Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

GoDaddy Demonstrated How Not to Educate Users About Phishing

GoDaddy Demonstrated How Not to Educate Users About Phishing

While phishing awareness is an important practice to teach to a business’ employees, some methods are better than others, as GoDaddy—the domain registrar and web-hosting company notorious for its run of risqué ads—is learning the hard way. On December 14, GoDaddy’s employees received an email that seemed to be a holiday bonus from the company… only to find out (the hard way) that it was a phishing test that their employer had run.

Let’s review the chain of events:

The Message GoDaddy’s Employees Received

When the employees GoDaddy involved in their phishing test opened their email on December 14, a message from the address “Happyholiday@Godaddy-dot-com” awaited them. Below, we have replicated the message it contained, under a large, branded announcement of a “Holiday Party.”

I hope you’re sitting down:

---

Happy Holiday GoDaddy!

2020 has been a record year for GoDaddy, thanks to you!

Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus! To ensure that you receive your one-time Bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th.

US

EMEA

Any submittals after the cutoff will not be accepted and you will not receive the one-time bonus of $650 (free money, claim it now!)

We look forward to celebrating with you again, in person next year!

---

I don’t know about you, but if that showed up in my email—just before the holiday season, during a year marred by a terrible pandemic, no less—I would be pretty excited.

However, no bonus was in store for the company’s 500 employees who clicked through the links. All they got was another email, two days later, from the company’s security chief. This was how these employees were informed that the email was nothing but a phishing test, and since they had failed, they would need to retake the company’s Security Awareness Social Engineering training.

Of course, this message did not land very well amongst many of these employees… and it certainly wasn’t helped, considering the “record year” that the email bragged about came after hundreds of employees were reassigned or completely laid off, and a data breach had exposed 28,000 GoDaddy customers’ data earlier in the year.

GoDaddy has since released a statement, apologizing for the poorly-thought-out phishing test. As a spokesperson for the company said:

“GoDaddy takes the security of our platform extremely seriously. We understand some employees were upset by the phishing attempt and felt it was insensitive, for which we have apologized.”

Companies Other Than GoDaddy Have Made Similar Errors

GoDaddy is not the only company to stumble during their phishing evaluations. In September, Tribune Publishing sent out an internal phishing email offering targeted bonuses worth anywhere between $5,000 and $10,000. As with GoDaddy, this attempt saw backlash from employees, one reporter tweeting that the cruelty of it was “stunning.” As happened with GoDaddy, the company apologized for its “misleading and insensitive” email.

In Fairness, Phishing Should Be Highlighted…Just Not This Way

While these examples prove that there is definitely a wrong way to educate users about phishing, it must be said that phishing is a very real threat for businesses of all sizes today.

However, when you try to educate your users, we suggest using different tactics. Seminars and training sessions are great options, and practical evaluations are very effective (as long as you do it differently than GoDaddy). The main issue in GoDaddy’s case was that they took advantage of their employees, during a time when many were already under financial strain, running a test that offered them a sizable bonus when they seemed to have no intention of actually distributing it.

Naturally, nobody should hope that their organization offends its workforce, and nobody should hope that their organization falls victim to a phishing attack. Fortunately, Voyage Technology can at least help you with the latter. Call our team at 800.618.9844 to find out how we can help you address the complicated issue of phishing attacks.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 25 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Hardware Internet Efficiency IT Support Malware Google Privacy Email Workplace Tips Phishing Computer IT Services Hosted Solutions Collaboration Users Mobile Device Ransomware Workplace Strategy Quick Tips Small Business Microsoft Cybersecurity Passwords Communication Data Backup Smartphone Backup Saving Money Business Management Smartphones VoIP Android Mobile Devices communications Upgrade Managed Service Disaster Recovery Browser Data Recovery Managed IT Services Social Media Microsoft Office Windows Tech Term Network Remote Internet of Things Current Events Automation Facebook Artificial Intelligence Productivity Gadgets Cloud Computing Covid-19 Miscellaneous AI Server Managed Service Provider Remote Work Outsourced IT Information Holiday Spam Encryption Employee/Employer Relationship Windows 10 Compliance Office Data Management Business Continuity Government Training Business Technology Virtualization Bandwidth Blockchain Wi-Fi Windows 10 Apps Data Security Mobile Office Two-factor Authentication Gmail Chrome Managed Services Voice over Internet Protocol Budget Employer-Employee Relationship Apple Networking App BYOD Vendor Mobile Device Management Office 365 IT Support Tip of the week WiFi Conferencing How To BDR Hacker Avoiding Downtime Computing Marketing Applications Information Technology Access Control Help Desk Analytics Office Tips Augmented Reality Big Data Retail Storage Password Healthcare Bring Your Own Device Managed IT Services Computers Operating System HIPAA Website Router Virtual Private Network Risk Management Health Monitoring The Internet of Things Document Management Remote Workers Social Telephone Scam Data loss Cooperation Free Resource Project Management Customer Service Windows 7 Going Green Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions Cybercrime Physical Security Windows 11 Display 2FA Printer Firewall Paperless Office Infrastructure Excel Data Storage Smart Technology Video Conferencing Safety Outlook Machine Learning Managed Services Provider Professional Services Money Saving Time Virtual Machines Humor Managed IT Service Maintenance Antivirus Sports Downloads iPhone Mouse Data Privacy Licensing Administration Customer Relationship Management Vulnerabilities Entertainment Images 101 Hacking Robot Mobility Telephone System Multi-Factor Authentication Presentation Cost Management Settings Wireless Printing Wireless Technology Content Filtering IT Management VPN Employees YouTube Meetings Integration Cryptocurrency Word User Tip Modem Computer Repair Mobile Security Processor Supply Chain Virtual Desktop Holidays LiFi Data storage Entrepreneur Windows 8 Workplace Laptop Websites Mirgation Hypervisor PowerPoint Drones Shopping Hiring/Firing Nanotechnology Optimization Addiction Paperless Electronic Medical Records Language Employer/Employee Relationships SharePoint Management PCI DSS Co-managed IT Halloween Chatbots Undo Navigation Writing Distributed Denial of Service Lenovo Gig Economy Technology Care Screen Reader Service Level Agreement Internet Service Provider Business Communications Virtual Reality Computing Infrastructure Teamwork Hacks Server Management Regulations Compliance Scams Scary Stories Private Cloud Identity Evernote Fun Superfish Bookmark Hybrid Work Identity Theft Smart Tech Memes Deep Learning Download Net Neutrality Human Resources Twitter Alerts SQL Server Application Financial Data Cables Error History IBM Social Engineering Break Fix Browsers Smartwatch Education Connectivity IT Upload Procurement Google Apps Remote Computing Azure Mobile Computing Social Network Telework IT Maintenance Cyber security Multi-Factor Security Tech Tablet IoT Communitications Search Dark Web CES Business Intelligence Best Practice Trends Supply Chain Management Shortcuts Alert Dark Data Google Calendar Term Managed IT Customer Resource management FinTech Ransmoware Buisness File Sharing Regulations Competition IT solutions Star Wars IT Assessment How To Microsoft Excel Legal Data Analysis Vendors Business Growth Gamification Flexibility Be Proactive Notifications Staff Value Legislation Organization Workforce Travel Social Networking Google Maps Smart Devices Cortana User Techology Fileless Malware Digital Security Cameras Threats Alt Codes Content Remote Working Workplace Strategies Wearable Technology Memory Comparison Google Play Health IT Meta Downtime Unified Threat Management Motherboard Data Breach Hosted Solution Assessment Electronic Health Records IP Address Permissions Unified Threat Management Directions Videos Amazon Typing Wasting Time Network Congestion Specifications Security Cameras Outsource IT Trend Micro Internet Exlporer Software as a Service Media Knowledge Fraud Recovery Google Drive User Error Microchip Environment Username Managing Costs Hard Drives Domains 5G Black Friday SSID Small Businesses Point of Sale eCommerce Displays Unified Communications Database Surveillance Experience Virtual Assistant Google Docs Bitcoin Network Management Running Cable Tech Support IT Technicians Virtual Machine Refrigeration Public Speaking Monitors Cyber Monday Medical IT Google Wallet Proxy Server Reviews Outsourcing Cookies Tactics Development Lithium-ion battery Hotspot Transportation

Blog Archive