Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
IT explains phishing exercises after suspicious Paychex email; staff urged to report suspicious messages
Summary
Steuben County IT/security staff said the county runs phishing campaigns to train employees and asked staff to use an Office 365 'phish' button to report suspicious messages; staff will sandbox and analyze suspected malicious attachments.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Several board members raised a March 11 Paychex onboarding email and asked whether it was legitimate. IT/security staff explained the county runs internal phishing campaigns and that some emails are intentionally realistic to test staff response; if an employee reports a simulated phish they receive a congratulatory notice, while real suspicious messages are sandboxed and analyzed by help‑desk staff.
"Steuben County runs phishing campaigns," IT security staff said, and explained a built‑in Office 365 'phish' button will notify the security team to sandbox messages. Staff recommended reporting suspicious attachments and warned not to open unknown EXE files. The IT team said they would follow up with additional information and encouraged employees to report suspicious messages so the help desk can analyze them and return legitimate items to mailboxes when appropriate.
Board members said they had received messages that appeared to spoof the county domain and asked about Paychex; IT staff confirmed the county does not use Paychex for onboarding and urged employees to report the email via the phish button.
