Skip to main content

Simulated phishing attack highlights cybersecurity threats

The Group Technology Solutions team recently conducted a simulated phishing attack as part of our ongoing cybersecurity education program. This helps us identify areas for improvement and ensure everyone is prepared for real-world threats.

Please find full details below of the training campaign and advise on how to protect yourself and Winslow from real threats in future.

You might recall receiving an email titled “Please review:leaked password” from Aura aura@password.land

The Results:

1005 staff members received the email.

  • Open Rate: 47.3% (opened the email)
  • Click Rate: 1% (clicked the link)
  • Phishing Report Rate: 17.8% (reported the email as suspicious by using the Phish Aert Button in Outlook or calling Service Desk)

Protecting Ourselves:

To keep everyone and our company safe, we encourage you to follow these steps when encountering suspicious emails:

Before you click on any links, run through the following questions:

  • Is the sender’s email address legitimate?
    No. From aura@password.land — an unusual, generic domain (not an official Aura domain). Treat as suspicious.
  • Do you know about this? No trusted relationship with password.land.
  • Is the company name or logo slightly altered?
    No obvious typo/alteration. “AURA” logo looks clean, but logos are easy to copy.
  • Does the logo/formatting look off? Not obviously, but that doesn’t prove legitimacy.
  • Does the email create urgency or fear?
    Yes. “Your password appeared in a data leak” + large Get Details button = pressure to act quickly.
  • Does the link look suspicious?
    Yes / treat as suspicious. Sender domain password.land is unusual, and the button hides the real URL (not visible in the screenshot) — another red flag.

    Is the domain unusual Yes (password.land).

  • Does the message ask for sensitive info / to “confirm my account”?

    Indirectly yes. “Visit your account / Get Details” likely pushes you to a login page — classic credential-harvesting flow.

    By staying vigilant, we can significantly reduce the risk of falling victim to real phishing attacks.

    We appreciate everyone’s participation in this simulation.

    As always, if you are not sure of the validity of an email, please contact the Service Desk: servicedesk@winslow.com.au Phone: 1300 308 079 

Safety