What should have raised suspicion?
- The email was unexpected and concerned an invoice.
- The email encouraged you to click a link to view an invoice and supporting documents.
- The link took you to a sign-in page rather than requiring you to access the supplier's website directly.
- The page presented a Microsoft sign-in in the context of a supplier invoice.
- The sender address was [email protected]. The displayed sender name alone is not proof that an email is genuine.
Indicators of compromise
Why your Microsoft account matters
Your Microsoft account is used to access multiple ARE applications and services.
It is also used to sign in to your ARE laptop and access your email.
This means that a compromised Microsoft account could provide access to more than just your email.
Treat unexpected Microsoft sign-in requests seriously, especially when you reach them through a link in an email.
What should you do?
If you receive an unexpected email asking you to sign in, stop before entering your credentials.
Check the sender, the link destination and the context of the request. If you are unsure, contact IT before continuing.
If you have any questions about this simulation or phishing emails, contact [email protected] .