IT / Helpdesk

The fake IT password reset email

An urgent notice claiming your password or account access is about to expire, designed to make you click without checking.

The scenario

This is an illustrative training example, not a real message from Claro or any organization. In this scenario the email is styled to look like a routine internal notice from 'IT Helpdesk' or 'IT Support'. The subject line typically reads something like 'Your password expires in 24 hours', and the body carries a company logo, a polite paragraph about a security policy update, and a single prominent 'Reset Password Now' button.

The pretext is built entirely around a small, believable inconvenience. Losing access to your email and work systems is a real fear, so the message frames itself as helping you avoid that disruption. It borrows the tone real IT teams use, references a policy you cannot easily disprove, and offers a one-click fix that feels faster than logging in the normal way.

The message reaches you the same way genuine IT notices do: straight to your work inbox, often early in the morning or just before a weekend when you are moving quickly through email. Some versions also arrive as a chat message or a calendar reminder to reinforce the sense that this is an official, coordinated rollout.

It is convincing because almost every part of it is copied from something real. The 'Reset Password Now' button leads to a lookalike login page that can be nearly identical to your actual portal, down to the fonts and colours. Because the request feels ordinary and the page looks familiar, most people focus on completing the task rather than questioning whether the email should exist at all.

Red flags to spot

Urgent deadline language such as 'expires in 24 hours'

Real IT policies rarely enforce password changes with a hard countdown designed to pressure immediate action.

Generic greeting like 'Dear User' instead of your name

Legitimate internal IT systems usually address you by name because they already hold your account details.

A login link that does not match your company's actual domain

Hovering over the button reveals a lookalike domain, a common sign the page is built to harvest credentials.

A request to enter your current password to 'verify' before resetting

No legitimate password reset flow needs your old password typed into a page reached from an email link.

The sender address is external or slightly misspelled

Genuine helpdesk mail comes from your own verified domain, not a public webmail address or a near-copy of it.

The email discourages you from contacting IT another way

Attackers want you to stay inside their flow, so they present the button as the only option and skip normal support contacts.

The lesson

Never reset a password through a link in an email, even if the message looks internal and urgent. Instead, open your company's known IT portal directly in your browser or contact the helpdesk through a verified channel you already trust. If anything feels off, use your email client's report button so your security team can investigate and warn colleagues.

These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.

Frequently asked questions

  • Change your password immediately from a device you trust, using your official IT portal rather than any link from the email. Then contact your IT or security team so they can secure your account, enable extra checks, and watch for misuse. Acting quickly limits what an attacker can do.

Run these patterns as real simulations

Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.

Request a demo