Wait, That Was a Test!
You clicked a simulated phishing link as part of our Security Awareness Program. Let us learn how to spot these in the future.
Do not worry! This was only a simulation. Nothing bad happened and you do not need to change your password. We are here to help you learn, not to punish.
Let Us Break Down This RRSP Statement Phishing Email
| |
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.
|
Red Flag #1: External Email Banner and Sender Address
The "External Email" banner is your first visual clue. While the sender display name showed "National Bank Direct Brokerage", the actual sending address was susan.norton[at]canwest[.]cc. VIU employee pensions are managed through the BC Pension Corporation (@pensionsbc.ca) and VIU Human Resources (benefits@viu.ca), never through an unrelated third-party domain.
🔒 Document Access Code
mULW9r8968H2
Red Flag #2: Fake Document Access Code
The email provided a "Document Access Code", yet the attachment opened immediately without asking for a password. Attackers often include fake access codes to create a false sense of security and make messages look like authentic encrypted business communications.
Sender: National Bank Direct Brokerage
Subject: [External] Vancouver island university RRSP Statement - Q3 October 2026
Footer: Vancouver Island University • BMO Pensions
Red Flag #3: Conflicting Institutional Branding
Notice how multiple financial institutions are mixed together. The header claimed "National Bank", the body mentioned "Vancouver Island University" and the footer cited "BMO Pensions". Scammers frequently copy fragments from different legitimate templates, resulting in contradictory branding.
VIEW RRSP SUMMARY
Destination: hXXps://www[.]financerts[.]org
Red Flag #4: Links Hidden Inside Attachments
Attackers frequently place links inside attachments to bypass basic email filtering systems. When you opened the attachment, the document contained little actual data and simply prompted you to click an external link to sign in. Always hover over buttons to check destination web addresses before clicking.
What Is the Number One Thing I Could Do
The number one thing you can do is treat your Inbox(es) like a school zone. Slow down when reading and acting on email.
We are all used to driving 10 km/hr over the speed limit on the highway. That behaviour can translate into our work. We are all super busy, and our attention is split. It is easy to be on autopilot without taking a moment to pause and think about what we are doing. However, I suspect none of us speed in a school zone. We slow down because of the heightened risk and greater impact of making a mistake on that stretch of road.
Email is the highest risk area of your job for being exploited and manipulating you into granting access to or sharing sensitive information.
What Should You Do Next Time?
Tips for identifying financial and pension scams:
- Check the sender address. Verify that the domain matches official university channels or your recognized pension provider.
- Beware of fake security codes. Treat unexpected attachments requesting you to log in with extra caution.
- Look for brand consistency. Watch out for emails that mix multiple bank or service names together.
- Hover over links. Always check where a button or link leads before clicking it.
- Verify through official channels. Contact VIU Human Resources or Payroll directly if you have questions about your benefits.
- Report it. Use the "Report" button in Outlook for suspicious emails.
- When in doubt, contact IT. We are here to help!