This was a simulated phishing attempt provided by the ICT Team at Leicester Partnership School.
On this occasion, your data is completely safe and no further action is required. However, this test is representative of a real phishing attempt that can, and will happen at any time.
What is Phishing?
“Phishing” refers to an attempt to steal sensitive information, typically in the form of usernames, passwords, credit card numbers, bank account information, or other important data in order to utilize or sell the stolen information. By masquerading as a reputable source with an enticing request, an attacker lures in the victim in order to trick them, similar to how a fisherman uses bait to catch a fish.
(Definition provided by Cloudflare - https://www.cloudflare.com)
Phishing can take many forms, including but not limited to; email, social media, generative AI, SMS and phone calls, all with a single goal; to trick you into providing sensitive information by means of deceit.
Things to look out for
In this particular exercise, an email phishing attempt was made. Let's look at some of the key giveaways.

- First of all, just ask yourself 'am i expecting this email, and does the subject seem reasonable?'. In this example, the email appears to be from a well known member of our team, and having a referral document shared via Google (our main file hosting platform) seems believable, but this may be something unexpected or the subject and its contents may not be relevant. If you are unsure, report it to the ICT team or check with the 'sender' first before opening any links and/or downloading attachments.
- Always check the sender name and email address. More recently, spoofing; the faking of sender names and email address has gotten harder to detect. However, its important to check for any errors, including spelling mistakes. In this example, the sender email address reads noreeplygoogle which is a clear misspelling. The email address also ends in @gmail.com. Companies such as Google and Microsoft will not use email domains like @gmail.com, @hotmail.co.uk, @yahoo.com and should appear as @xxx.google.com or @xxx.microsoft.com. Some email clients may also show a verified symbol next to email addresses to confirm they are legitimate.
- When receiving an email containing links, you should also check that these are genuine. Links can be disguised to say anything, in this case 'Open', 'Learn more' and also the name of the document 'Referals2026.docx'. Hovering over the link will display its true origin, and as we can see from this example, it does not show a link to Google Drive and/or a document.
.png)
