The IT security department at Hendricks & Vale, a procurement consultancy based in Swindon, marked a significant milestone on Tuesday by acknowledging the fifth anniversary of an email that precisely none of its 247 recipients have ever opened.
The message, sent at 09:47 on 14 March 2019 with the subject line “IMPORTANT: Updated Password Security Protocols and Multi-Factor Authentication Guidance”, remains unopened in 183 inboxes, deleted unread from 62, and mistakenly filed under “Read Later” in two others. Its 4.2MB PDF attachment, which outlined a comprehensive approach to credential management over seventeen pages, has been downloaded zero times.
To commemorate the occasion, the three-person security team shared a Tesco Finest lemon drizzle cake in Meeting Room C during their lunch break. No candles were lit.
“We had hopes, initially, that the all-caps subject line might convey some sense of urgency,” said David Marsh, the department’s senior security analyst, who authored the original email during what he now describes as a period of misplaced optimism. “We even considered adding one of those red exclamation marks in Outlook, but decided that might be seen as alarmist.”
The anniversary comes during a year in which Hendricks & Vale has experienced six successful phishing attacks, four cases of password-sharing via Post-it notes affixed to monitors, and one incident wherein an employee named their laptop password “Password123” after receiving, but not reading, three separate emails explaining why they should not do precisely that.
Jennifer Holbrook, who works in accounts payable and once accidentally forwarded a credential-harvesting scam to the entire finance department, said she had “a vague memory” of an email from IT a few years ago. “I think I meant to read it,” she added, “but it looked quite long and I was waiting for a delivery.”
The security team has continued its awareness work undeterred, having since dispatched a further 73 guidance emails on subjects ranging from ransomware identification to the dangers of public Wi-Fi networks. The average read rate across all these communications currently stands at 4.7 per cent, a figure Marsh describes as “not as catastrophic as it could be, technically speaking”.
When asked whether the team planned any special measures to mark the anniversary, Marsh indicated that he had briefly considered resending the original email with “URGENT” added to the subject line, but ultimately decided that such an approach might come across as “a bit desperate”.
The cake, he confirmed, was very nice. Moist, even. He had saved a slice for his colleague who was working from home, though he suspected it would go uneaten, much like the guidance it commemorated.