677
Have I Been Pwned owner, pwned.
(htxt.co.za)
This is a most excellent place for technology news and articles.
I've clicked an obvious phishing link once in an isolated environment with a hardened browser on purpose. It had a tracking link and all and the URL was just ever so slightly off. Nothing happened on the target page though. No attempted script execution, no iframes, no cross site shenanigans, no weird popups or a fake login UI urging me to enter my credentials asap.
Someone from my company's security department called me shortly, telling me how I've failed the obvious phishing exercise and I had to undergo a half hour long mandatory awareness training. Wasn't getting out of that one.
If you look at the headers, you can tell which ones are fake phishing and real phishing.
Please explain
Most companies add an email header like "X-PHISHTEST" to the phishing tests (and a corresponding spam filter rule) to ensure they don't get caught by spam filters. If you look at the headers of a spam email, the company test emails will have that header.
Any company that does that needs to be sent on a mandatory awareness training for failing an obvious fake phishing exercise. It's far too easy to whitelist that and send it to an "ignore" folder.