Nano-lesson · usually takes 2–3 minutes
Help — I've clicked! How to report it
Everyone gets caught out now and then. Reporting quickly limits the damage.
Anyone can be caught out
Even experienced colleagues get caught out. The most important thing isn't to avoid every mistake, but to react quickly — minutes matter.
Have you clicked, entered a password or made a payment?
- Report it straight away — even in the middle of a night shift. It can't wait until tomorrow, and no one gets into trouble for speaking up.
- Did you enter a password? Change it immediately — including everywhere else you use the same password.
- Don't feel embarrassed — speed protects both you and the company.
Why is it so urgent?
Because you usually have a small window of time. When you've entered your Log in on a fake page, the details are rarely used that same second — scammers often harvest credentials in bulk and only put them to use later. When you report it quickly, IT can change your password and check for intruders before the details are used. React quickly enough, and there's honestly no harm done — which is why those first few minutes count.
Unsure about an email?
Forward it to report@weakestlink.io anyway. A report is also a warning to the colleagues who got the same email.
Remember
What the research says
Your report works. In a large study, colleagues' reports were so accurate (~68%) that new attacks were caught in under ~5 minutes. People who've recently trained report ~4× more often — and every report simultaneously warns all colleagues who received the same email.
Lain et al., IEEE S&P 2022 · Verizon DBIR 2025 · Chen et al., USENIX SOUPS 2024.
Question 1 of 3
At 11:40 pm on a night shift you realise you've entered your password on a fake page. What do you do?
✓ Correct!
Changing the password is right — but only IT can see whether anyone has already got in, and warn colleagues who received the same email. And it can't wait: the window of time is now.
Question 2 of 3
An email looks suspicious, but you're only half sure — and you'd rather not waste IT's time. What do you do?
✓ Correct!
IT would rather have ten reports too many than one too few — and your report automatically warns colleagues with the same email. Asking around only causes delay.
Question 3 of 3
You entered your password on a fake page ten minutes ago — and nothing has happened. Why is reporting still urgent?
✓ Correct!
Stolen credentials are often harvested in bulk and only used hours or days later. That's exactly why a quick report works: the door can be locked before anyone walks in.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.