Security Awareness Program
Phishing Simulation

This was a Security Awareness Test

You clicked a link in an email and opened this page. This page exists to teach you how to spot real attacks before it is too late.

Don't worry — nothing was captured. Your real account is 100% safe.
What happened

You clicked. In a real attack, that would have been enough.

The email you opened impersonated a trusted company and pushed you to act quickly. Phishing attacks rely on urgency and trust — and they only need one click.

  • You entered your details on a look-alike page. No legitimate service asks for your password via an emailed link.
  • In this simulation no data was saved. In a real attack, your password would be in the attacker's hands.
  • The lesson: slow down. One extra second of verification can stop an entire breach.
Example of what the fake email looked like
From: "Security Team" <admin@demotch.com> — Subject: Your account requires immediate action

Compare the sender with the address it claims to be:

Looks like the real company Actually demotch.com Not the real company!

Always check the domain after the @ symbol and before the first / in any link.

Learn to spot it

5 signs of a phishing email

Check these before you ever click a link or type a password.

Verify the sender

Open the real address (not just the display name). Confirm it is the official company domain and not a look-alike.

Sense the urgency

Act within 24 hours or your account is locked! — attackers manufacture panic to skip your thinking.

Hover before you click

Hover over the button to reveal the true destination. If it is not the official domain, close it.

Never enter passwords

Legitimate services never ask for your password via an emailed link. Always go to the site directly.

Check the greeting

Real organizations use your name. Generic greetings like "Dear User" are a warning sign.

Attachments and links

Unexpected attachments and shortened URLs are how malware and credential theft get delivered.

Red flags

Warning signs in this email

A third-party sending domainA legitimate company never sends account warnings from a third-party domain.
A time limit to force action"Within 24 hours" is pressure, not policy.
Requests for your passwordNo legitimate company ever asks for your password in an email.
A look-alike login pageSmall differences in the URL give it away. Compare, don't assume.
What to do now

If you ever click a real phish

Act fast — these three steps contain most of the damage.

1

Change your password

Update the compromised account and any account that uses the same password.

2

Enable two-factor

2FA stops attackers even if they already have your password.

3

Report the email

Mark it as phishing and tell your security team immediately.

Ready to be more careful?

Confirm you understand this training. Your response is recorded for your organization's awareness program.

No personal data was collected during this simulation.