This was a simulated phishing test run by
Hill & Smith Group IT. No credentials were captured and nothing you typed was
stored or transmitted.
What to look for next time
- Check the sender's domain, not the display name. Display names are
trivial to fake; the domain after the @ is the part that matters.
- Hover the link before clicking. The address in the status bar is
where you are actually going.
- Be suspicious of urgency. Deadlines, threats of account closure and
"action required today" exist to stop you checking.
- Never enter your password on a page you reached from an email. Open
the application yourself from your browser or the company portal.
If in doubt, report it. Use the Report Phishing button in Outlook.
Reporting is always the right call, and reporting something genuine is never a mistake.