GOTCHA

you clicked a phishing link. good news: it was us.

Keep this to yourself. Your teammates are taking the same test. We want to understand where additional awareness and reinforcement may be needed, so it’s important that everyone gets a genuine test, no spoilers!

Relax, you are not in trouble

Real phishing fools smart, busy people every single day. That is the design.

We run these to find gaps in our training, not to name and shame. Read this, get a little sharper, carry on.

That "New Documents shared in Teams" email? Fake. Sent by the EnterpriseAlumni Security & Compliance team as a training exercise. No real attack, and your password was not captured.

What happens next

Once this exercise is complete, the Security & Compliance team will reach out with a short follow-up and some quick training, so we can reinforce anything worth a second look. Nothing to prepare, and nothing to worry about.

$ how to spot a phishing attack

The email you just clicked showed the classic signs. Here is what to watch for next time:

What gives a phish away

  • Urgency: "do this now", "today only", "your account will close".
  • Sender mismatch: the display name says one thing, the address another.
  • A request for secrets or access: passwords, codes, payment details.
  • Secrecy: "don't mention this", "handle it discreetly".
  • A login you did not expect: real services don't email you a sign-in page.

Where it shows up

  • Fake Microsoft or Okta sign-in pages
  • File-share invites (SharePoint, OneDrive, Dropbox)
  • Teams or Slack messages from a spoofed colleague
  • Exec impersonation asking for gift cards or payments
  • Invoice or bank-detail change requests
  • IT support asking you to install or approve something
  • MFA prompts you did not trigger
  • QR codes in emails, PDFs or posters