Your company is participating in a Cyber Security Education Program.
This Mailbox Full Phishing Attack included the following social engineering techniques:
- Pretexting: A fabricated scenario informing the user that the mailbox is nearly full.
- Urgency: The warning that less than 5% of storage remains pressures the recipient to act quickly without carefully verifying the message.
- Impersonation: The message appears to come from the organization’s IT department.
- Fear and Loss Aversion: The email exploits concern about missing important messages or attachments to motivate the recipient to click.
How to spot this was a phishing email:
- Unexpected warning with pressure to act: The message raised an urgent storage problem without prior notice.
- Reach out directly to IT through a verified channel to confirm if in doubt. Do not reply to the message.
- The sender email address was not associated with your company.
- Example: <no-reply@locked-outlook.com>
- The link provided used the same unrelated domain as the sender address.
