Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

GoDaddy Demonstrated How Not to Educate Users About Phishing

GoDaddy Demonstrated How Not to Educate Users About Phishing

While phishing awareness is an important practice to teach to a business’ employees, some methods are better than others, as GoDaddy—the domain registrar and web-hosting company notorious for its run of risqué ads—is learning the hard way. On December 14, GoDaddy’s employees received an email that seemed to be a holiday bonus from the company… only to find out (the hard way) that it was a phishing test that their employer had run.

Let’s review the chain of events:

The Message GoDaddy’s Employees Received

When the employees GoDaddy involved in their phishing test opened their email on December 14, a message from the address “Happyholiday@Godaddy-dot-com” awaited them. Below, we have replicated the message it contained, under a large, branded announcement of a “Holiday Party.”

I hope you’re sitting down:

---

Happy Holiday GoDaddy!

2020 has been a record year for GoDaddy, thanks to you!

Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus! To ensure that you receive your one-time Bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th.

US

EMEA

Any submittals after the cutoff will not be accepted and you will not receive the one-time bonus of $650 (free money, claim it now!)

We look forward to celebrating with you again, in person next year!

---

I don’t know about you, but if that showed up in my email—just before the holiday season, during a year marred by a terrible pandemic, no less—I would be pretty excited.

However, no bonus was in store for the company’s 500 employees who clicked through the links. All they got was another email, two days later, from the company’s security chief. This was how these employees were informed that the email was nothing but a phishing test, and since they had failed, they would need to retake the company’s Security Awareness Social Engineering training.

Of course, this message did not land very well amongst many of these employees… and it certainly wasn’t helped, considering the “record year” that the email bragged about came after hundreds of employees were reassigned or completely laid off, and a data breach had exposed 28,000 GoDaddy customers’ data earlier in the year.

GoDaddy has since released a statement, apologizing for the poorly-thought-out phishing test. As a spokesperson for the company said:

“GoDaddy takes the security of our platform extremely seriously. We understand some employees were upset by the phishing attempt and felt it was insensitive, for which we have apologized.”

Companies Other Than GoDaddy Have Made Similar Errors

GoDaddy is not the only company to stumble during their phishing evaluations. In September, Tribune Publishing sent out an internal phishing email offering targeted bonuses worth anywhere between $5,000 and $10,000. As with GoDaddy, this attempt saw backlash from employees, one reporter tweeting that the cruelty of it was “stunning.” As happened with GoDaddy, the company apologized for its “misleading and insensitive” email.

In Fairness, Phishing Should Be Highlighted…Just Not This Way

While these examples prove that there is definitely a wrong way to educate users about phishing, it must be said that phishing is a very real threat for businesses of all sizes today.

However, when you try to educate your users, we suggest using different tactics. Seminars and training sessions are great options, and practical evaluations are very effective (as long as you do it differently than GoDaddy). The main issue in GoDaddy’s case was that they took advantage of their employees, during a time when many were already under financial strain, running a test that offered them a sizable bonus when they seemed to have no intention of actually distributing it.

Naturally, nobody should hope that their organization offends its workforce, and nobody should hope that their organization falls victim to a phishing attack. Fortunately, Voyage Technology can at least help you with the latter. Call our team at 800.618.9844 to find out how we can help you address the complicated issue of phishing attacks.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Sunday, 03 May 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Hardware Efficiency Network Security User Tips Internet IT Services Malware Phishing IT Support Privacy Google Email Workplace Tips Computer Workplace Strategy Collaboration Small Business Hosted Solutions Backup Users Ransomware AI Managed Service Mobile Device Productivity Microsoft Saving Money Quick Tips Passwords Communication Cybersecurity Smartphone Data Backup Data Recovery Disaster Recovery Android Upgrade VoIP Business Management Smartphones Mobile Devices communications Windows Browser Social Media Managed IT Services Microsoft Office Current Events Network Tech Term Internet of Things Remote Miscellaneous Information Artificial Intelligence Facebook Holiday Automation Compliance Cloud Computing Covid-19 Gadgets Training Managed Service Provider Outsourced IT IT Support Remote Work Server Encryption Spam Employee/Employer Relationship Windows 10 Office Data Management Business Continuity Government Windows 10 Bandwidth Blockchain Virtualization Wi-Fi Business Technology Data Security Vendor Apps Managed Services Two-factor Authentication Mobile Office Mobile Device Management Chrome Networking Gmail Budget WiFi Apple BYOD App Employer-Employee Relationship Tip of the week Voice over Internet Protocol Office 365 Managed IT Services How To BDR Password HIPAA Physical Security Applications Access Control Computing Hacker Information Technology Avoiding Downtime Conferencing Marketing Healthcare Analytics Office Tips Augmented Reality Storage Bring Your Own Device Big Data Router Virtual Private Network Operating System Health Computers 2FA Help Desk Risk Management Website Retail Telephone Scam Data loss Firewall Cooperation Free Resource Project Management Windows 7 The Internet of Things Patch Management Save Money Microsoft 365 Remote Monitoring Vulnerability End of Support Vendor Management Solutions Social Going Green Display Printer Customer Service Paperless Office Windows 11 Cybercrime Infrastructure Monitoring Excel Document Management Remote Workers Managed IT Service Maintenance Antivirus Word Downloads iPhone Outlook Licensing Money Vulnerabilities Humor Entertainment Data Privacy Safety Images 101 Sports Mouse Telephone System Multi-Factor Authentication Robot Mobility Cost Management Administration IT Management VPN Employees Meetings Integration Customer Relationship Management User Tip Modem Settings Computer Repair Mobile Security Processor Printing Wireless Holidays Content Filtering Hacking Presentation Data Storage YouTube Smart Technology Supply Chain Cryptocurrency Video Conferencing Wireless Technology Machine Learning Managed Services Provider Saving Time Virtual Machines Professional Services Virtual Desktop Data storage LiFi Download Net Neutrality Laptop Twitter Alerts SQL Server Technology Care Hard Drives Windows 8 Domains Drones Financial Data Error History Business Communications Social Engineering Break Fix Scams Browsers Smartwatch Connectivity IT Upload Procurement Halloween Remote Computing Azure Hybrid Work Refrigeration Public Speaking Social Network Telework Cyber security Multi-Factor Security Tech Human Resources Dark Web Cables Lithium-ion battery CES Tablet IoT Communitications Trends Supply Chain Management Entrepreneur Scary Stories Alert Hacks Managed IT Customer Resource management FinTech File Sharing Regulations Fun Dark Data Google Calendar Term Google Apps How To Microsoft Excel IT Maintenance Data Analysis Deep Learning Star Wars IT Assessment Gamification Flexibility Notifications Staff Value Business Intelligence Undo Organization Education Travel Social Networking Legislation Shortcuts Ransmoware Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Mobile Computing Content Remote Working Wearable Technology Memory Vendors Health IT Unified Threat Management Motherboard Data Breach Search Comparison Google Play Be Proactive Permissions Workforce Unified Threat Management Directions Videos Application Best Practice Assessment Electronic Health Records Buisness Wasting Time Threats IBM Legal IT solutions Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Fraud Meta User Error Microchip Business Growth Internet Exlporer Software as a Service Username Managing Costs Amazon Point of Sale eCommerce Cortana Black Friday SSID Virtual Assistant Outsource IT Alt Codes Database Surveillance Competition Network Management Downtime Tech Support IT Technicians Virtual Machine Environment Media Proxy Server Reviews Hosted Solution Cookies Monitors Cyber Monday Medical IT Hotspot Transportation Small Businesses Typing Tactics Development Websites Mirgation Hypervisor Displays Google Drive Shopping User Nanotechnology Optimization Knowledge PowerPoint Electronic Medical Records Language Employer/Employee Relationships Outsourcing SharePoint Addiction Management PCI DSS Chatbots 5G Navigation IP Address Google Docs Lenovo Gig Economy Unified Communications Screen Reader Experience Writing Distributed Denial of Service Workplace Running Cable Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Bitcoin Service Level Agreement Internet Service Provider Google Wallet Server Management Regulations Compliance Private Cloud Identity Evernote Paperless Superfish Bookmark Recovery Identity Theft Smart Tech Memes Co-managed IT

Blog Archive