🤫 Please keep this exercise confidential
To allow your teammates to experience the simulation naturally, do not share or discuss this activity with colleagues over Slack/Teams during the test window.
What just happened?
You received a simulated internal request and, if you continued, reached a look-alike sign-in page. This campaign is an authorized cybersecurity awareness activity run by 57 Blocks. It measures whether people click unexpected links and attempt to enter credentials. It is not a punitive test.
Key indicators of phishing
- Urgency and consequences. Messages that demand action before payroll, access, or HR deadlines are designed to skip verification.
- Unexpected sender or look-alike domain. Hover over links and inspect the actual hostname before clicking. Internal processes rarely arrive from a newly registered domain.
- Credential prompts from email. Legitimate directory or SSO updates start from known portals (Okta, Google Workspace, Microsoft 365), not from a link in an unsolicited message.
- Generic greetings plus specific threats. A mix of personalization and fear (payroll hold, account lock) is a common pretext.
- Requests to “verify” data you already provided. Attackers reuse HR and IT language because people are trained to comply with those teams.
What you should do next
- Do not reuse the password you typed, even though this simulation discarded it in the browser.
- If you use Google / SSO day to day: changing a local password is not enough. In a real incident, revoke active Google sessions, review third-party app access (OAuth), and confirm MFA is on your account.
- Report suspicious messages with the phishing-report button in your mail client, or contact Juan Quintero (juan@57blocks.com).
- When in doubt, open a separate browser tab and navigate to the official 57 Blocks portal yourself. Do not use the email link.