GO PHISH/ 50PUBP 6725 ASSIGNMENT 01 EDUCATIONAL SIMULATION

THE POST-CLICK DEBRIEF01 / RECOGNIZE

You’ve been
phished.

The invitation looked convincing.
That was the point.

You followed a link from a simulated conference invitation. This is where a real attacker might ask you to sign in. Here, the story stops—and the lesson starts.

See how it worked
THE IMPORTANT DISTINCTION

A click is not the same as a stolen password.
But it can be the start of the conversation.

02 / UNDERSTAND

A familiar name.
An unfamiliar destination.

The simulated invitation used conference branding and a professional tone to make a request feel routine. Here’s the sequence—and where this exercise ends.

ANATOMY OF THE ATTEMPTILLUSTRATED SEQUENCE · NOT ACTIVITY TRACKING

A convincing invitation → a call to action → this educational debrief. In a real attack, a fake sign-in page could follow.

  1. 01

    Borrow credibility

    Recognizable conference branding and a speaker invitation make an unexpected email appear relevant.

  2. 02

    Make the click feel routine

    “Respond to This Invitation” frames the link as an ordinary administrative step—not a security decision.

  3. 03

    Change the destination

    The link leads here. In a real attack, it could lead to a fake sign-in page that captures what you enter.

This exercise ends at the debrief. Credential theft and further account access are hypothetical—not actions performed by this page.

03 / TAKE IT WITH YOU

Trust the source.
Check the route.

A polished email is easy to imitate. A few independent checks are harder to fool.

01

Read the actual address.

Check the sender’s full email address, not just the display name. Look for unexpected domains or subtle misspellings.

02

Inspect before you follow.

Hover over a link—or long-press on mobile—to inspect the destination. A familiar logo, HTTPS, or a legitimate hosting domain does not prove who sent it.

03

Verify somewhere else.

Open the organization’s website independently or contact the organizer using a known address. Don’t rely on contact details in the suspicious message.

ONE LAST THING

What if this happens outside a simulation?

If you only clicked, close the suspicious page and report the message using your organization’s usual process. If you entered a password, change it through the real service and contact your security team promptly. If you downloaded or ran a file, ask your security team for help. A click alone does not establish that an account was compromised.

What does this page collect?

This website includes no forms, analytics, tracking pixels, cookies, or recipient-specific identifiers. The animation runs in your browser using locally served assets. Your hosting provider may still process standard request information, such as IP addresses; that is separate from this page’s code.