Chief Information Security Officer.

Cycode has promoted Seth Robbins to President and Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.