This is a phishing simulation test for Alfalak employees

The goal of this simulation is to increase the security awareness of Alfalak employees to safeguard against future phishing attacks

Warn img

How To Identify Phishing Emails

What To Do If You Receive a Suspicious Email


1- Do not click anything or respond

2- Contact IT for support

IT img

Be Aware of Phishing Tactics

Attackers are constantly finding new ways to gain sensitive data to exploit users and organizations. It is important to always be alert and updated with attackers' new tactics to protect your data. The following are the most used phishing tactics:

■ False Urgency:


Attackers use an urgent tone to rush users into accidentally ignoring the obvious red flags.

■ Rush Hours:


Attackers send their harmful content during rush hours when users are most likely distracted.

phishing_img

■ Personalized Scams:


Attackers can retrieve user's information through social engineering and social media, etc; So, even if the email contained personal information that is not a sign that it is legitimate.

■ Verify the Sender:


Make sure to investigate the sender's address before trusting the email, some attackers might not use verified emails.

■ Slow Down:


We encourage you to always take your time when reading the email before taking any action.

■ Stay Vigilant:


We encourage you to always look for suspicious signs before trusting the email and to remain alert to any suspicious activity.

Be Aware of Hidden Threats

Make sure not to interact with emails from unknown senders; Attackers have various methods to hide malicious URLs and files.

Attackers can embed malicious URLs through buttons.
Before clicking on a button, make sure to check the hovered displayed URL.

excel_image
Confidential_File.xlsx 153 KB
download_image

Attackers can embed a malicious executable file through attachments.
Before clicking on download, make sure to verify the sender.

click_image

Attackers can embed malicious URLs through images.
Before clicking, make sure to check the hovered displayed URL.

Read more

Attackers can embed malicious URLs through text links.
Before clicking, make sure to check the hovered displayed URL.

Warn_image

Stay Alert at All times

Always take your time reading email content and investigating the sender

Attackers often create a deceptive button that looks like an attachment file to trick you into clicking on harmful content.

To help protect yourself, here are a few tips to distinguish between a genuine attachment and a deceptive button:

Attachment

Confidential_File.xlsx
excel_image
Confidential_File.xlsx 153 KB
download_image
  1. Hover over the content

    If the display text is the file name. Then this is an attachment

  2. Verify the display text

    Check if the displayed text is the same as the hovered filename

  3. Verify the Sender

    If you do not know the sender, do NOT click; attackers can embed malware with the attached file

  4. Contact the IT for support

Button

https://finance.al-falak.com/Q3Salary.php?efF56fdE4fvmf4Rfffkt5t5
excel_image
Confidential_File.xlsx 153 KB
download_image
  1. Hover over the content

    If the display text is link. Then this is a button

  2. Verify the display text

    Check on the displayed link, and do not click anything, this is suspicious content; official organizations do not embed links in attachment-like buttons

  3. Contact the IT for support

Be Aware of SMS Phishing

dont_respond_image

Do not respond to suspicious phone numbers

dont_click_image

Do not click links from unknown senders

dont_download_image

Do not download attachments from unknown senders

dont_share_image

Do not share personal or financial information

dont_share_otp_image

Do not share OTP codes with anyone

Cyber Security Video