• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • LOGIN
  • Law Office ManagerHOME
  • Book StoreBook Store
  • WebinarsWebinars
  • LOGIN
  • Manage Your Account
  •  
Law Office Manager

Law Office Manager

  • Hiring
  • Increasing profits
  • Technology
  • Billing
  • Managing staff
  • More! ⇩
    • Newsletter Archive
    • Time tracking
    • Client relations
    • Termination
    • Tool Box
    • Risk management
    • Recordkeeping
    • Cartoons
    • Reader tips
    • Purchasing & leasing
    • Marketing
    • Managing the office
    • Information security
    • Your career
    • Working with lawyers
    • Employee benefits
    • Compliance
    • Workplace Safety
  • Special Reports

Top 10 phishing phrases of 2018: The KnowBe4 list

March 29, 2019

By Jay Stromberg  bio

As you may know, Savvy is the largest reseller in the legal industry for KnowBe4 security awareness training. We are seriously proud of this partnership because of the significant security improvements that KnowBe4 has delivered to our clients. At a time when law firms are hacked into daily, this training platform is delivering quantifiable results that translate into bottom-line improvements. (Imagine the dollars lost from security breaches.)

KnowBe4 reports every quarter on the top-clicked phishing emails. Here are the results for Q4 2018. KnowBe4’s analysts tracked three different categories: general email subjects, those related to social media, and “in the wild” attacks. The results come from a combination of the simulated phishing emails used by KnowBe4 customers, as well as from the millions of users that click the platform’s free Phish Alert Button to report suspicious emails to their IT department.

Trends that persisted throughout 2018

In reviewing the Q4 2018 most-clicked-subject lines, trends were easily identified: five subject line categories appeared quarter-over-quarter throughout 2018, including:

  • Deliveries
  • Passwords
  • Company Policies
  • Vacation
  • IT Department (in-the-wild)

The subject lines tell us users are concerned about security

“Clicking an email is as much about human psychology as it is about accomplishing a task,” said Perry Carpenter, chief evangelist and strategy officer at KnowBe4. “The fact that we saw ‘password’ subject lines clicked four out of four quarters shows us that users are concerned about security. Likewise, users clicked on messages about company policies and deliveries each quarter showing a general curiosity about issues that matter to them. Knowing this information gives corporate IT departments tangible data to share with their users and to help them understand how to think before they click.”

Top 10 most-clicked general email subjects in Q4 2018

KnowBe4 compiled the top 10 list of the most-clicked subject line topics in the fourth quarter of 2018. Drumroll please:

  1. Password Check Required Immediately/Change of Password Required Immediately 19%
  2. Your Order with com/Your Amazon Order Receipt 16%
  3. Announcement: Change in Holiday Schedule 11%
  4. Happy Holidays! Have a drink on us. 10%
  5. Problem with the Bank Account 8%
  6. De-activation of [[email]] in Process 8%
  7. Wire Department 8%
  8. Revised Vacation & Sick Time Policy 7%
  9. Last reminder: please respond immediately 6%
  10. UPS Label Delivery 1ZBE312TNY00015011 6%

*Capitalization and spelling are as they were in the phishing test subject line.

**Email subject lines are a combination of both simulated phishing templates created by KnowBe4 for clients, and custom tests designed by KnowBe4 customers.

Most common ‘in the wild’ attacks in this period were:

  1. Apple: You recently requested a password reset for your Apple ID 
  2. Employee Satisfaction Survey
  3. Sharepoint: You Have Received 2 New Fax Messages
  4. Your Support Ticket is Closing
  5. Docusign: You’ve received a Document for Signature
  6. ZipRecruiter: ZipRecruiter Account Suspended
  7. IT System Support
  8. Amazon: Your Order Summary
  9. Office 365: Suspicious Activity Report
  10. Squarespace: Account billing failure

*Capitalization and spelling are as they were in the phishing test subject line.

**In-the-wild email subject lines represent actual emails users received and reported to their IT departments as suspicious. They are not simulated phishing test emails.

To see a nifty infographic from KnowBe4 on these results, click here.

Free phish alert button

Would you like a free way to protect your firm?

When prominent phishing emails hit your organization, it is vital that IT staff be alerted immediately. The phish alert button allows your users to report suspicious and potentially dangerous phishing emails when they slip past other security layers. It is a safe way for users to forward email threats to your security team for analysis and deletes the email from their inbox to prevent future exposure.

A few benefits of this button include:

  • It reinforces your organization’s security culture
  • Users can report suspicious emails with just one click
  • Incident response gets early phishing alerts from users, creating a network of “sensors”
  • Email is deleted from the user’s inbox to prevent future exposure
  • Easy deployment via MSI file for Outlook, G Suite deployment for Gmail (Chrome)

To get a free KnowBe4 phish alert button for your firm, contact Savvy today! I can quickly set you up.


About Savvy Training & Consulting: For over 20 years, Savvy Training & Consulting has been the training partner of choice for the legal industry. Other generic training companies may say they understand the needs of law firms, but the people at Savvy have lived and breathed the cultural, budgetary and structural challenges that are unique to the legal industry. We’ve been law firm insiders. Today, we use our exclusive insights to deliver turnkey and custom-designed content, products and services to law firms. And we do it all for less than the other guys. Our work translates directly into higher earning power for law firms throughout the United States, Canada and Europe.


Editor’s picks:

Is a false sense of confidence among your employees exposing your practice to costly phishing emails?


Gone phishin’: CyLab researchers find our ability to spot phishing emails is far from perfect


Worried about a data breach? Here’s why you should be


Filed Under: Topics, Information security, Managing staff, Managing the office, Risk management, Working with lawyers, articles Tagged With: cybersecurity, phishing, emails, hacking, security breaches

Primary Sidebar

Free Reports

    • Guide to Advanced Hiring Techniques
    • Employee Morale in the Law Office
    • Workplace Bullying

Free Premium Reports

    • 7 Smart Cost-Cutting Strategies for Your Law Office
    • Guide to Advanced Hiring Techniques
    • Employee Morale in the Law Office
    • Workplace Bullying
    • 7 Proven Ways to Make Your Billing and Collections More Profitable
    • 7 Simple, Proven Steps to Hiring the Right Staff
    • 7 Policies Every Law Office Should Have

Download Current Issue

Current Issue

Recent Headlines

8 Proven Ways to Totally Destroy Your Credibility as a Manager

How to Communicate New Raised Rates for 2026 to Your Clients

The Benefit of a Wind-Down Ritual

17 Proofreading Tips for the Law Office

Budgeting and Planning for Long-Term Stability

Your Career

8 Proven Ways to Totally Destroy Your Credibility as a Manager

The Benefit of a Wind-Down Ritual

17 Proofreading Tips for the Law Office

Top 10 Essential Skills Every Law Office Manager Needs to Succeed

How to Unplug from Work Over the Thanksgiving Holiday

Deliver Your Message

Footer

Return to the Top

Download the Current issue
Monthly Magazine Archive
Advertise in Law Office Manager
Download Media Kit

Become a Premium Member
Download a Sample Issue of LOM
Renew your Law Office Manager Membership
Manage Your Account
Contact Law Office Manager
About Law Office Manager
Terms & Conditions
Privacy Policy
Give Us Feedback


Copyright © 2025 Plain Language Media, LLLP • 1-888-729-2315