NBS Phishing Simulation

That password-change email was a test. You clicked it.

No harm has been done. The "Change Your Google Account Password" email you acted on was sent by the NBS Offsec Team as part of a controlled phishing simulation. Nothing was installed, no credentials were captured, and this is not a disciplinary matter. It was written to look completely routine which is exactly the point. Take two minutes to see what should still have made you pause.

Campaign
NBS-INTERNAL PHISH-SIM 2026
Sent by
Offsec Team
Data captured
None

The email you received

It looked official - it even included a security reminder. Six things in it should still have made you stop.

Specimen - simulated phishing email
From: Administrator 1[email protected]
To: 2[email protected]
Subject: Action Required: Change Your Google Account Password

Hi All,

As part of our ongoing Information Security activities, and in support of the requirements of ISO/IEC 27001:2022, 3all staff are required to change their Google account password.

Please change your password using Google's official account page by 9 September 2026:

  • Go to myaccount.google.com/security → How you sign in to Google → Password
  • Alternatively, open Manage your Google Account from your profile picture.

Your new password must:

  • be at least 12 characters long;
  • not reuse any previous password; and
  • not contain your name, username, or the company name.

Once you have changed your password, complete the acknowledgement form below to confirm completion:

4Password Change Acknowledgement Form: https://forms.clickup.com/1851634/f/1rg7j-57156/…

5All staff are required to complete this by the stated deadline. Staff who have not completed the password change and acknowledgement by the deadline will be identified and mentioned in the designated channel for follow-up.

6Reminder: IT will never ask you for your password by email, chat, or phone. Never enter your password on any page other than Google's own sign-in screen.

Thank you for your cooperation and continued commitment to information security.

Regards,
Administrator

What should have made you pause

None of these are typos. Good lures rarely have any.

  1. 1

    A lookalike sender that isn't really us

    The email came from "Administrator" at [email protected] - read it carefully. Our real domain is netbytesecurity.com; this one quietly drops a letter from "byte". A domain a single character off is one of the oldest impersonation tricks there is, and an impersonal "Administrator" sending from it is a red flag on its own. Genuine notices come from a named colleague (e.g. Naimah) on our own domain - always read the address behind the display name.

  2. 2

    Addressed to you alone, not the whole team

    The message opens with "Hi All" and claims to be for "all staff", yet it arrived addressed to [email protected] on its own. Genuine all-staff notices are sent to a group or distribution address (for example [email protected]), not to you as a single named recipient. When the audience an email claims and the way it's actually addressed don't line up, treat it as suspect.

  3. 3

    This is not how NBS asks you to change a password

    NBS does not send emails telling staff to go and change their password. When a reset is genuinely required, it's enforced at sign-in through our identity provider - you're prompted the next time you log in. An unsolicited email demanding a password change is one of the most common phishing pretexts there is, and here it doesn't match any process we actually run. Citing ISO 27001 doesn't make it real.

  4. 4

    A link to an outside site asking you to act

    The real Google links were a decoy of legitimacy which the action that actually mattered was the external form you were told to "confirm" on. That's the exact move a real attacker uses: swap that form for a page that captures your Google login, and a credential is stolen. Hover any link (long-press on mobile) and read the true destination before you click. A security email that sends you off-domain to confirm or sign in deserves a second look every time.

  5. 5

    A deadline backed by a social threat

    "Identified and mentioned in the designated channel for follow-up" is pressure - fear of being named makes people act before they think. Urgency and consequence are persuasion tools, not proof the message is real.

  6. 6

    A security reminder doesn't make an email safe

    This message even warned you never to hand over your password and that reassurance is precisely what made it more convincing. Attackers copy the trust signals of real IT notices, including anti-phishing reminders, to lower your guard. Judge an email by its sender and what it asks you to do, never by how security-aware it sounds.

Key takeaways

When a message feels off, work through these four steps.

Stop

Don't click, reply, or download. Pause before you act on it.

Check

Verify the sender's real address and hover any links before trusting them.

Report

Report suspicious messages to the Offsec Team straight away.

Delete

Once reported, remove the message so you don't act on it later.

How to report: use the Report Phishing button in Gmail, or forward the message to the Offsec Team at [email protected] or Detecx Team [email protected]. Reporting is always welcome, even if you turn out to be wrong and if you've already clicked or entered credentials on a real one, tell Offsec at once. Speed limits the damage more than anything else, and nobody is penalised for reporting.