Sept. 25, 2023, 5:51 p.m. | /u/SecurityCocktail

cybersecurity www.reddit.com

It's not uncommon that through either URL Rewriting or someone reporting a phishing attack, I find an individual who clicked on a link in a phishing email, which took them to a phishing form, typically trying to steal their username and password.

When the user has NOT entered any credentials, how do you handle these? Do you force a password reset anyway? Reset login tokens? Wipe computer? Force the end user into a phishing training program?

Again, this is not …

attack clicks credentials cybersecurity email find link links password phish phishing phishing attack reporting steal uncommon url username

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)