My brush with cyber insecurity
- 3 days ago
- 2 min read
My cyber security guy has always made himself available for interviews. Whenever a government agency or big corporation has a problem, I know I can call him up, and he's ready to explain the differences between a cyber attack or an internal software or hardware issue.
I've done the cyber attack interview again and again. And I roll my eyes whenever someone gets hacked and think, "Who would fall for that?!"
After so many conversations, I can even recite some of his talking points: scammers send out thousands of emails because they just need one person in a company to click on a fake link to put the whole system at risk. You also shouldn't include personal information in an email because it's not secure.
This week, I fell for it.
Since I no longer work at the station full-time, I often get emails asking me to fill in for someone on short notice. So when I saw this email from my news director, I didn't think much of it.

I was somewhat flummoxed, mind you.
"Since I'm part-time now, am I the vendor?" I asked myself.
The computer machine imitating my boss explained he had a "time-sensitive issue." I probably should have understood I was getting scammed.
"But I do enjoy getting payments," I continued to myself. "Let's see what this is all about."
As soon as I replied, I got this email from IT.

In my defense, the email seemed reasonable enough, and since I don't work full-time, I'm actually part of the traffic budget, so it's the traffic company, Metro Networks, could have a reason to get in touch with me.
Plus, I can confirm Drew Anderssen is a real-life mammal. And the email referred to "Programming Initiative 2026."
"Hmmm... that does sound like a legitimate corporate buzzword," I thought to myself. Plus, the email never mentioned how he's been trying to reach me about my car's extended warranty.
However, if I had paid closer attention, I would have spotted clear signs this was a teaching moment. The email had more typos than I'd expect. More substantially, the company wasn't, technically, spelled correctly.

Also a technicality, I just learned the traffic provider, Metro Networks, no longer exists.
I finished the phishing training (singing to myself when they posted warnings about spam). The next time I was at the station, I learned just about everyone else figured it out themselves.
So now, when I get an email from my news director while I'm at the station, I'll just smile smugly, lean back and put my feet up on the desk.
"Don't read that!" I'll tell everyone. "It's all part of the scam! I passed the training!"
But let's not mention to my associate at M3 Networks I did the exact opposite of what he's been telling me for years.



Comments