⚠  Security Alert — System Compromised
Your Files Have Been Encrypted
All documents, photos, and data on this device
are now locked and inaccessible to you.
⏱ Time before permanent deletion
47:59:47
Ransom Amount 0.25 BTC
≈ SGD 24,500 at current rate
Send to Bitcoin Address
1A1zP1eP5QGefi2DMPTfTL5SLmv7Divf  [Bitcoin Address]
After payment, email: decrypt@crypto.com with your payment ID
Affected files
C:\Users\...\Documents\*.docx  ........... ENCRYPTED
C:\Users\...\Desktop\*.xlsx    ........... ENCRYPTED
C:\Users\...\Pictures\*.jpg    ........... ENCRYPTED
\\SERVER01\Shared\Finance\*.xlsx ........ ENCRYPTED
[ 4,847 files affected ]
🛡 IT Security Team — Re Sustainability Singapore
You clicked a phishing simulation.
This was an authorized security awareness exercise. Your files are safe — nothing was encrypted or stolen.
You are not in trouble. This exercise helps everyone recognize real threats before they happen. What you just saw is exactly what a real ransomware attack looks like. Take a moment to understand why it worked.
What happened

You clicked a link or opened an attachment in a simulated phishing email. In a real attack, that single action installs malware, encrypts your files, or steals credentials — with no further interaction needed from you.

Red flags in that email
  • Sender address didn't match. Attackers use domains like resustainability-it.com or company-support.net — one character off from the real thing.
  • Unexpected attachment or link. If you weren't expecting a file from that sender, that's your first signal to stop and verify before clicking.
  • Urgency and pressure. "Your account will be suspended," "Action required now" — attackers manufacture panic so you act without thinking.
  • Hover before you click. On a PC, hover over any link to preview the real URL in the status bar. On mobile, long-press to see the destination.
  • Bitcoin ransom demands are always a scam. No legitimate organization will ever ask you to pay in cryptocurrency.
What to do when you spot a suspicious email
  • 1
    Do not click any links, open attachments, reply, or forward the email.
  • 2
    Report it to IT Security — forward as an attachment or use the Report Phishing button in Outlook.
  • 3
    If you already clicked something: disconnect from the network immediately and call IT. Time matters.
  • 4
    Don't be embarrassed — reporting fast stops a real breach. We'd rather get 100 false alarms than miss one real attack.