Your company is participating in a Cyber Security Education Program.


This Mailbox Full Phishing Attack included the following social engineering techniques:


  1. Pretexting: A fabricated scenario informing the user that the mailbox is nearly full.
  2. Urgency: The warning that less than 5% of storage remains pressures the recipient to act quickly without carefully verifying the message.
  3. Impersonation: The message appears to come from the organization’s IT department.
  4. Fear and Loss Aversion: The email exploits concern about missing important messages or attachments to motivate the recipient to click.


How to spot this was a phishing email:


  1. Unexpected warning with pressure to act: The message raised an urgent storage problem without prior notice.
  2. Reach out directly to IT through a verified channel to confirm if in doubt. Do not reply to the message.
  3. The sender email address was not associated with your company.
  4. Example: <no-reply@locked-outlook.com>
  5. The link provided used the same unrelated domain as the sender address.




“An employee is either an asset to your cyber security or a risk.”