What is Phishing?
Spot the Red Flag
Think Before You Click
Real or Fake?
Cybersecurity Habits
100

A cyberattack where criminals pretend to be a trusted source to steal information.

What is phishing?

100

An email asks you to act immediately or your account will be locked.

What is urgent language?

100

The first thing you should do before clicking a suspicious link.

What is check the sender’s email domain?

100

An email from IT.Security@synchrony.com asking employees to confirm MFA settings.

What is a legitimate email?

100

Security practice requiring two forms of verification when logging in.

What is multi-factor authentication a.k.a MFA?

200

Phishing emails often try to steal this type of information used to access accounts.

What is login credentials or passwords?

200

The email address says: IT-Support@synchr0ny-secure.com.

What is a misspelled or altered domain?

200

A safe way to check a link without clicking it.

What is hovering over the link?

200

An email from a CEO asking you to urgently buy gift cards.

What is a phishing scam?

200

The best practice for protecting your passwords.

What is never sharing your password?

300

This type of phishing targets a specific person or employee using personal information.

What is spear phishing?

300

An email begins with “Dear User” instead of your name.

What is a generic greeting?

300

The department you should contact if you receive a suspicious email.

What is IT or the security team?

300

An unexpected invoice email from a vendor you don’t recognize.

What is a phishing attempt?

300

The action employees should take if something in an email feels suspicious.

What is verify before clicking?

400

Phishing attacks sent through text messages are called this.

What is smishing?

400

An email asks you to download an unexpected file or invoice.

What is a suspicious attachment?

400

The action employees should take after identifying a phishing email.

What is report the email?

400

A password reset email that you requested from the official company site.

What is legitimate communication?

400

Why phishing attacks are dangerous to organizations.

What is they can cause data breaches or financial loss?

500

Phishing attacks conducted through phone calls pretending to be IT or a bank.

What is vishing?

500

A link looks like a company site but directs to another website.

What is a fake or malicious link?

500

If you accidentally click a phishing link, you should do this immediately.

What is report it to IT/security immediately?

500

An email threatening immediate account suspension if you don’t click a link.

What is a phishing tactic?

500

Who is responsible for cybersecurity in an organization.

Who is everyone/all employees?