Email - Simulated Phishing Campaigns at UCO

Simulated Phishing Campaigns

The Office of Information Technology employs multiple layers of security and follows industry best practices to protect UCO email accounts from malware, phishing, and other email-based threats. While these safeguards significantly reduce risk, no security solution can prevent every malicious message from reaching users' inboxes. As cybercriminals increasingly leverage artificial intelligence (AI), phishing attacks have become more sophisticated, convincing, and difficult to detect. AI enables attackers to generate phishing campaigns at a much greater scale while tailoring messages to closely resemble legitimate communications, making phishing one of the most significant cybersecurity threats facing organizations today.

To help protect the university community against these evolving threats, the Office of Information Technology, in conjunction with the Information Security Department, conducts simulated phishing campaigns for all UCO faculty and staff throughout the year. These simulations provide a safe and effective way to evaluate security awareness, reinforce the importance of carefully evaluating email messages, identify opportunities for targeted security education, and strengthen UCO's overall cybersecurity posture.

These simulations helps faculty and staff recognize and respond appropriately to phishing attempts before they result in compromised accounts or unauthorized access to university systems. By continually improving phishing awareness across campus, UCO reduces the risk of successful cyberattacks and better protects its people, data, and technology resources.

What to expect during a Simulated Phishing Campaign

Simulated phishing emails are designed to reflect the types of phishing attacks that commonly target UCO faculty and staff. Throughout the year, you may receive simulations based on one or more of the following attack types:

Click Phishing

Click phishing attempts to trick users into selecting a malicious link. In a real attack, clicking the link could lead to the installation of malware, such as spyware, ransomware, or keyloggers, or direct the user to a fraudulent website designed to steal sensitive information.

Credential Phishing

Credential phishing attempts to convince users to disclose login credentials, such as usernames, passwords, or multi-factor authentication (MFA) verification codes. Attackers use this information to gain unauthorized access to email accounts and other university systems.

Vendor Email Compromise (VEC)

Vendor Email Compromise (VEC) occurs when attackers use a compromised account belonging to a trusted vendor or business partner to send phishing emails to customers, suppliers, or other contacts. Because these messages originate from legitimate external accounts, they often pass standard email authentication checks and may not contain obvious indicators of malicious activity, such as suspicious links or attachments.

Business Email Compromise (BEC)

Business Email Compromise (BEC) is one of the most sophisticated and financially damaging forms of phishing. In these attacks, cybercriminals impersonate trusted individuals within an organization—such as executives, supervisors, or coworkers—to persuade recipients to transfer funds, disclose sensitive information, or perform other unauthorized actions.

If you receive an unexpected or unusual request from a trusted sender, verify the request through a separate communication channel before taking action. For example, call the individual using a known phone number, contact them through Microsoft Teams, or speak with them in person. Never rely solely on the email to confirm its legitimacy.

How to report email (Outlook Client and Outlook Web)

When you receive an email that you believe may be a phishing message—whether it is a real phishing attempt or a simulated phishing email—report it using the Phish Report button in Outlook. To locate the Phish Report button in Outlook on iOS or Android, please refer to the short guide below.

To report the email:

  1. Open or preview the email in Outlook.
  2. Locate the Phish Report button:
    • In the upper-right corner of the email window, or
    • On the Outlook toolbar under Add-ins, depending on your version of Outlook.
  3. Select Phish Report (the green and black hook icon).
  4. Follow any prompts to submit the email for analysis.

A screenshot taken in Outlook, depicting a suspicious email with a red arrow in the top right-hand corner pointing to a green and black button.

A screenshot taken in Outlook depicting the toolbar, with a red arrow pointing to a black-and-green button labelled Phish Report in the add-ins section.

Selecting the Phish Report button opens the Apps: Phish Report sidebar, where you can review and confirm your report before it is submitted.

To report the email, select the red Report as Phishing button. Once submitted, the email will be reported to the Information Security Department for analysis and, if deemed to be unsafe, removed from your inbox.

.

A sidebar titled Apps: Phish Report with information about the email being reported and a large red button with the text, "Report as phishing."

 

Locating the Phish Report button in Outlook (Mobile)

For iOS

1. Open or preview the email.
2. Click the ellipses (...) at the upper-right corner of the email preview.

A screenshot taken in Outlook on iPhone depicting the header of a suspicious email with a right-facing red arrow pointing to an ellipses.

3. Select Phish Report (the green and black hook icon).

A cropped screenshot taken in Outlook on iPhone depicting an actions menu, with an upward-facing red arrow pointing to a green and black hook icon titled Phish Report.

 

For Android

1. Open or preview the email.
2. Select the three vertical dots in the upper-right corner of the email preview.

A cropped screenshot taken in Outlook on Android depicting the header of a suspicious email with a right-facing red arrow pointed to three vertical dots.

3. Select the Phish Report button.

A cropped screenshot taken in Outlook on Android depicting an actions menu with a diagonal red arrow pointing at a green-and-black hook icon titled Phish Report.

 

What to expect when reporting a Simulated Phishing Email?

When you use the Phish Report button to report a simulated phishing email, you will receive immediate feedback confirming that you correctly identified and reported the simulation.

A screenshot depicting a sidebar in Outlook titled "Apps: Phish Report" with a green checkmark icon adjacent to text congratulating the user for catching and reporting a phishing simulation.

After reporting a simulated phishing email, you will receive a follow-up email containing additional information about the simulation. This message explains why the simulation was selected, highlights the phishing tactics and indicators used, and provides guidance to help you recognize similar threats in the future.

A screenshot in Outlook showing an email with the subject line "Great Job! You Successfully Identified a Security Training Email," with more information about the simulation.

 

What is Just-in-time remedial training?

If you interact with or do not successfully identify a simulated phishing email, you will be assigned remedial security awareness training. The training can be completed immediately or at a later time within seven days.

The training provides additional information about the simulated phishing email, including why the simulation was selected, the warning signs and red flags that could help identify the threat, recommended actions for responding to similar emails, and a brief knowledge assessment to reinforce security awareness.

A page titled Security Awareness Training with University of Central Oklahoma branding, including information about the phishing simulation.

 

References


We strive to keep our articles relevant and informative. Please take a moment to leave feedback on the helpfulness of this article.