Relax — this was an exercise
This was a simulated phishing email
It was sent by <ORGANISATION> as part of our security awareness programme.
No harm was done, and nothing has been reported about you personally.
It is worth thirty seconds to see what gave it away
- The sender address did not match the organisation it claimed to come from —
the display name looked right, the address behind it did not.
- The request created urgency — a deadline, a threatened suspension, or a problem
needing immediate action. Urgency is the single most reliable phishing signal.
- The link destination differed from the text of the link. Hovering over it
(or long-pressing on mobile) would have shown the real address.
- The greeting was generic where a genuine message from this sender would have
used your name.
<OPTIONAL: 90-second explainer video embedded here>
What to do next time
Do not act on the message. Use the Report Phishing button in your email client.
That takes one click, it protects your colleagues, and it is the single most valuable
security action available to you.
If you have already entered a password or personal information in response to a message
you now suspect, contact <SECURITY CONTACT> immediately. You will not be
blamed — reporting fast is what limits the damage.
Contact the security team
Should you feel distressed or anxious, our
<medical staff / psychologists / social workers> are there for you. Please contact them.