Your company is participating in a Cyber Security Education Program.
This Email Password Expiration Phishing Attack included the following social engineering techniques:
- A product you probably use everyday (example: MS Outlook)
- Attackers exploit probability and assume most use this product.
- Urgency in the <subject> to get your attention. (example: expires in 72 h)
- Urgency to act (example: expires in 72 h).
- Most phishing attack emails have a sense of urgency.
- Reference to corporate policy or reason for this action.
- Spoofed domain which appears legitimate (example: msoffice@lang-fr-en.ca).
- Simple clean email to minimize suspicion.
How to spot this was a phishing email:
- Was this an email you expected to receive? No - Be cautious
- Did your IT department advise this needed to happen?
- You should reach out to IT department to confirm.
- Is this a policy which is already in place?
- Why now? - Contact IT department.
- The sender named email address was suspicious (domain is not associated with the your company or software provider.)
- Brining up browser and typing in domain used isn't valid (example: lang-fr-en.ca).
- The link provided used suspicious domain similar to above.