Malmö University carried out a staged cyberattack last fall. One in ten employees, including senior managers, fell for the trap and gave away sensitive user data, reports Southern Swedish.
In October, the university's 1,800 employees received an email with questions about vacation pay that appeared to come from the HR department.
Only the rector, Kerstin Tham, knew about the scam. The university's internal audit had hired IT security experts to review the security mindset of the employees.
A total of 209 people clicked on the phishing link in the email. Of those, 179 people went ahead and provided their login details, meaning one in ten employees, according to Sydsvenskan.
”"The review has been conducted against the background that this is a highly relevant risk for all actors today, including authorities, municipalities, regions and the business community," says Jean Odgaard, head of internal audit, to the newspaper.
The review continued in November with prefects and other managers. Two out of eighteen managers, or eleven percent, clicked on the fake link and provided information.
According to University Director Susanne Wallmark, this is the first time a Swedish university has done something similar.
”"Now we will work on measures to increase security," she tells Sydsvenskan.
Source: TT-DI.SE








