This is a phishing simulation test for Alfalak employees
The goal of this simulation is to increase the security awareness of Alfalak employees to safeguard against future phishing attacks
How To Identify Phishing Emails
Subject: Confidential : Q3 Salaries Review
From: Falak Finance <finance@al-falak.com>
Date: Mon 6/30/2026 3:58 PM
Please find attached the salary changes of Q3, 2026 salaries.
Kindly review and approve.
Your approval is REQUIRED IMMEDIATELY.
Your coapration is appreciated.To proced on time for the upcoming payroll
Tell me if u have questions.
Thanx.
Kind Regards,
Head of Finance
Al-Falak Electronic Equipment & Supplies Co.
Attackers use fake sensitive phrases to deceive users into opening emails.
Make sure to validate the email sender, the domain, it should be official. Alfalak's official domain is @Alfalak.com not @Al-falak.com
Attackers often use unverified email addresses. Keep an eye out for warning flags or security banners displayed at the top of your emails.
Attackers use attachments to hide dangerous malware that harms the user. Be careful to verify the sender before you click.
Attackers use urgency to anxious users. Make sure to take your time in reading the email carefully without rushing.
Official companies proofread their email content.
Official companies uses their logos in a high quality. And it often blocks images from suspicious or external emails.
The email does not specify the user name, sender's name, and uses poor language. Official organizations use a formal tone.
What To Do If You Receive a Suspicious Email
1- Do not click anything or respond
2- Contact IT for support
Be Aware of Phishing Tactics
Attackers are constantly finding new ways to gain sensitive data to exploit users and organizations. It is important to always be alert and updated with attackers' new tactics to protect your data. The following are the most used phishing tactics:
■ False Urgency:
Attackers use an urgent tone to rush users into accidentally ignoring the obvious red flags.
■ Rush Hours:
Attackers send their harmful content during rush hours when users are most likely distracted.
■ Personalized Scams:
Attackers can retrieve user's information through social engineering and social media, etc; So, even if the email contained personal information that is not a sign that it is legitimate.
■ Verify the Sender:
Make sure to investigate the sender's address before trusting the email, some attackers might not use verified emails.
■ Slow Down:
We encourage you to always take your time when reading the email before taking any action.
■ Stay Vigilant:
We encourage you to always look for suspicious signs before trusting the email and to remain alert to any suspicious activity.
Be Aware of Hidden Threats
Make sure not to interact with emails from unknown senders; Attackers have various methods to hide malicious URLs and files.
Attackers can embed malicious URLs through buttons.
Before clicking on a button, make sure to check the hovered displayed URL.
Attackers can embed a malicious executable file through attachments.
Before clicking on download, make sure to verify the sender.
Attackers can embed malicious URLs through images.
Before clicking, make sure to check the hovered displayed URL.
Attackers can embed malicious URLs through text links.
Before clicking, make sure to check the hovered displayed URL.
Stay Alert at All times
Always take your time reading email content and investigating the senderAttackers often create a deceptive button that looks like an attachment file to trick you into clicking on harmful content.
To help protect yourself, here are a few tips to distinguish between a genuine attachment and a deceptive button:
Attachment
- Hover over the content
If the display text is the file name. Then this is an attachment - Verify the display text
Check if the displayed text is the same as the hovered filename - Verify the Sender
If you do not know the sender, do NOT click; attackers can embed malware with the attached file - Contact the IT for support
Button
- Hover over the content
If the display text is link. Then this is a button - Verify the display text
Check on the displayed link, and do not click anything, this is suspicious content; official organizations do not embed links in attachment-like buttons - Contact the IT for support
Be Aware of SMS Phishing
Do not respond to suspicious phone numbers
Do not click links from unknown senders
Do not download attachments from unknown senders
Do not share personal or financial information
Do not share OTP codes with anyone