You have been trapped !
Your credentials have been compromised !


Do not panic, this is an internal campaign, but think about modifying your password if you entered it before arriving on this page.


This phishing campaign was created by the Security team of Sewan in order to estimate the group employee's knowledge on this subject. Whatever the way you arrived on this website (you clicked on the link without paying attention or you hesitated before clicking), take a few minutes to read the awareness document we wrote.


But be carefull, the next time, it won't necessarily be a test.

hacker

What is Phishing ?

The "Phishing" is one of the hacking methods the most known and used, it aims to retrieve personal and critical data like credentials or bank details through a legitimate looking email. Phishing can also be used against an organisation to retrieve professional credentials and/or send malware.

This aimed attacks are easier nowadays with the raise of social networks (personal and profesional) which alow the hacker to find information about a company and it's organizational chart.

Today, the Phishing is still one of the major hacking vector.

phishing

« Phishing is the simplest and, at the same time, the most dangerous and effective form of cyberattack. »

Adam Kujawa

How to identify a Phishing attempt ?

Acknowledge a Phishing attemp is not always easy, especially when the attacks are more and more perfected with a few clues to analyse.

The Security team made a list of all the email parts you need to look when you doubt about it's legimitimacy. By paying attention to this key points, you'll be able to identify traditionnal phishing attempts and help us enhance the security of the company :

identification
  • profil
    The sender

    Look closely to the domain name (sewan.fr for example) and if possible, compare the sender email with the known email.

    In the example, we modified the domain name "microsoft.com" by deleting the caracter "r". By reading it fast we might not see the difference.

  • expediteur
    True
    expediteur
    False
  • urgent
    The signature

    If the received email contains a signature, look at the details closely. Ask yourself: "Is the logo, the font, the addresses, etc. match the ones of my correspondent?"

  • Will you be able to find the errors we made in this Sewan signature ?
    expediteur
    True
    expediteur title
    texte
    False
  • pdf
    Attachments

    Although the email antivirus analyses the attachements in order to detect any malware, if you doubt about the origin of the email, don't download the files from it.

  • url
    Links

    If there is a link in the email you received, don't click on it without a thought.

    Mouse over without clicking the link. It will display on a little screen the the URL you'll be redirected to.

    Check the redirect URL and it's domain name to ensure it's safety.

  • Orthographe
    Spelling

    Even though it seems basic, if there is a lot of spelling mistakes in the email, it is most likely an illegitimate email.

  • Let's see together the clues put in the email received by the employees :

    mail

    How to react in case of phishing ?

    When you receive a phishing or if you hqve qny doubt, you can notify Sewan Security teams by forwarding the email. The teams will then be able to tell you if it's a legitimate email or not and will take the appropriate measures (blocking the sender).

    In the case you clicked on a link or opened an attachement and some software has been installed on your device, disconect it immediately from the network in order to prevent the spread of the malware through the whole company. After that, contact as soon as possible the Security teams which will tell you what to do.

    If credentials where asked (and you gave them), change them immediately.

    protection

    As a reminder, Security teams email are :

    rssi@sewan.fr
    Contact
    securite@sewan.fr
    Contact

    Even if the Sewan messaging is secured, it will always subsist some security breach that hackers will try to use against you and the company.

    Take Precautions, and be mindful.