Skip to content

Exercise

A phishing attack, annotated.

Seventeen messages in an inbox that looks like any other. Each one is marked up with the signals that give it away — plus one exercise in sending personal data without leaking it.

How this works

You're an employee at Vantor. The mailbox is invented; the messages are modeled on what actually lands in corporate inboxes.

  1. 01

    Sign in with anything

    The sign-in screen accepts any address and any password. Nothing is sent or stored — it is part of the set dressing.

  2. 02

    Read with the guide open

    Every message has its signals marked in the text and explained alongside. Three messages are perfectly fine, and those are marked too.

  3. 03

    Send a file containing personal data

    The last message is an ordinary request from HR. You will download a file, protect it with a password, and send it back — and we check whether you did it safely.

  • Runs in your browser
  • Nothing is collected
  • About 10 minutes

This is what our scenarios look like

In PhishSpot the same tactics reach your team as a controlled campaign, with a short lesson at the moment of the click and a report that shows how the team improves.