City employees click a fake timesheet-correction message that harvests Microsoft 365 passwords. What is the attack vector?
Select an answer to reveal the explanation.
Short Explanation
This one walked in through the inbox, not through a pump-house PLC. A fake timesheet note that steals Microsoft 365 passwords is classic email phishing. Do not drag OT gear into a mail lure just because the city also has a water plant.
Full Explanation
The observed delivery path is a deceptive municipal email that harvests cloud credentials, which is phishing over email. Water-plant PLC abuse, a parking-meter vendor compromise, and an exposed historian are different vectors that this evidence does not support. Defense analysts classify the vector from how the lure actually arrived, not from other civic systems that happen to exist.