Fake courier SMS, 'HR' on WhatsApp, and the Facebook page takeover. Something you can read out at the Monday meeting.
A lot of phishing training uses examples from other countries: fake Amazon deliveries, tax refund emails from agencies nobody here deals with. Staff look at those and think "that wouldn't fool me", and they're probably right. The messages that do catch people in Sri Lanka look different.
Here's a short briefing you can read out at a staff meeting. Change it to fit your company.
Courier and customs SMS. "Your parcel is on hold, pay a small fee at this link." If you're expecting something, check on the courier's own website or call them. Don't use the link.
WhatsApp messages from "the boss" or "HR". A new number, a profile photo copied from Facebook, and something urgent: buy gift cards, make a quick transfer, send the staff list. Call the person on the number you already have for them.
Bank or mobile wallet messages asking for an OTP. No bank or wallet provider needs your OTP. Anyone asking for it is trying to get into your account.
"Your Facebook page will be removed." These go after whoever manages the company page, often by email or Messenger, with a link to "appeal". Real notices from Meta show up inside Facebook itself, in the page's own notifications.
If you clicked something, tell IT (or whoever looks after this) straight away. Nobody gets in trouble for reporting. The expensive situation is someone who clicked and said nothing for a week.
If people remember one thing: when a message is urgent and asks for money, a code or a login, check it using a number or app you already had, not the details in the message.





Comments (0)
No public comments yet.