You're safe. No password was captured and nothing was harmed. Simulated test by Mullins IT · for H2O Professional Services

Security awareness · specimen review

You clicked a phishing email. Let's take it apart.

This one was a drill. A real attacker who sent it would now have your Microsoft 365 password. Below is the exact message you clicked, laid out on the table. The marked spots are the tells that gave it away, hover or tap any one to see what a real inbox would never do.

The message you received5 tells marked

[Action Required] Your password expires today3

Microsoft 365 Security Team
<account-security@microsoftonline-secure.com1>
to staff@h2oprofessionalservices.com

Dear User,2

Our records show the password for your account will expire within the next 3 hours. To keep your email and files active, you must re-verify your account now. Failure to act will result in permanent loss of access.

Thank you,
The Microsoft Account Team

© 2026 Microsoft Corperation. All rights reserved. This is a mandatory security notification, you cannot unsubscribe.5

What to do when a message pushes you to log in

Five habits that stop a real one cold.

RULE 01Reach the site yourselfType the address or use a bookmark. Never log in from a link an email handed you.
RULE 02Read the domain, not the nameThe friendly name is free to fake. The part after the @ is the truth.
RULE 03Hover before you clickYour browser shows the real destination in the corner. On mobile, press and hold.
RULE 04Turn on multi-factorWith MFA, a stolen password alone can't get anyone in.
RULE 05When unsure, just askA ten-second message to IT beats a compromised account every time.
Think a real one slipped through?

Don't click anything. Forward it to IT at it@h2oprofessionalservices.com and delete it. Reporting one email can protect everyone.