Simulated Phishing Email of August 2026 – Dormant Administrative Account Review

Published: Posted on

Can you trust this page?

Look at the address bar at the top of this page. This page is on blog.bham.ac.uk. This tells you that it is part of the official bham.ac.uk domain owned by the University of Birmingham.

If you came here to verify whether a suspicious email was part of a phishing simulation, then check that the image below matches the email you received.

What We Did

On 11 August 2026, IT Security sent a simulated phishing email to IT-related staff, it appeared to be:

  • From: Identity Governance Team <identity-review@bham-ac.org>
  • Subject: Action Required: Dormant Administrative Account Review
  • Included the recipient’s first name
  • Linked to a fake Microsoft login page requesting your University email and password

It pretended to be from someone working as a Consultant for the University and encouraged recipients to enter their University credentials on a fake sign‑in page. No passwords were collected during the exercise.

Anyone who entered details was redirected to a confirmation page explaining that: the exercise was safe ,that no password information had been stored, that line managers would not be told and that they were not in any trouble because of this.

What the Email Looked Like

(with the suspicious parts underlined in red and other manipulations underlined in orange)

Why the Email Was Suspicious

1. An external email, from someone outside the organization, telling you to verify a University account?

This should immediately arouse suspicion.
The Sender address identity-review@bham-ac.org does not belong to the University or Microsoft.

2. It requested your University password

Genuine University emails do not direct you unexpectedly to a login page requesting credentials.
The link pointed to e-service.biz, which is not a legitimate University or Microsoft domain.

3. Personalisation can be faked

Attackers often use names or personal details to make an email look more convincing. If another University account has been compromised it would have access to the GAL and full names.

4. The sign‑in page URL was suspicious

Although the fake login page looked genuine, the address bar showed e-service.biz.com. Attackers commonly copy logos and layouts from real sites, so always check the URL before entering passwords.

5. Other manipulations

The parts underlined in orange in the first image above are intended to create a sense of urgency to stop you thinking. Most fake emails try to manipulate your emotions to trigger you into an immediate response without giving yourself time to think.

About URLDefense

External links in most University emails are now automatically prefixed with urldefense.com/v3/ (shown underlined in green in the first image above. This is part of our security system which checks each external email link for threats. Even so, always check the final destination of any link before entering information.

How to Protect Yourself

Nothing is so urgent that you can’t Pause and Think before you click

  • Was I expecting this message?
  • Do I recognise the sender?
  • Does the message look appropriate?
  • Is the URL genuine?
  • Be cautious if an email asks for your username and password.
  • Avoid using a direct email link to reset your password, go the webpage using a browser and login that way.
  • Always check the URL of sign-in pages.
  • Hover over links (or long-press on mobile) to reveal the full destination address.

Report all suspicious messages

Use the Report Email button in Outlook to report all suspicious emails. This helps to protect others by training our security system to automatically detect and quarantine similar threats. This works 24/7/366 and can remove all copies of a phishing email from users’ inboxes while it is being reviewed.

If the email is a training exercise then you will be told immediately. Even if you are confident that an email is a training exercise, please still use the Report Email button. Your report helps us measure the effectiveness of our last line of defence – YOU.

If a link seems suspicious then don’t click on it! – resist the temptation to “carefully” enter dummy details, out of curiosity or “just to be sure”. In a real attack, there is a risk of a “zero-day” “drive by download” which your browser and security software might not protect you against. You are playing with fire.

Why We Run These Exercises – awareness not blame

This simulation is part of the University’s ongoing security awareness work. No individuals are blamed or identified, and managers are not given any results which could identify any individual.

Phishing remains one of the most common methods of credential theft. Simulations help staff recognise real threats, much like fire drills prepare people for emergencies.

Learn More (further quick training 5-10 mins)

Fraudsters are very devious in using addresses which look similar to genuine ones. This page, from CalTech, shows you how to read URLs (web addresses) correctly, to help you to avoid some of the dirty tricks used https://www.imss.caltech.edu/services/security/recommendations/how-to-read-urls

You can test your knowledge in this quiz by identifying which of 10 emails are legitimate or phishing https://www.phishingbox.com/phishing-iq-test/quiz.php

Questions or Comments?

If you work or study at the University of Birmingham and have questions about this simulation, please contact:

itsecurity @ contacts.bham.ac.uk

Leave a Reply

Your email address will not be published. Required fields are marked *