You reached the training debrief
No credentials were collected in this exercise, nothing was stored, and any text you typed stayed in your own browser. You can safely close this tab.
What the lure was built from
This simulation used only real, public facts about the target to make the message feel credible:
- Current employer and role: Group Product Manager at Google (since 2019), San Francisco Bay Area.
- Named product: health and fitness features on Wear OS.
- Named project: Real-World Evidence / Project Baseline at Verily (Alphabet).
- Prior employers: Roche (Lead Product Manager), Aetna (Senior Product Manager), plus Savored, Inc. and Ladders.
- Institution: MBA, Columbia University - Columbia Business School; MA/BA Philosophy, Western Michigan University.
How to spot it next time
- Spearphishing borrows true details (employer, projects, schools) to look legitimate.
- Urgency plus a sign-in link is the classic credential-harvest pattern.
- Check the domain in the address bar before typing a password; a real partner portal lives on the vendor's own domain.
- Report unexpected sign-in requests to your security team instead of following the link.
Authorized security-awareness training. Facts shown above were gathered from public profile pages (RocketReach, Crunchbase, LinkedIn directory, Verily / Duke CTSI).