Phishing Awareness Challenge

Can you navigate the digital waters safely? Test your phishing detection skills in this 5-step challenge.

0%

Challenge Completed!

Quick Tips Recap

    Why practice beats reading

    Most people can list the warning signs of a phishing message. Far fewer spot them in the moment, because real attacks do not arrive labelled as tests — they arrive when you are busy, distracted, and expecting something that looks roughly like what has just landed in your inbox.

    This challenge puts you in that position five times. Each scenario is modelled on a tactic currently in circulation, and after every answer you are shown which specific signals gave it away.

    What the five scenarios cover

    • Credential-harvesting email. A message about account activity with a link to a convincing login page.
    • Job and task scams. Unsolicited offers of easy remote work, which build trust with a small real payment before asking for a deposit.
    • Tech-support pop-ups. Fake security warnings that freeze the browser and supply a phone number to call.
    • Delivery and fee messages. Small, believable charges designed to collect card details rather than the fee itself.
    • Impersonation. Requests that appear to come from a manager or relative, relying on urgency and authority rather than a malicious link.

    The signals that carry the most weight

    Urgency is the common thread. Nearly every scam manufactures a deadline, because deliberation is what defeats it. A message insisting you act within 24 hours deserves more scrutiny, not less.

    Read addresses from the right. The real domain is the part immediately before the first single slash. Everything to the left of it can be anything the sender chooses, including a familiar brand name placed to look reassuring.

    Unusual payment methods are decisive. Gift cards, wire transfers and cryptocurrency are chosen because they cannot be reversed. No legitimate organisation will ask for them.

    Secrecy is a red flag by itself. Requests not to tell anyone exist to remove the one thing most likely to stop the scam — a second opinion.

    The padlock proves nothing. Free certificates mean any fraudster can display exactly the same one your bank does.

    What to do when something looks wrong

    Do not reply, and do not use the contact details in the message. Open a new tab, type the organisation's address yourself, and check your account directly. If someone claiming to be a person you know asks for money, call them on a number you already have. Then report the message and delete it — engaging at all confirms your address is live.

    Frequently asked questions

    Is this phishing game safe to play?

    Yes. Every scenario is a simulation running inside this page. No real links are opened, nothing is downloaded, and no information you enter is transmitted or stored.

    How long does the challenge take?

    About five minutes. There are five scenarios, and each one explains which signals identified it after you answer.

    What if I get the answers wrong?

    That is the useful part. Each scenario explains exactly which details gave it away, which is what transfers to the real messages you receive later.

    Are the scenarios based on real scams?

    Yes. Each one is modelled on a tactic currently in circulation, including credential-harvesting emails, task scams, fake tech-support pop-ups, delivery fee messages and impersonation requests.

    Last reviewed: · Reviewed by the ShowMyIP team

    We use cookies to improve your experience. Learn more.