Spot the Phish
Which message should make you stop?
Cybersecurity without complicated terminology. Try a few everyday situations and see how easily a normal decision can become a security problem.
Choose the answer you would genuinely pick. There is no login and these exercises do not ask for or store real passwords.
Never give a real password to an unexpected page. Check the exact domain and why the password is being requested.
Urgency is a classic social-engineering technique. OTP and MFA codes are credentials too.
Attackers often use look-alike names. Read the real domain from right to left before the first slash.
A backup attackers can encrypt with the computer is not enough. Keep independent copies and test restoration.
HTTPS encrypts the connection. A fraudulent site can also have a valid HTTPS certificate.
Payment-detail fraud often begins with a compromised mailbox. Verify through a trusted channel, not the contact details inside the suspicious message.
Unexpected MFA prompts can mean someone already knows the password. Deny the request, secure the account and report it.
A successful job log is encouraging, but only a tested restore confirms that the data is usable.
Unknown removable media can contain malicious files or emulate a keyboard. Do not connect it to a business device.
Training rule #1: never type a genuine password, OTP, bank detail or confidential information into a demonstration.
Each lesson runs entirely in your browser and uses fictional information.
Which message should make you stop?
Which domain actually belongs to Microsoft?
Ransomware encrypts the laptop and its connected USB disk. What survives?