Security Awareness Team

Phishing simulation result

You were caught by a simulated phishing email.

This was an authorized security-awareness exercise designed to help participants recognize and report suspicious messages safely.

Dear User. Your interaction with the transportation registration message demonstrated how a convincing email can create urgency and encourage quick action. This is a learning opportunity—not a punishment.

The simulation has now ended

Do not enter or submit any additional information on this page. Your interaction may be recorded only for the authorized awareness exercise and its reporting process.

Red flags in the simulated message

Several clues could have helped identify the email before clicking its registration link.

01

Unexpected request

The message introduced a new employee service without prior confirmation through an established internal channel.

02

Artificial urgency

A prominent registration deadline encouraged immediate action instead of giving you time to verify the request.

03

Link verification

Hovering over the button or checking the destination carefully may have revealed that it did not lead to the expected official portal.

04

Request for personal details

The landing page requested employee and travel information. Sensitive or identifying details should be entered only after independently verifying the service.

05

Trust through branding

Logos, polished formatting and familiar terminology can be copied. Professional appearance alone does not prove authenticity.

06

Independent verification

The safest response was to confirm the announcement using a known HR, transport, help-desk or security contact rather than replying to the email.

What to do next time

1

Pause

Be cautious when a message creates urgency, fear, curiosity or an unexpected benefit.

2

Verify

Check the sender, inspect the link destination and confirm the request through a trusted channel.

3

Report

Use your organization’s approved phishing-reporting method so the security team can investigate quickly.

Remember: stopping for a few seconds to verify an unexpected request can prevent account compromise, data loss and wider organizational impact.