You clicked a link in an email and opened this page. This page exists to teach you how to spot real attacks before it is too late.
The email you opened impersonated a trusted company and pushed you to act quickly. Phishing attacks rely on urgency and trust — and they only need one click.
Compare the sender with the address it claims to be:
Always check the domain after the @ symbol and before the first / in any link.
Check these before you ever click a link or type a password.
Open the real address (not just the display name). Confirm it is the official company domain and not a look-alike.
Act within 24 hours or your account is locked! — attackers manufacture panic to skip your thinking.
Hover over the button to reveal the true destination. If it is not the official domain, close it.
Legitimate services never ask for your password via an emailed link. Always go to the site directly.
Real organizations use your name. Generic greetings like "Dear User" are a warning sign.
Unexpected attachments and shortened URLs are how malware and credential theft get delivered.
Act fast — these three steps contain most of the damage.
Update the compromised account and any account that uses the same password.
2FA stops attackers even if they already have your password.
Mark it as phishing and tell your security team immediately.
Confirm you understand this training. Your response is recorded for your organization's awareness program.
No personal data was collected during this simulation.