Analyse a phishing incident, practise security vocabulary, conditionals and modal verbs.
Last Tuesday, several employees received an email that appeared to come from our IT department. The message claimed that their mailboxes were full and asked them to 'verify' their accounts through a link. The link led to a fake login page that copied our company design.
Three colleagues entered their credentials before the security team was alerted. Their passwords were reset immediately, and two-factor authentication stopped the attackers from accessing the accounts β the criminals had the passwords, but not the codes from the employees' phones.
This incident shows why you must never click links in unexpected emails. If a message asks for your password, it is almost certainly phishing: our IT department never asks for credentials by email. Check the sender's address carefully, and if you are unsure, forward the message to the security team before you do anything else. Remember: one careless click can lead to a serious data breach.
Review your answers below, then send them to your teacher.
Leave this empty if you don't want feedback. If you enter your email, your teacher will reply with feedback on your answers.
Click the button below to send your answers directly to your teacher.