I laughed at our IT guy for forcing password managers on us, then watched a phish take down accounting
Back in March our IT lead made all 40 of us at the Columbus office install a password manager and I rolled my eyes hard, said it was overkill for a small logistics company. Three weeks later someone in accounting clicked a fake DocuSign link and the attacker got into their email, then started replying to real invoice threads from the thread history. The kicker was their password was reused from an old gym account that showed up in some breach dump, so the MFA prompt was the only thing that stopped a wire. I set mine up that same afternoon and I've been the annoying guy reminding people ever since. Am I wrong for thinking we should force this on vendors too, or is that overstepping?
Man, that MFA prompt saving you from a wire is the part that gets me. So the gym password was from an old breach, but how did the attacker know which email login to even try it on? I keep hearing vendors are the weak link because they have their own logins into your systems and nobody watches them. Has your IT lead actually floated a rule for vendors yet, or is that still just you bringing it up in meetings?