One in four US Postal Service (USPS) employees clicked on a phishing email designed to test their security, highlighting the ongoing challenge companies face in training their staff to be prepared to spot potential cyber attacks.
The Office of Inspector General conducted this employee test in May and the results were announced last week.
He claims that the Postal Service runs one of the largest corporate email systems in the US, with over 3.5 million emails sent to more than 200,000 accounts per day.
Despite this, the results were particularly disappointing, as 789 of the 3,125 employees who took part in the test took the bait and clicked on the link contained in the phishing email.
And as if that weren't enough, 93% of those who received the email in question didn't even report it to the company's Computer Incident Response Team, as its policy dictates.
The test revealed that 95% of those who clicked on the phishing link and 96% of those who took the test did not complete the annual information security awareness training conducted by the Postal Service.
It should be noted that the same audit was conducted in November 2014 after a major cyber attack that hit the company, which is believed to have started with a simple phishing email.
The personal data of employees and customers who called the USPS call center between January and August is believed to have been exposed as part of this attack.
The company's media relations manager, Mr. David Partenheimer, explains that the exposed information related to employees may have included information such as names, dates of birth, Social Security numbers, addresses, emergency contact information, and so on
However, he assures USPS customers that no information regarding their credit cards or other financial details was stolen.

