AJCxZ0<p>How average folks don't stand a chance against phishing, example #78,821,042: Github</p><p>• Email from GitHub <no-reply@github.com> with officialegal subject demanding personal information with urgency else undesirable consequences.<br>• Multiple text links in HTML email including literal "click here to" do not go to known domain, but MSP redirects.<br>• Visiting <a href="https://github.com" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com</span><span class="invisible"></span></a> and looking around shows no sign of this important and urgent change before or after login.<br>• A web version of the notice can be found on github.blog, but who registered that and when?* whois/Internic doesn't know.</p><p>While you and I know how to dig deep enough to validate this kind of thing [or do we just think so?], this is just another in a never-ending stream of emails from companies we trust with our personal information, money, services, etc. training us to fall for phishing far more effectively than any anti-phishing effort can.<br>As sad as it is to expect this from the usual suspects such as the finance industry (especially mortgage companies), it's sadder to see <span class="h-card" translate="no"><a href="https://hachyderm.io/@github" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>github</span></a></span> fail this hard.</p><p>See also <span class="h-card" translate="no"><a href="https://infosec.exchange/@troyhunt" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>troyhunt</span></a></span>'s "Scam" blog posts: <a href="https://www.troyhunt.com/tag/scam/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">troyhunt.com/tag/scam/</span><span class="invisible"></span></a></p><p>*[Created 2018-05-17, registered to Organization "GitHub, Inc" by the same registrar with which github.com was registered for Organization who-knows-because-privacy (but actually GitHub, Inc. if you ask the registrar), hosted by Knock Knock WHOIS There, LLC, which is the only reason I mention this.]</p><p><a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/GitHub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GitHub</span></a> <a href="https://infosec.exchange/tags/MarkMonitor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MarkMonitor</span></a> <a href="https://infosec.exchange/tags/whois" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>whois</span></a></p>