This was an authorized security awareness exercise. Your files are safe — nothing was encrypted or stolen.
You are not in trouble. This exercise helps everyone recognize real threats before they happen. What you just saw is exactly what a real ransomware attack looks like. Take a moment to understand why it worked.
What happened
You clicked a link or opened an attachment in a simulated phishing email. In a real attack, that single action installs malware, encrypts your files, or steals credentials — with no further interaction needed from you.
Red flags in that email
Sender address didn't match. Attackers use domains like resustainability-it.com or company-support.net — one character off from the real thing.
Unexpected attachment or link. If you weren't expecting a file from that sender, that's your first signal to stop and verify before clicking.
Urgency and pressure. "Your account will be suspended," "Action required now" — attackers manufacture panic so you act without thinking.
Hover before you click. On a PC, hover over any link to preview the real URL in the status bar. On mobile, long-press to see the destination.
Bitcoin ransom demands are always a scam. No legitimate organization will ever ask you to pay in cryptocurrency.
What to do when you spot a suspicious email
1
Do not click any links, open attachments, reply, or forward the email.
2
Report it to IT Security — forward as an attachment or use the Report Phishing button in Outlook.
3
If you already clicked something: disconnect from the network immediately and call IT. Time matters.
4
Don't be embarrassed — reporting fast stops a real breach. We'd rather get 100 false alarms than miss one real attack.