Start
— / 10
✉️ Your inbox · one message stands out

You’re about to read one phishing email the way it actually arrived — no warning label, no hints.

Not a list of tips — a short story that runs the way these attacks really do. First you read one email cold, with no warning label, exactly as it landed. Then you find out what it cost, and take it apart to see how it was built.

It’s built around your role, so pick who you are and the scenario fits. Three principles at the end hold for everyone.

Which best describes your role?
The scenario adapts to feel relevant to you. There's no wrong answer — pick whichever feels closest.
Any role works — the mechanisms behind these attacks are the same everywhere.
—An email arrives in your inbox.
Your call
—
What happened
👤
—
—
—
—
—
Looking at this now — do you think they made a mistake?
Inside the attackThe same email — annotated
Click the ! markers and highlighted text to see what the attacker was doing.
Click the markers to investigate
✓ You found everything. Now you can see the full picture.
Psychological triggers
Attacks like this use predictable psychological triggers. Click each card to see how it was used here.
The Helpful Colleague
🤝
Reciprocity & trust
A request framed as a normal favour between colleagues. Refusing feels like distrust.
↓ click to see if it was used here
🤝
Used in this attack
—
—
The Technical Ghost
⚡
Urgency & pressure
A manufactured deadline that kills the impulse to stop and check.
↓ click to see if it was used here
⚡
Used in this attack
—
—
The Gossip Mask
👀
Curiosity & lure
Something too personal, exclusive or intriguing not to open.
↓ click for examples
👀
Watch for
"Your salary review is ready." "Someone viewed your profile." Curiosity fires before judgment.
"You've been mentioned in a document. Click to view."
If an email makes you feel urgency, social pressure or curiosity — that feeling is the attack. Name the trigger. It creates distance.
Your turn
—
All four are genuinely dangerous. Which one concerns you most — and why does it matter?
What the outcome depended on
—
Here's why the timing mattered — and what a single verification step would have changed.
Three rules
The three rules. Same for every role, every situation.
01
Verify through a channel you already control
Any unusual request — financial, data, credentials, access — needs verification through something you already have: a phone number from your records, an internal directory, walking over to someone's desk. Not a number or link from the email itself.
Calling a supplier on their existing number
Messaging a colleague on your internal chat
Walking to the person's desk
02
Urgency is a reason to slow down, not speed up
Pressure and deadlines are the most reliable signal that something is wrong. Legitimate requests — from real colleagues, real suppliers, real IT teams — can wait ninety seconds for a confirmation. Fraudulent ones can't afford to.
"Before the banking cutoff at 4 PM"
"I'm in a meeting, need this now"
"Every minute of downtime costs us"
03
More than half-sure it's wrong? Report it.
You don't need certainty. If something feels off — the domain, the timing, the request itself — that's enough. Security teams would rather investigate a hundred false alarms than miss one real incident. Reporting after you've already acted still matters: it limits the damage.
Forward the email to your security team
Flag it even if you already clicked
Don't delete the email — it's evidence
✓
—
The attack worked because it looked completely legitimate. The defence isn't sharper instincts — it's a rule that fires automatically: verify through a channel you already control.