This Was A Phishing Simulation

This email and sign-in page were part of a security awareness exercise conducted by ARE IT.

The exercise was designed to demonstrate how a realistic phishing email can lead to a fake sign-in page.

No Microsoft password was requested or collected as part of this simulation.

What should have raised suspicion?

  • The email was unexpected and concerned an invoice.
  • The email encouraged you to click a link to view an invoice and supporting documents.
  • The link took you to a sign-in page rather than requiring you to access the supplier's website directly.
  • The page presented a Microsoft sign-in in the context of a supplier invoice.
  • The sender address was [email protected]. The displayed sender name alone is not proof that an email is genuine.

Indicators of compromise

Unexpected invoice request The email created an urgent reason to access an invoice and supporting documents.
Sign-in link The email directed you to a sign-in page instead of asking you to access the supplier service directly.

Why your Microsoft account matters

Your Microsoft account is used to access multiple ARE applications and services.

It is also used to sign in to your ARE laptop and access your email.

This means that a compromised Microsoft account could provide access to more than just your email.

Treat unexpected Microsoft sign-in requests seriously, especially when you reach them through a link in an email.

What should you do?

If you receive an unexpected email asking you to sign in, stop before entering your credentials.

Check the sender, the link destination and the context of the request. If you are unsure, contact IT before continuing.

Have questions?

If you have any questions about this simulation or phishing emails, contact [email protected] .