"IRS employees ignored security rules and turned over sensitive computer information to a caller posing as a technical support person, according to a government study.
Sixty-one of the 102 people who got the test calls, including managers and a contractor, complied with a request that the employee provide his or her user name and temporarily change his or her password to one the caller suggested, according to the Treasury Inspector General for Tax Administration, an office that does oversight of Internal Revenue Service."
and
"Only eight of the 102 employees contacted either the inspector general's office or IRS security offices to validate the legitimacy of the caller."
http://www.signonsandiego.com/news/nation/20070803-0750-irs-computersecurity.html
http://it.slashdot.org/article.pl?sid=07/08/05/1834201
We really should do a similar study where I'm at, I know for a fact that this is not limited to the IRS. At least eight went to higher-ups to report the incident. This is why you can buy the t-shirt that says "Social Engineering: Because there is no patch for human stupidity."
Sixty-one of the 102 people who got the test calls, including managers and a contractor, complied with a request that the employee provide his or her user name and temporarily change his or her password to one the caller suggested, according to the Treasury Inspector General for Tax Administration, an office that does oversight of Internal Revenue Service."
and
"Only eight of the 102 employees contacted either the inspector general's office or IRS security offices to validate the legitimacy of the caller."
http://www.signonsandiego.com/news/nation/20070803-0750-irs-computersecurity.html
http://it.slashdot.org/article.pl?sid=07/08/05/1834201
We really should do a similar study where I'm at, I know for a fact that this is not limited to the IRS. At least eight went to higher-ups to report the incident. This is why you can buy the t-shirt that says "Social Engineering: Because there is no patch for human stupidity."