Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

GoDaddy Demonstrated How Not to Educate Users About Phishing

GoDaddy Demonstrated How Not to Educate Users About Phishing

While phishing awareness is an important practice to teach to a business’ employees, some methods are better than others, as GoDaddy—the domain registrar and web-hosting company notorious for its run of risqué ads—is learning the hard way. On December 14, GoDaddy’s employees received an email that seemed to be a holiday bonus from the company… only to find out (the hard way) that it was a phishing test that their employer had run.

Let’s review the chain of events:

The Message GoDaddy’s Employees Received

When the employees GoDaddy involved in their phishing test opened their email on December 14, a message from the address “Happyholiday@Godaddy-dot-com” awaited them. Below, we have replicated the message it contained, under a large, branded announcement of a “Holiday Party.”

I hope you’re sitting down:

---

Happy Holiday GoDaddy!

2020 has been a record year for GoDaddy, thanks to you!

Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus! To ensure that you receive your one-time Bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th.

US

EMEA

Any submittals after the cutoff will not be accepted and you will not receive the one-time bonus of $650 (free money, claim it now!)

We look forward to celebrating with you again, in person next year!

---

I don’t know about you, but if that showed up in my email—just before the holiday season, during a year marred by a terrible pandemic, no less—I would be pretty excited.

However, no bonus was in store for the company’s 500 employees who clicked through the links. All they got was another email, two days later, from the company’s security chief. This was how these employees were informed that the email was nothing but a phishing test, and since they had failed, they would need to retake the company’s Security Awareness Social Engineering training.

Of course, this message did not land very well amongst many of these employees… and it certainly wasn’t helped, considering the “record year” that the email bragged about came after hundreds of employees were reassigned or completely laid off, and a data breach had exposed 28,000 GoDaddy customers’ data earlier in the year.

GoDaddy has since released a statement, apologizing for the poorly-thought-out phishing test. As a spokesperson for the company said:

“GoDaddy takes the security of our platform extremely seriously. We understand some employees were upset by the phishing attempt and felt it was insensitive, for which we have apologized.”

Companies Other Than GoDaddy Have Made Similar Errors

GoDaddy is not the only company to stumble during their phishing evaluations. In September, Tribune Publishing sent out an internal phishing email offering targeted bonuses worth anywhere between $5,000 and $10,000. As with GoDaddy, this attempt saw backlash from employees, one reporter tweeting that the cruelty of it was “stunning.” As happened with GoDaddy, the company apologized for its “misleading and insensitive” email.

In Fairness, Phishing Should Be Highlighted…Just Not This Way

While these examples prove that there is definitely a wrong way to educate users about phishing, it must be said that phishing is a very real threat for businesses of all sizes today.

However, when you try to educate your users, we suggest using different tactics. Seminars and training sessions are great options, and practical evaluations are very effective (as long as you do it differently than GoDaddy). The main issue in GoDaddy’s case was that they took advantage of their employees, during a time when many were already under financial strain, running a test that offered them a sizable bonus when they seemed to have no intention of actually distributing it.

Naturally, nobody should hope that their organization offends its workforce, and nobody should hope that their organization falls victim to a phishing attack. Fortunately, Voyage Technology can at least help you with the latter. Call our team at 800.618.9844 to find out how we can help you address the complicated issue of phishing attacks.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Monday, 30 March 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Hardware Efficiency Network Security User Tips Internet IT Services Malware IT Support Workplace Tips Privacy Email Computer Phishing Google Workplace Strategy Hosted Solutions Collaboration Small Business Backup Users Managed Service Ransomware Mobile Device Productivity Microsoft Quick Tips Passwords Saving Money AI Communication Cybersecurity Smartphone Data Backup Disaster Recovery Data Recovery Android VoIP Upgrade Business Management Smartphones communications Mobile Devices Windows Browser Social Media Managed IT Services Microsoft Office Current Events Network Tech Term Remote Internet of Things Information Holiday Facebook Miscellaneous Automation Artificial Intelligence Cloud Computing Training Gadgets Compliance Covid-19 Remote Work Outsourced IT Server Managed Service Provider IT Support Employee/Employer Relationship Spam Encryption Windows 10 Office Data Management Business Continuity Government Windows 10 Wi-Fi Virtualization Business Technology Bandwidth Blockchain Two-factor Authentication Managed Services Apps Data Security Mobile Office Vendor BYOD Gmail WiFi Tip of the week Voice over Internet Protocol Employer-Employee Relationship Chrome Budget Apple Networking App Mobile Device Management Applications Computing Physical Security Information Technology Access Control Office 365 Conferencing Hacker Managed IT Services Avoiding Downtime How To BDR Marketing HIPAA Operating System Virtual Private Network Risk Management 2FA Help Desk Big Data Health Office Tips Analytics Augmented Reality Healthcare Retail Storage Password Computers Bring Your Own Device Website Router Firewall Vendor Management Cybercrime Windows 11 Display The Internet of Things Printer Monitoring Paperless Office Excel Infrastructure Social Remote Workers Managed IT Service Document Management Telephone Customer Service Scam Cooperation Free Resource Project Management Data loss Windows 7 Microsoft 365 Going Green Patch Management Solutions Save Money Remote Monitoring Vulnerability End of Support Content Filtering Modem IT Management User Tip VPN Processor Meetings YouTube Mobile Security Safety Holidays Cryptocurrency Data Storage Computer Repair Smart Technology Supply Chain Virtual Desktop Video Conferencing Managed Services Provider Data storage LiFi Saving Time Virtual Machines Professional Services Outlook Machine Learning Money Customer Relationship Management Downloads Humor iPhone Licensing Maintenance Antivirus Entertainment Sports Hacking Vulnerabilities Mouse Presentation Data Privacy Images 101 Administration Wireless Technology Multi-Factor Authentication Mobility Telephone System Cost Management Robot Word Settings Employees Printing Wireless Integration Unified Threat Management Hosted Solution Username Public Speaking Managing Costs Amazon Lithium-ion battery eCommerce Black Friday SSID Typing Database Surveillance Network Congestion Virtual Assistant Outsource IT Entrepreneur Media Google Drive User Error Knowledge IT Technicians Virtual Machine Environment Proxy Server Reviews Cookies Cyber Monday Medical IT Point of Sale Tactics Development 5G Undo Hotspot Transportation Small Businesses Mirgation Hypervisor Displays Google Docs Unified Communications Experience Shopping Tech Support Running Cable Nanotechnology Optimization PowerPoint Network Management Bitcoin Google Wallet Addiction Monitors Language Employer/Employee Relationships Outsourcing Chatbots Navigation Management PCI DSS Windows 8 Gig Economy Websites Laptop Screen Reader Application Distributed Denial of Service Workplace Drones Service Level Agreement Internet Service Provider Computing Infrastructure Teamwork Hiring/Firing Electronic Medical Records IBM Identity Evernote Paperless SharePoint Regulations Compliance Bookmark Halloween Smart Tech Memes Co-managed IT Lenovo Download Net Neutrality Writing Alerts SQL Server Technology Care Virtual Reality History Business Communications Financial Data Hacks Server Management Browsers Smartwatch Private Cloud Scary Stories Connectivity IT Break Fix Scams Superfish Identity Theft Upload Procurement Fun Competition Azure Hybrid Work Twitter Cyber security Multi-Factor Security Tech Human Resources Deep Learning Social Network Telework CES Error IoT Communitications Dark Web Cables Education Trends Supply Chain Management Social Engineering Remote Computing Regulations User Google Calendar Term Google Apps Customer Resource management FinTech Mobile Computing Data Analysis Star Wars IT Assessment Microsoft Excel IT Maintenance Tablet Gamification Flexibility Search Staff Value Business Intelligence Alert IP Address Social Networking Legislation Shortcuts Best Practice Organization Managed IT Fileless Malware Digital Security Cameras File Sharing Buisness Smart Devices Dark Data Ransmoware Legal IT solutions Content Remote Working How To Wearable Technology Memory Vendors Notifications Motherboard Data Breach Recovery Comparison Google Play Be Proactive Business Growth Health IT Directions Videos Travel Assessment Electronic Health Records Hard Drives Permissions Workforce Techology Google Maps Cortana Domains Wasting Time Threats Trend Micro Specifications Security Cameras Workplace Strategies Alt Codes Microchip Unified Threat Management Downtime Internet Exlporer Software as a Service Refrigeration Fraud Meta

Blog Archive