Aller au contenu
Phishing

One email.
One compromised account.

A step-by-step simulation that reproduces a real attack: a fraudulent email, a fake Microsoft login page, and the reveal of the warning signs.

Realistic emailMicrosoft 365 cloneCredential capture
outlook.office365.com/mail/inbox
Inbox — Outlook
H
HR10:24

Leave schedule — approval needed

I
IT Support09:15

Scheduled update tonight — no action needed

S
Sophie L.yesterday

Re: Q2 project meeting

✓ Normal session — no alerts
Active signal
Step 1 of 4

The victim is working normally

Their inbox is open. The attacker already has their address — the campaign is being sent.

The attacker collects addresses from LinkedIn, the company website or past leaks. The email is personalized with the first name, job title and IT department to maximize credibility. This is spear phishing.

Key figures

0,0B

Phishing emails

sent every day worldwide

0%

Of targeted users

fail to spot an elaborate phishing attempt

0%

Of cyberattacks

start with a fraudulent email

Interactive demo

Live the attack from the inside

Four realistic scenarios — email, clone, SMS, call — to recognize manipulation techniques before falling victim to them.

An email targeted at a specific employee

Spear Phishing

The attacker uses real information (first name, company, context) to make the email credible and bypass the victim's natural wariness.

Simulation

Interactive demo — follow the steps

https://outlook.office.com/mail/inbox

⚠️ Your Microsoft account is temporarily suspended

Microsoft

We detected unusual activity on your account. Your access has been temporarily suspended.

To avoid permanent deletion of your mailbox within 24 hours, confirm your identity.

https://microsoft-secure-login.com/verify?token=a8f3k2...

💡 Hover over the button to see the destination URL

Attack analysis

  • ·A personalized, urgent subject line with real context
  • ·A sender mimicking an official domain with a subtle typo
  • ·A redirect to a perfect clone of the login page

Best practices

  • Check the sender's full domain, not just the displayed name
  • Access services by typing the URL directly into your browser
  • If in doubt, contact the sender through another channel