No data collected
You have been "phished" - this was a simulation
You followed a link from a simulated phishing email and landed on a page built to resemble our sign-in portal. This is an authorized, self-targeted security-awareness exercise. Nothing you entered was stored, logged, or transmitted - this site is static and has no data-capturing forms.
What the simulated email did
The message used a plausible, time-pressured work pretext. Attackers frequently impersonate IT, HR, or compliance to get you to "re-authenticate" through a link.
Red flags in the message you received
1
Urgency and a deadline. A short countdown is designed to make you act before you think.
2
Unexpected request. You did not initiate a password or access reset.
3
Link goes elsewhere. The link text and the real destination differ - always hover and inspect the domain first.
4
Credential request. Real IT never asks you to confirm a password through an emailed link.
Personalization used in this exercise (public sources only)
This exercise shows how little public information is needed to make a lure convincing. The following was gathered from publicly available sources only.
| Detail | Value used | Source type |
|---|---|---|
| Name | Chad Allen | Provided seed |
| Employer | Fisher Investments | Public professional profile |
| Role | GVP, Consulting Services | Public business directory |
| Location | San Francisco Bay Area / San Mateo, CA | Public professional profile |
| Tenure | Joined Nov 2018 | Business profile site |
| Education | UC Davis | Public professional directory |
How to protect yourself
- Reach portals from a bookmark or by typing the address - never from an emailed link.
- Verify unexpected requests out-of-band, using a phone number you already trust.
- Hover over links and read the destination domain before clicking.
- Report suspicious messages instead of acting on them.