The email you received
It looked official - it even included a security reminder. Six things in it should still have made you stop.
Hi All,
As part of our ongoing Information Security activities, and in support of the requirements of ISO/IEC 27001:2022, 3all staff are required to change their Google account password.
Please change your password using Google's official account page by 9 September 2026:
- Go to myaccount.google.com/security → How you sign in to Google → Password
- Alternatively, open Manage your Google Account from your profile picture.
Your new password must:
- be at least 12 characters long;
- not reuse any previous password; and
- not contain your name, username, or the company name.
Once you have changed your password, complete the acknowledgement form below to confirm completion:
4Password Change Acknowledgement Form: https://forms.clickup.com/1851634/f/1rg7j-57156/…
5All staff are required to complete this by the stated deadline. Staff who have not completed the password change and acknowledgement by the deadline will be identified and mentioned in the designated channel for follow-up.
6Reminder: IT will never ask you for your password by email, chat, or phone. Never enter your password on any page other than Google's own sign-in screen.
Thank you for your cooperation and continued commitment to information security.
Regards,
Administrator
What should have made you pause
None of these are typos. Good lures rarely have any.
-
1
A lookalike sender that isn't really us
The email came from "Administrator" at
[email protected]- read it carefully. Our real domain isnetbytesecurity.com; this one quietly drops a letter from "byte". A domain a single character off is one of the oldest impersonation tricks there is, and an impersonal "Administrator" sending from it is a red flag on its own. Genuine notices come from a named colleague (e.g. Naimah) on our own domain - always read the address behind the display name. -
2
Addressed to you alone, not the whole team
The message opens with "Hi All" and claims to be for "all staff", yet it arrived addressed to
[email protected]on its own. Genuine all-staff notices are sent to a group or distribution address (for example[email protected]), not to you as a single named recipient. When the audience an email claims and the way it's actually addressed don't line up, treat it as suspect. -
3
This is not how NBS asks you to change a password
NBS does not send emails telling staff to go and change their password. When a reset is genuinely required, it's enforced at sign-in through our identity provider - you're prompted the next time you log in. An unsolicited email demanding a password change is one of the most common phishing pretexts there is, and here it doesn't match any process we actually run. Citing ISO 27001 doesn't make it real.
-
4
A link to an outside site asking you to act
The real Google links were a decoy of legitimacy which the action that actually mattered was the external form you were told to "confirm" on. That's the exact move a real attacker uses: swap that form for a page that captures your Google login, and a credential is stolen. Hover any link (long-press on mobile) and read the true destination before you click. A security email that sends you off-domain to confirm or sign in deserves a second look every time.
-
5
A deadline backed by a social threat
"Identified and mentioned in the designated channel for follow-up" is pressure - fear of being named makes people act before they think. Urgency and consequence are persuasion tools, not proof the message is real.
-
6
A security reminder doesn't make an email safe
This message even warned you never to hand over your password and that reassurance is precisely what made it more convincing. Attackers copy the trust signals of real IT notices, including anti-phishing reminders, to lower your guard. Judge an email by its sender and what it asks you to do, never by how security-aware it sounds.
Key takeaways
When a message feels off, work through these four steps.
Stop
Don't click, reply, or download. Pause before you act on it.
Check
Verify the sender's real address and hover any links before trusting them.
Report
Report suspicious messages to the Offsec Team straight away.
Delete
Once reported, remove the message so you don't act on it later.
How to report: use the Report Phishing button in Gmail, or forward the message to the Offsec Team at [email protected] or Detecx Team [email protected]. Reporting is always welcome, even if you turn out to be wrong and if you've already clicked or entered credentials on a real one, tell Offsec at once. Speed limits the damage more than anything else, and nobody is penalised for reporting.