AJCxZ0<p>How average folks don't stand a chance against phishing, example #79,144,823: Citi Wealth / Salesforce</p><p>• Email from Citi Wealth <CPWM@personalwealthmanagement.citi.com><br>• Multiple links in HTML email including "Read More", "Unsubscribe", and "Read additional Important Information" to click.personalwealthmanagement.citi.com are all insecure (http://)<br>• There is no secure connection for the site</p><p>According to Wikipedia, "Citigroup is the third-largest banking institution in the United States by assets" with 2023 revenue of US$78.46 billion and US$2.412 trillion in assets.<br>I'd joke about how this isn't enough to afford a free certificate or training on how to not teach customers to click on insecure links, but the site is operated by a little under-resourced company with limited technical expertise: Salesforce.</p><p><a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/Citi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Citi</span></a> <a href="https://infosec.exchange/tags/CitiGroup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CitiGroup</span></a> <a href="https://infosec.exchange/tags/CitiWealth" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CitiWealth</span></a> <a href="https://infosec.exchange/tags/Salesforce" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Salesforce</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/InformationSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InformationSecurity</span></a> <a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a></p>