Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Homeland Security Is Spending $1 Billion on ‘Autonomous’ Border Surveillance Towers

23 minutes ago

Nolan’s Odyssey Review: Beautiful but Dreary

32 minutes ago

Crypto exchange Luno cuts 20% of staff amid automation push and retail trading slumps

42 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Friday, July 31
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»News»Media & Culture»Lawyer Challenges Suspension for Being Too Phishable; No Dice, Says Appellate Court
Media & Culture

Lawyer Challenges Suspension for Being Too Phishable; No Dice, Says Appellate Court

News RoomBy News Room1 hour agoNo Comments7 Mins Read450 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

From Bedrossian v. Cal. State Pers. Bd., decided Tuesday by California Court of Appeal Justice Frances Rothschild, joined by Justices Gregory Weingart and Michelle Kim:

The [State Compensation Insurance Fund] employed Bedrossian as a staff attorney beginning in March 2004 and ultimately promoted her to attorney IV. In the latter position, she was responsible for litigating worker’s compensation cases involving “confidential and sensitive information.” A “duty statement” Bedrossian signed lists among her responsibilities as an attorney IV “[m]aintain[ing] user mastery over [the Fund’s] computer-based technology” and “communicat[ing] professionally and efficiently.” …

The Fund “require[s] that all employees take [cyber]security awareness and privacy training annually so that they can recognize external threats such as phishing and other social engineering tactics.” “Phishing” refers to the process of sending emails purporting to be from a legitimate source and encouraging the recipient to “click on … a malicious link” or attachment or provide sensitive information. “If a phishing email is successful, [it] can either steal data from the user,” “compromise the user’s account,” or “compromise the entire system” of an organization.

Over the course of her employment at the Fund, Bedrossian participated in numerous training sessions on how to identify and handle phishing emails. This training educated employees about “red flags” which should alert the reader that an email is potentially dangerous, such as asking the recipient to click a link to avoid a negative consequence. In 2019, the Fund began automatically adding an “external sender notification” banner on all emails from outside the Fund, which reminded the recipient in yellow highlighted text that the email “was sent from outside [the Fund]” and not to click on links or open attachments “unless you recognize the source and know the content is safe.” …

[1.] Phishing Email Test Campaign

In 2018, the Fund security department circulated a memorandum to all employees announcing the Fund was starting “organization-wide security phishing awareness tests … on a regular basis to test [employees’] security awareness knowledge.” These tests involved the Fund sending emails “to all 4000 [Fund] employees in a randomized fashion”—that is, in “groups of employees at a time, at different dates and times.”

The test emails “mirrored what a real phishing email might look like. When an employee clicked on links contained [therein] …, replied to the emails, or opened [an] attachment, [the employee was] deemed to have ‘failed’ the test. Simply opening the phishing test emails did not trigger a failure result, nor did hovering over a link.” The memorandum informed employees that those “who click on a phishing test email [would] receive counseling and reinforcement training,” and that “[r]epeated violations may result in formal disciplinary action.”

[2.] Bedrossian’s Failed Tests Resulting in Additional Training Effort

Between December 2021 and December 2022, Bedrossian failed three phishing tests. As a result of the first failed test, she was required to participate in remedial cybersecurity training sessions in the form of both “recorded trainings as well as one-on-one coaching.” These training sessions failed to alleviate the problem; Bedrossian failed two more tests, after which the Fund suspended her for five days. That suspension is the subject of the writ petition ruling before us on appeal.

On December 21, 2021, Bedrossian received a phishing test email purporting to be authored by a Fund employee, but from a non-Fund email address. It instructed the recipient to click on a link and enter an email address and password. Bedrossian opened the email with her Fund-issued mobile phone and clicked the link.

The Fund issued her a memorandum “remind[ing] [her] of the dangers of phishing attacks” and required her, inter alia, to participate in a one-on-one security awareness training session with a Fund security analyst. At the beginning of that February 2022 training session, the analyst informed Bedrossian that the analyst was “solely there to provide training,” and “[a]ny questions … in regards to the personnel actions” should be directed to human resources or Bedrossian’s supervisor.

Bedrossian “became very abrupt, very rude, disrespectful, [and] started … ask[ing] … all kinds of questions that had nothing to do with the training,” “making accusations,” and “being very belittling.” For example, Bedrossian asked the analyst “about the number of employees who received the test emails, and whether specific individuals were targeted to receive them. [Bedrossian] accused [the analyst] of not being a [Fund] employee and of being improperly supplied with private information about [Bedrossian].”

The analyst felt she could not continue the session and ended it “within the first few minutes.” Later that day, Bedrossian emailed the analyst and the analyst’s supervisor accusing the security department of trying to entrap employees and unfairly targeting Bedrossian with the phishing test email.

{The following is a representative excerpt from Bedrossian’s February 11, 2022 email: “You are not on the employee list and neither is your boss. You have private information that … HR or IT is supplying you with in order to ‘catch the employees’…. You would not answer my questions about how many employees you targeted on 12/21/21 at 3:50 p.m. with the phishing email. You indicated that it was not done through the whole 4000 employees. You said it was random and yet you would not give me information how you knew that my computer was having issues with hacking. When I asked about your affiliation with IT or HR and your boss[‘s] name you refused to give me an answer and hung up on me. This is not proper procedure….

“Are you an independent vendor providing services for [the Fund]. Are you hired by IT or HR to conduct these tests on their behalf. I want to know your boss[‘s] name. I want to know how many people were on the mailing list on 12/21/21 at 3:50 p.m. How did you designate who will be on the specific targeted email? Who is giving you the private information for you to gear it to those people?”}

On May 11, 2022, Bedrossian received a phishing test email purporting to be from state vehicle registration. It instructed her to click on links to renew her license and registration in order to avoid penalties. Bedrossian opened it on her Fund-issued mobile phone and clicked the link. Bedrossian again received a memorandum from her supervisor admonishing her about this failed test.

On December 9, 2022, Bedrossian received a phishing test email from wework@invite-workplace.com inviting her to accept an invitation to a new WeWork account by clicking on a link. The Fund does not use WeWork. Bedrossian opened the email and clicked on the link.

Bedrossian was suspended without pay for five days, based on “Bedrossian’s failed phishing tests and her interactions with the security analyst and Fund personnel about the December 2021 test.” She challenged that in trial court and on appeal, but lost. An excerpt:

Bedrossian argues we must reverse and grant her petition because her failed phishing tests did not harm, or create a risk of harm to, public service. [California precedent] identifies “‘[h]arm to the public service'” from an employee’s conduct, or risk thereof, as a key factor in assessing whether discipline imposed for that conduct was excessive and thus an abuse of discretion. We need not consider whether her actions actually resulted in harm, because we agree with the trial court that Bedrossian’s clicking links in emails containing red flags, “if repeated[,] is likely to result in, ‘[h]arm to the public service …'” by compromising data the Fund has a fiduciary obligation to protect. (Ibid.) In addition, because “[c]ooperation among public employees is essential to the smooth functioning of public service,” Bedrossian’s discourteous behavior toward the security analyst harms the Fund’s public service efforts as well….

Bedrossian next argues the discipline imposed was unlawful because it was the result of fraud, entrapment, and larceny, and constitutes an unconstitutional restriction on free speech. We agree with the court below that Bedrossian forfeited these arguments by not raising them before the SPB [State Personnel Board]….

Michael J. Monteiro represents the Fund.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

#Democracy #InformationWar #MediaBias #MediaEthics #PoliticalNews
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

Homeland Security Is Spending $1 Billion on ‘Autonomous’ Border Surveillance Towers

23 minutes ago
Debates

Nolan’s Odyssey Review: Beautiful but Dreary

32 minutes ago
Debates

What Nolan’s Film Can’t Capture

2 hours ago
Media & Culture

John Oliver Dares Buc-ee’s To Sue Him Over Trademark Infringement

2 hours ago
Media & Culture

Trump’s New Director of National Intelligence Is a Menace to Liberty

2 hours ago
Media & Culture

The Bond Market Is Unhappy With the Federal Reserve’s Unwillingness To Fight Inflation

3 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Nolan’s Odyssey Review: Beautiful but Dreary

32 minutes ago

Crypto exchange Luno cuts 20% of staff amid automation push and retail trading slumps

42 minutes ago

Crypto’s Next Altseason May Have Fewer Winners: Wintermute

42 minutes ago

Lawyer Challenges Suspension for Being Too Phishable; No Dice, Says Appellate Court

1 hour ago
Latest Posts

What Nolan’s Film Can’t Capture

2 hours ago

Crypto’s resilience is tested as oil surges back above $90 and the Fed signals rates could still rise

2 hours ago

Senator Schumer Proposes Agency to Address Corruption, Including Trump’s Crypto Ventures

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Homeland Security Is Spending $1 Billion on ‘Autonomous’ Border Surveillance Towers

23 minutes ago

Nolan’s Odyssey Review: Beautiful but Dreary

32 minutes ago

Crypto exchange Luno cuts 20% of staff amid automation push and retail trading slumps

42 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.