Skip to main content

This Was a Phish

Ohio State regularly runs phishing training exercises to the university community. By clicking the link that brought you to this page, you succumbed to a university phishing simulation. Read on to learn how to spot phishing messages and protect yourself and the university from malicious attacks.

Spotting the Phish

You received this email:

This is an internal HR-themed lure impersonating Ohio State University, asking the recipient to complete an annual Code of Conduct and Conflict of Interest disclosure. It uses a numbered three-step list and a blue "Complete the form" button to drive the click, with soft urgency ("by the end of the week") and an offer to reply with questions. The design mimics a legitimate internal HR notice — clean letterhead bar, muted OSU-style palette, and a plain footer reading "Internal HR communication."

 

Sender Addresses: The sender address, hr.representative@hr-dept.info, is not a legitimate domain for the Ohio State's human resources department and should raise red flags. The domain (everything after the @ symbol) is the first indication that this might be a phishing attack. 

Suspicious Language: The email is encouraging the recipient to "Complete the form" by the end of the week, suggesting some urgency.

Branding: The email does not follow Ohio State branding standards and should be seen as suspicious. At the bottom of the email, 'ohio state university' is not capitalized. 

Review the URL of web page before engaging with it: When you clicked from the email, a website was loaded with a URL of https://order-history.paypol-login.com, which is not a legitimate site. Attempt to confirm the legitimacy of a site before you enter login credentials or personal information like name, email address or phone number.

 

Report Phishing Attempts

Image of the 'report suspicious' banner displayed at the top of every external email you receive. Click this banner to report suspected phish.

If you ever suspect an email to be a phishing attempt, please report it immediately by clicking the "Report Suspicious" button in the warning banner which appears at the top of that external email.