This short module covers the red flags used in real phishing attempts, what to do when you see one, and a walkthrough drawn from our own recent simulation. It ends with a short quiz.
Most phishing emails share the same three tells. Learn these and you'll catch the majority of attempts at a glance.
The name in your inbox looks right. The address behind it often isn't.
Pressure is the payload. It's designed to make you act before you think.
What you see and where it actually leads are often two different things.
Four steps, in order. The most common mistake isn't clicking — it's deleting the evidence before it's reported.
Any interaction can confirm to the sender that your address is active and being read.
Use your organization's official reporting process (report button or forwarding to your security team) so it can be traced and blocked for everyone.
Don't delete it — IT Security may need the original headers and content to investigate.
Change that password immediately and report it — speed matters far more than embarrassment here.
This is the real email sent in our Group‑wide simulation — a spoofed HR "compensation review" request sent from a lookalike Docusign domain. Tap each numbered marker to see why it's a red flag.
8 questions. Pick an answer for each — you'll see which ones were correct, with explanations, at the end. Once you move to the next question you can't go back.
Here's how you did.
Your result is being recorded to the training completion log for .