🔐 About This Simulation
The email you received was part of a controlled phishing simulation. If you clicked the link or entered your credentials, there is nothing to worry about. No personal data was at risk, and no disciplinary action will be taken. Treat this as a learning opportunity.
🎯 Why We Run Phishing Simulations
- Assess organizational resilience against real-world phishing attacks
- Identify high-risk departments and roles for targeted training
- Improve everyone's ability to recognize and report phishing emails
- Validate the effectiveness of our security incident response process
🎣 6 Tips to Identify Phishing Emails
1Check the Sender Address
Don't trust the display name — always inspect the full email address.
| ✅ Legitimate |
❌ Phishing |
| SAFE colleague@company.com |
PHISH c0lleague@company.com (digit substitution) |
| SAFE vendor@partner.com |
PHISH vendor@partner-security.com (extra domain) |
| SAFE support@microsoft.com |
PHISH support@rnicrosoft.com (letter swap) |
2Watch for Urgency & Threatening Language
Phishing emails often try to rush you into action before you can think:
- ⏰ False urgency: "Your password expires in 24 hours" / "Act now or account will be locked"
- 💰 Too good to be true: "You've won a gift card — claim here"
- 😨 Fear tactics: "Suspicious login detected — verify immediately" / "Security breach notification"
- 🔒 Authority impersonation: "CEO/VP requests urgent action" / "Legal department notice"
3Hover Before You Click
Hover your mouse over any link to see the actual destination before clicking:
Display text: https://company.com/login
Actual link: https://company-security.com/login SUSPICIOUS
Actual link: https://company.com.login.evildomain.com PHISHING
Actual link: https://company.com/auth/verify?token=xxx SAFE
4Check Email Formatting & Language
| Red Flag |
What to Look For |
| Spelling & grammar errors |
Professional companies proofread their communications |
| Generic greeting |
"Dear Customer" vs personalized "Dear {{.FirstName}}" |
| Distorted branding |
Blurry logos, wrong colors, misaligned layout |
| Unusual signature |
Missing contact details, odd formatting, wrong title |
| Asking for password |
Legitimate companies never ask you to enter a password via an email link |
5Be Cautious with Attachments
- HIGH RISK Compressed files (.zip, .rar) — commonly used to deliver malware
- BLOCKED Executables (.exe, .scr, .msi) — never open these
- CAUTION Office documents with macros (.docm, .xlsm) — macros are a common infection vector
- PHISHING "Enable macros to view this document" — classic malware delivery technique
6Verify Sensitive Requests
For any email involving financial transactions, sensitive data, or system access:
✅ DO
- Call the sender to verify (use phonebook number, not the one in the email)
- Confirm via internal chat (Teams / WeCom)
- Contact the Information Security team to verify
❌ DON'T
- Process payments based on email instructions alone
- Reply to the email asking "Did you send this?" — the attacker may be monitoring the inbox
- Click links in the email to log into any system
📋 What to Do When You Suspect a Phishing Email
You receive a suspicious email │
│
▼
Does it look like phishing? │
┌──────┴──────┐
▼ ▼
YES — Report it UNSURE?
Click "Report Phishing" │
button (PAB) ├─ Hover to check URL
Do NOT forward or click ├─ Check sender address
└─ Contact IT/Security
One-Click Reporting
- Click the "Report Phishing" button (PAB) in your email client
- The email is automatically forwarded to security@wuxibiologics.com
- The security team analyzes and responds with feedback
- Don't be embarrassed — every report helps make our company safer
📊 Campaign Timeline
| Phase |
Description |
| During Campaign |
Go about your normal work. The security team monitors simulation data in real time. |
| Campaign Ends |
Receiving this page means the simulation is complete. |
| Training Follow-up |
High-risk departments will receive targeted security awareness training. |
| Recognition |
Employees who successfully identified and reported the phishing email will be recognized. |
🔐 关于本次模拟
您收到的邮件是一次受控钓鱼模拟的一部分。如果您点击了链接或输入了凭据,无需担心。没有任何个人数据面临风险,也不会采取任何纪律处分。请将此视为一次学习机会。
🎯 我们为何开展钓鱼模拟
- 评估组织面对真实钓鱼攻击的抵御能力
- 识别高风险部门和岗位,以便开展针对性培训
- 提升每个人识别和举报钓鱼邮件的能力
- 验证我们安全事件响应流程的有效性
🎣 识别钓鱼邮件的 6 个技巧
1检查发件人地址
不要轻信显示名称 — 始终检查完整的电子邮件地址。
| ✅ 合法 |
❌ 钓鱼 |
| 安全 colleague@company.com |
钓鱼 c0lleague@company.com(数字替换) |
| 安全 vendor@partner.com |
钓鱼 vendor@partner-security.com(额外域名) |
| 安全 support@microsoft.com |
钓鱼 support@rnicrosoft.com(字母替换) |
2留意紧迫感和威胁性语言
钓鱼邮件常试图在您思考之前催促您采取行动:
- ⏰ 虚假紧迫感:“您的密码将在 24 小时后过期” / “立即操作,否则帐户将被锁定”
- 💰 过于美好而难以置信:“您赢得了一张礼品卡 — 在此领取”
- 😨 恐吓策略:“检测到可疑登录 — 立即验证” / “安全违规通知”
- 🔒 冒充权威:“CEO/VP 要求紧急操作” / “法务部门通知”
3点击前先悬停
将鼠标悬停在任何链接上,以查看实际目标地址:
显示文本: https://company.com/login
实际链接: https://company-security.com/login 可疑
实际链接: https://company.com.login.evildomain.com 钓鱼
实际链接: https://company.com/auth/verify?token=xxx 安全
4检查邮件格式和语言
| 危险信号 |
注意要点 |
| 拼写和语法错误 |
正规公司会校对邮件内容 |
| 通用称呼 |
“尊敬的客户” 与 个性化的 “尊敬的 {{.FirstName}}” |
| 品牌标识失真 |
模糊的徽标、错误的颜色、错位的布局 |
| 异常的签名 |
缺少联系方式、奇怪的格式、错误的职务 |
| 索要密码 |
正规公司 绝不会 通过邮件链接要求您输入密码 |
5谨慎对待附件
- 高风险 压缩文件(.zip、.rar)— 常用于传递恶意软件
- 已阻止 可执行文件(.exe、.scr、.msi)— 切勿打开
- 谨慎 带有宏的 Office 文档(.docm、.xlsm)— 宏是常见的感染途径
- 钓鱼 “启用宏以查看此文档” — 经典的恶意软件投递手段
6核实敏感请求
对于涉及 财务交易、敏感数据或系统访问 的任何邮件:
✅ 应做
- 致电发件人核实(使用通讯录中的号码,而非邮件中提供的)
- 通过内部聊天(Teams / 企业微信)确认
- 联系信息安全团队进行核实
❌ 不应做
- 仅凭邮件指令处理付款
- 回复邮件询问“是您发的吗?” — 攻击者可能正在监控收件箱
- 点击邮件中的链接登录任何系统
📋 怀疑收到钓鱼邮件时应如何操作
您收到可疑邮件 │
│
▼
看起来像钓鱼吗? │
┌──────┴──────┐
▼ ▼
是 — 举报 不确定?
点击“举报钓鱼” │
按钮 (PAB) ├─ 悬停检查 URL
不要转发或点击 ├─ 检查发件人地址
└─ 联系 IT/安全团队
一键举报
- 在邮件客户端中点击 “举报钓鱼” 按钮(PAB)
- 邮件会自动转发至 security@wuxibiologics.com
- 安全团队进行分析并反馈
- 不要觉得难为情 — 每次举报都有助于公司更加安全
📊 演练时间线
| 阶段 |
说明 |
| 演练期间 |
正常进行日常工作。安全团队会实时监控模拟数据。 |
| 演练结束 |
收到此页面表示模拟已完成。 |
| 后续培训 |
高风险部门将接受针对性的安全意识培训。 |
| 表彰 |
成功识别并举报钓鱼邮件的员工将获得表彰。 |