GitLab phished its employees and 20% handed over credentials

The exercise was designed to test the susceptibility of GitLab's remote workforce

GitLab recently concluded a phishing campaign designed to target its remote employees.

The exercise sought to test the susceptibility of GitLab’s remote workforce, and 20% of employees fell for the attack by submitting their credentials to a fake login page.

While one in five is much better than average, it’s still more than GitLab would like to see. What was more alarming to GitLab was the number of employees who submitted the campaign to its security team. 

The exercise was a simulated phishing campaign designed to secure the credentials of GitLab employees. By using the domain name gitlab.company, the GitLab Red Team - the team taking on the role of the attacker  - used the open-source GoPhish framework and Google's GSuite to send unsuspecting GitLab employees targeted phishing emails.

"Targets were asked to click on a link in order to accept their upgrade and this link was instead a fake GitLab.com login page hosted on the domain 'gitlab.company'," explained Security Manager Steve Manzuik in a GitLab post.

"While an attacker would be able to easily capture both the username and password entered into the fake site, the Red Team determined that only capturing email addresses or login names was necessary for this exercise."

Of the 50 emails sent as part of the phishing campaign, 34% of recipients clicked on the link that led to the simulated phishing website. Of those who clicked, 59% went on to enter their GitLab credentials. Meanwhile, only 12% of recipients reported the phishing attempt to GitLab’s security personnel. 

In an email to The Register, Johnathan Hunt, VP of security at GitLab, shared, "Initially, the team had the assumption that more people would fall for the phishing scam but that assumption turned out to be false. Some vendors claim that the average rate of successful phishes is somewhere around 30-40% so it is nice to see us trending below that."

GitLab's findings shed additional light on cybersecurity concerns related to remote workers, which have grown in numbers due to the spread of the coronavirus.

Remote employees often become their own IT administrators, though not all work-from-home employees are up for the task. To address this, Hunt encourages companies to provide their employees with the knowledge they need to avoid falling for phishing campaigns.

"This means that companies, whether remote or not, should be training their staff to have a healthy level of caution when it comes to email communications," shared Hunt.

"As organizations move to being more remote and potentially leveraging cloud services, user identity management and multi-factor authentication become very important."

Featured Resources

2021 Thales cloud security study

The challenges of cloud data protection and access management in a hybrid and multi cloud world

Free download

IDC agility assessment

The competitive advantage in adaptability

Free Download

Digital transformation insights from CIOs for CIOs

Transformation pilotes, co-pilots, and engineers

Free download

What ITDMs did next - and what they should be doing now

Enable continued collaboration and communication for hybrid workers

Recommended

Education and government most at risk from email threats
phishing

Education and government most at risk from email threats

26 Nov 2021
US government warns of increased risk of ransomware over holiday season
ransomware

US government warns of increased risk of ransomware over holiday season

24 Nov 2021
Hackers use Linux backdoor on compromised e-commerce sites with software skimmer
malware

Hackers use Linux backdoor on compromised e-commerce sites with software skimmer

19 Nov 2021
Iranian hackers ramp up attacks against IT services sector
hacking

Iranian hackers ramp up attacks against IT services sector

19 Nov 2021

Most Popular

Microsoft 365 prices to soar by 20% for pay monthly subscribers
Managed service provider (MSP)

Microsoft 365 prices to soar by 20% for pay monthly subscribers

7 Dec 2021
What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

30 Nov 2021
What is single sign-on (SSO)?
single sign-on (SSO)

What is single sign-on (SSO)?

2 Dec 2021