9 ms·
Launch HN: Riot (YC W20) – Phishing training for your team
Ahoy Hacker News! I'm Ben, founder of Riot (https://tryriot.com https://tryriot.com), a tool that sends phishing emails to your team to get them ready for real attacks. It's like a fire drill, but for cybersecurity.
Prior to Riot, I was the co-founder and CTO of a fintech company operating hundred of millions of euros of transactions every year. We were under attack continuously. I was doing an hour-long security training once a year, but was always curious if my team was really ready for an attack. In fact, it kept me up at night thinking we were spending a lot of money on protecting our app, but none on preparing the employees for social engineering.
So I started a side project at that previous company to test this out. On the first run, 9% of all the employees got scammed. I was pissed, but it convinced me we needed a better way to train employees for cybersecurity attacks. This is what grew into Riot.
For now we are only training for phishing, but our intention is to grow this into a tool that will continuously prepare your team for good practices (don't reuse passwords for example) and upcoming attacks (CEO fraud is next), in a smart way.
Your questions, feedback, and ideas are most welcome. Would love to hear your war stories on phishing scams, and how you train your teams!
- ttul 6y agoThis is a hot area, but there are already huge competitors. How do you differentiate?
- BenjaminN 6y agoGreat question! 1. From Gophish: you need to be technical and you need at least a week off to prepare the attacks. With Riot, you can be sending attacks in a matter of minutes. 2. From Knowbe4, …: those are products made for enterprise companies, that are trying somehow to adapt to smaller companies. Riot is doing the opposite: it was built with smaller companies in mind. Overall, I think there's a huge need today for product-centric cybersecurity companies, where most of the big players are sales-centric companies.
- bfrit 6y ago> Overall, I think there's a huge need today for product-centric cybersecurity companies, where most of the big players are sales-centric companies. Totally agreed, and I love this. High five from a Techstars 2020 company doing a similar product-first approach to cyber security program planning and implementation for small businesses. We use Webroot as a vendor to supply phishing right now but would love to talk. brian@havocshield.com
- ttul 6y agoSo, to summarize, it's phishing training for small companies. Makes sense.
- elkos 6y agoHonestly I mixed this with riot.im
- BenjaminN 6y agoThat's because you're not a LoL player ;-)
- hombre_fatal 6y agoheh, I appreciate you leaning into it.
- the-pigeon 6y agoLove the idea! Unfortunately the IT group in my company is swamped with COVID-19 related work at the moment. But will be sure to bring it up with them once things calm down a little. My company recently had a user fall for a very poor phishing attack (entered password into a Google Sheets request) so something like this could save IT and the company a lot of money.
- BenjaminN 6y agoSince everyone is moving to remote right now, hackers are enjoying the overall disorganization of companies. I've seen a growing number of phishing attacks for the past few weeks. I wouldn't be surprised if we get a major data leak caused by COVID-19 in the coming days. PS: great username by the way.
- mbs348 6y agoIt’s been honestly pretty fun to run this at BackerKit. Sad to say it caught my COO, but actually more inspiring seeing my team banding together and fighting back and letting folks know in Slack. Also, a bonus, a really cool lean use of Drift which inspired us to use that tool better.
- BenjaminN 6y agoGreat to have BackerKit on board!
- eggbrain 6y agoHow do you work with the service providers you use to host your platform and send out emails (e.g. Heroku / Mailgun) to let them know you are not a malicious phishing company, but an anti-phishing company? I say this because I ended up reporting the phishing email I received from you guys to Mailgun, and I believe accidentally got your account disabled. Sorry about that.
- BenjaminN 6y agoYES you did! I called them just right after that, and I have to say they've been great so far. We agreed I would pay for a dedicated IP, and they now fully support Riot. And having a dedicated IP is actually better, because you can now remove the unexpected warning on Gmail.
- ackbar03 6y agoIf you reported their email you probably passed the test anyways
- jedberg 6y ago> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100% coverage. I wish you luck, but don't get discouraged if it doesn't work. We've been trying to educate people about phishing for 17+ years. :) We shifted our focus to tracking the phishing sites and then tying that back to which user accounts were hacked, and disabling the hacked accounts and notifying the users before damage could be done. PayPal actually holds the patent on what we built, along with a ton of other anti-phishing and phishing site tracking patents.
- BenjaminN 6y agoI actually started coding in 2000 trying to hack my brother, so I can relate: phishing has been a never-ending story. It's still worth trying though!
- jedberg 6y agoDefinitely worth trying! Just want to help you set expectations. :)
- BenjaminN 6y agoThanks!
- johnwheeler 6y agoDid you try punitive disincentives?
- rwmurrayVT 6y agoThe company sends out fake phishing emails. The same people keep falling for it... I suppose the outlined punishments are not strictly enforced.
- equidistant 6y agoThat's an unfortunate business name
- BenjaminN 6y agoDefinitely bad timing. My experience with names: they are never good enough. What I look for in a name: 1. If I say it out loud, you know how to write it. 2. If I say it out loud today, you remember it tomorrow. On that 2 criteria, Riot works quite well I think.
- equidistant 6y agoIt's bad in that there's already a very popular game company named Riot (Games) which everyone refers to as 'Riot'.
- BenjaminN 6y agoSome people know League of Legends, most don't know Riot Games. And I double checked: Riot Games don't own a trademark for anything related to cybersecurity.
- Arathorn 6y agoUnfortunately that doesn't seem to stop them going after companies with Riot in their name (even though Riot is also a dictionary word) :(
- pipework 6y agoWay more people already know riot games and league of legends than will ever know about your security startup, so I don't see what they're upset about for you. Hand-wringing, perhaps?
- thenewnewguy 6y agoDisagree, I have serious doubts you could confuse the two. I can see almost no context where 'Riot (Games)' and 'Riot (Anti-Phish Company)' could be meaningfully confused.
- cones688 6y ago> "I was pissed" How do you balance/deal with "security shaming", which is proven to put you further at risk as an organization? There is some interesting research from the UK Government in this space - https://www.ncsc.gov.uk/blog-post/trouble-phishing#section_3 https://www.ncsc.gov.uk/blog-post/trouble-phishing#section_3 The relevant bit: "If just one user reports a phish, you can get a head start on defending your company against that phishing campaign and every spotted email is one less opportunity for attackers...but phishing your own users isn't your only option. Try being more creative; some companies have had a lot of success with training that gets the participants to craft their own phishing email, giving them a much richer view of the influence techniques used. Others are experimenting with gamification, making a friendly competition between peers, rather than an 'us vs them' situation with security."
- BenjaminN 6y ago1. There's an option to hide the names of the employees. It would replace all the names with random animal name + a color. It's great if you don't want to know which employees are falling for attacks. 2. I love the idea to actually make the employees create their own attacks, but seems a bit hard to do and pretty much time consuming for a company.
- cones688 6y agoIts not the actual individuals - its the culture it creates, "HA! We caught you, you dumbass, here's 2hrs of training". This means people are afraid to report or take ownership over looking out for phishing as it creates no benefit for them, its just there to make the security team smug. Having been part of and designed these campaigns before (with open source options like https://getgophish.com/ https://getgophish.com/), there is no way to report as phishing or reward users who detected but therefore didn't interact with it. This means in your example - did the other 81% just not open it, ignored it, or actively thought it was phishing? These are key metrics a company needs to know their potential attack surface.
- bubblethink 6y ago>How do you balance/deal with "security shaming", which is proven to put you further at risk as an organization? I've had this happen to me, not for phishing, but for the kensington lock thing. Probably not that common any more, at least not in the west, but some workplaces have aggressive laptop locking policies. Workplace tried this stunt of confiscating laptops that were not locked, and everyone had to meet some manager type person. It was completely asinine. This is a typical badge access controlled workplace with additional security personnel. The laptop locks were a total overkill.
- brian_herman__ 6y agoHow do you differentiate yourself with places like https://www.knowbe4.com/ https://www.knowbe4.com/ which offer free services against phishing.
- BenjaminN 6y agoI tried Knowbe4, I think it's a horrible product. I heard once you try the "free service" they call you daily to sign you up for the paid plan.
- thrownaway954 6y agoi used knowbe4 before and I found their product to be very good and easy to use. also i like that they had training videos and assessment tests as part of their packages. i didn't see anything on your site pertaining to this.
- jiveturkey 6y agolike sibling, i found knowbe4 to be pretty good. easy to setup, easy to use, great support, pretty comprehensive. not perfect, mind you, but still pretty good. they do bug the hell out of you but who cares? it's just one of dozens of calls i have to ignore on the daily. i told them to back off and they did. i'll tell you what product is actually horrible, and perhaps ironically so. SANS security training (phishing part relevant here, but the entire suite is horrid). just stay away, don't waste a minnit evaluating it.
- meter 6y agoHow do avoid spam filters when sending your fake phishing emails?
- BenjaminN 6y agoDepending on your email provider (most of the time it's Google), you need to whitelist the IP address I use to send the emails. It takes probably no more than 4 minutes to do.
- mc32 6y agoWhat are the steps necessary to get this up and running? Step 1, 2, 3... Besides signing up. ESP if you have O365 or GApps for mail.
- BenjaminN 6y ago1. Import the list of your employees. 2. Whitelist the IP address we use to send the emails. 3. Activate the "phishing simulation" module. 4. Wait and see. Takes 5 minutes.
- bt3 6y agoI work at a large professional services firm (think Big 4), so the risk of any single breach in our network is taken pretty seriously. Our IT department added an Outlook plugin years ago that you can use to immediately reporting phishing attempts to them. As a bonus, they'll sometimes send these "tests" and if you select to "Report Phishing", you'll get a atta-boy type notification. I would assume at a macro level, they have stats on everyone and know who the "riskier" employees are. I have no idea if this is done inhouse at other large companies. Sidenote/ question for you: some of the "test" attacks my company sends are very specific to the work we're doing and can sometimes sound very convincing. Do you have a catalogue of "attacks" based on industry or department (procurement might fall for something completely different than sales or marketing)? I'm sure with enough tests, you could measure the effectiveness of attacks (or maybe the difficulty of detection)... then you can start rating organizations not just based on what percentage of folks fell for it, but what specifically they fell for, or what was more likely to get them to bite. Almost like targeted training? Cool idea overall and wish you guys the best.
- BenjaminN 6y ago1. I've talked with a lot of companies (Stripe for example) who do that internally and it takes a tremendous amount of time to set up. 2. For now attacks are very generic, but will soon be sector-based and department-based. 3. Yes for sure it's probably worth adapting the pace of the attacks depending on the level of the employees. Thanks for the kind words!
- MalachiC0nstant 6y agoWhy is this any better than product offerings from PhishMe, Wombat, or KnowBe4?
- BenjaminN 6y agoMost of them target big companies. It makes a very different product. I have a fun story with Wombat: I tried to use the product in my previous company (100 employees), had 4 different calls, with 4 different sales persons, during 2 months. At the end they just forgot about me.
- jiveturkey 6y agodon't know about wombat and the other, but how can you say knowbe4 targets big companies? Their SCORM integration is horrible.
- Arathorn 6y agoHi Ben - cool product! Speaking as the lead for Riot.im, I would recommend picking another name asap, if nothing else because Riot Games has an awful lot of lawyers (as we know first hand, unfortunately).
- codegeek 6y agoPricing feedback. I would love this type of training for our small team of 12 people BUT at this time, I cannot spend $199/Month even though one could argue that there is no cost high enough for security. Perhaps add another smaller tier for companies with 20 or less employees in the 2 digit range ?
- BenjaminN 6y agoSure! Pricing is actually very hard to set up.
- jtthe13 6y ago100% agree. CEO of 13 people services biz here. We're currently priced out of this when it could actually be useful. One thing of note: when we consider security tools / training, monthly is not the right frame of reference. It's either brought back to a daily expense (i.e. how does it compare in my daily costing vs. billed revenue per day), or annually, compared to an insurance premium. I know ho much my cyber liability insurance costs me and it's easier to compare on a yearly basis. FWIW, it would be an instant buy for us at 199 per year. Above this, it'll fall in the budget security bucket and under comparison with others.
- Kkoala 6y agoSeems to be a hot topic recently. I first discovered https://www.hoxhunt.com/ https://www.hoxhunt.com/, there are probably some other competitors as well, what makes you different?
- tomashertus 6y agoI would be interesting in this answer as well. There is actually quite heave competition in this space: PhishMe, PhishLabs, IronScales, MediaPro, KnowBe4, Wombat (acquired by ProofPoint). What convinced YC to invest in your company?
- thejournalizer 6y agoNot OP, but I will say, of those companies, only two or so really focus on this as the market is incredibly saturated. For example, Attack Simulator via Microsoft was recently announced, and their O365 brand is one of the most abused. Most have acquired other organizations to find higher ground.
- thedrake 6y agoOne that is happening in nearly every parish is that scammers are using church bulletins to get the personal info and then sending a "message" from the priest to those people. So while not CEO fraud it is very similar. A great setup and one that you could find a way that you charge when teams are doing the right thing... have the test be free and the training have a cost
- bearcobra 6y agoMy company uses Knowbe4, and I'm constantly frustrated how it considers it a fail if I only click a link vs entering in credentials. Sometimes it's tough to tell if something is phishing when your checking email on your phone. Does Riot work the same way? Or do you test to see if users notice issues once they've actually opened something in the browser?
- jiveturkey 6y agoThat's not a knowbe4 thing, that's your company's choice. opened/clicked/creds and so forth are various levels. Your company has decided that a mere click is a fail. also, in gmail, if you 'report phishing' (without clicking), gmail will "click" it for you as part of their back-end analysis. this will show up in the click report. this type of click is distinguishable from a user click, but it's not obvious and knowbe4 has zero docs on it. Keep in mind, a mere click can in fact be a fail. There are still drive-by attacks that work simply by clicking.
- mike_d 6y ago> I'm constantly frustrated how it considers it a fail if I only click a link vs entering in credentials That is a failure. There is currently a Windows font parsing vulnerability that is being exploited in the wild just like this. If you click the link, you are subjecting your browser and OS to an attacker crafted payload.
- rsync 6y agoI wonder if you can comment on the weirdly pro-phishing behavior of many US banks who, if I didn't know better, appear to be trying hard to make their customers vulnerable to phishing attacks ... - TIAA Bank redirects customers, after login, to "cibng.ibanking-services.com". - US Bank, depending on which account you log into will redirect you to "loansphereservicingdigital.bkiconnect.com". - Union Bank will redirect you to "unionbank.customercarenet.com" if you look at a mortgage account. These are big, serious US Banks and these domain jumpings (to domains that almost look like parodies of an actual bank domain) occur to every online banking customer. They are training their customers to be phished. FWIW, I have never seen Wells Fargo do this ...
- dmurray 6y agoMy bank in Ireland (Ulster Bank) has a notice on the login page: "You will NEVER need your card reader [their 2FA] to log in". Last year they changed their login flow so you are asked to use your card reader to log in. I complained about it on Twitter but got a meaningless response about customer safety/new regulations. If they wanted to train their customers to be phished, I can't think how they could do a better job.
- jiveturkey 6y agoYou are double the price of knowbe4. How do you expect to possibly compete?
- BenjaminN 6y agoThe pricing is a work in progress.
- Nuzzerino 6y agoSo we have Riot Games, Riot.im, and now this. As if two wasn't enough confusion.
- ph0rque 6y agoTrue story (except for the last two lines): Boss: install this antivirus and run it: [link]. Me: I dunno, that seems like a phishing attempt... is that really you, boss? What's the code word? Boss: DO IT OR YOU ARE FIRED! Me: oh yeah, definitely you; installing it right now.
- jaredwiener 6y agoCurious how you differ from Cofense Phishme? https://cofense.com/ https://cofense.com/
- skocznymroczny 6y agoAt the company I work at they send phishing training emails every now and then. Luckily, the email headers have special fields, so that the IT firewall lets the "spam" through. I managed to set up a rule in my outlook to catch these headers and move all the emails to a special "Phish" folder.
- igammarays 6y agoEveryone's vulnerable to phishing, no matter how technically literate. It's too easy to click through an email during a moment of inattention. I've often thought that the only way to reliably prevent phishing is to enforce the use of a password manager browser extension, which will refuse to enter a saved password except on the original domain. Nobody should ever be manually typing passwords, or even copy-pasting passwords (in the rare case copying becomes necessary, it should be done with a big bold warning). A safer, phish-proof enterprise password manager may be your killer product here.
- jujodi 6y agoFor some reason I thought this was the pitch and I LOVE this idea. Is it possible for a password manager plugin to capture your "paste" and verify the window url? I know there's an onpaste clipboard event so sure seems like this would be possible.
- cyphar 6y agoPassword managers that have browser integration already function this way -- you have to go out of your way to copy-paste your password. The main problem is that some sites design their login forms to make this kind of functionality harder (such as putting the password and username fields on different pages, or having strange layouts where you need to also input your last name, and so on). I personally use KeepassXC which has a browser plugin that does this for you (and it's nice that the plugin doesn't have access to your passwords directly -- it has to request access from the password manager which be default gives you a popup asking for permission to share specific credentials).
- jujodi 6y agoThe only time that a phishing attempt actually worked for our company (afaik) occurred when someone emailed an executive in our company (ugh) with a docusign looking email with content that he was EXPECTING. it redirected him to a fake Active Directory sign in link that he fell for. Immediately after entering his password his outlook spammed his entire contact list with the same phish except addressed to them specifically from his actual email, with a link that looked like a shared Office 365 document. It wasn't good.
- BenjaminN 6y agoI had this exact same attack in my previous company, and it spread quite rapidly.
- 0898 6y agoThe copy in your post is great. I understood what you do straight away.
- BenjaminN 6y agoThanks!
- BlackFly 6y agoI always thought the point of fire drills was to inure people to them so that in case of an emergency they would just blasély treat it like a drill instead of panicking: you want them to treat a real positive like a false positive. Injecting false positives generally can impair quality and whether or not quality will be impaired or improved with false positives is really context dependent. Indeed, low false positive rates are often used as a measure of quality, so in generally you don't want to increase them carelessly. In the case of things like phishing training, I imagine (but I could be wrong) that the injection of false positives just causes the people who recognize phishing emails to ignore them instead of reporting them: there is too much noise and too little signal. The people who don't recognize them will continue to fall victim. In that case, inuring the knowledgeable seems detrimental since you lose the likelihood of receiving a report. I follow inbox zero practices and routinely delete all my email. Since forwarding a phishing email to security is a lot more complicated then hitting the delete key (like I probably just did for another email) I'm personally most likely to delete phishing emails unless I am getting them very rarely or it seems especially pernicious. Indeed, most of the phishing emails I receive lack a certain phishy feeling (like lacking a DKIM signature or other weird mail header shenanigans). I generally just assume they are these sorts of false positives.
- higb 6y agoI invented this space. Ask me anything. Aaron Higbee
- olegious 6y agoGreat idea, just some copywriting fixes: 1. "runs the latest scams techniques on your team" should be "runs the latest scam techniques on your team" 2. "trainings" while technically a word, native English speakers will find it odd as you rarely see it used. use "training" instead, ex: "We get it: trainings are annoying" to "We get it: training is annoying" 3. "Riot offers an interactive, tailor-made 5-minutes training your employees will actually enjoy and learn from." to "Riot offers an interactive, tailor-made, 5-minute training your employees will actually enjoy and learn from." 4. "Riot will perform attacks and trainings on your team" to "Riot will perform attacks and training for your team"