Nano-lesson · usually takes 2–3 minutes
The myth of the harmless click
For you, who has seen it all before — and therefore clicks “just to have a look”. Why that trick has become dangerous.
For those of you who've seen it all before
You don't take the bait. You read sender addresses, check links and have spotted more scam emails than most. That's exactly why this course is for you — because the habit many experienced people have is clicking "just to have a look". Without typing anything. Without logging in. Completely harmless, right? It used to be. Not any more.
Three reasons the click alone is enough
- The link is tagged with your name. Links in scam emails today are unique per recipient. One click tells the scammer: "the address works, and the person behind it clicks". That puts you at the top of the list for the next, sharper attempt.
- The click can redeem a one-time ticket. Some links carry a code that does something the instant they're opened — confirms a sign-up, approves a request, signs off on a document. "But I didn't type anything" — no, but the click was the action.
- Your phone is no safe haven. On mobile a page can, in rare cases, exploit holes in the browser without you doing more than opening it — and the screen is too small to show you the full address. "I'll just open it on my phone, it's safer" is exactly backwards.
Notice the code at the end?
http://
Domaincompany-document.info
/open?id=YOUR-NAME-8841Path
- Protocol
- The way the page is retrieved (http or https).
- Domain
- The actual place the page lives. This is the part you need to read.
- Path
- The specific page on the domain.
id=YOUR-NAME-8841 isn't decoration — it points to you. If you click, the scammer records who opened it, when and from which device. The "I'll just look without doing anything" test doesn't exist: the click is the record.
The copycat page that patches through to the real one
Modern fake login pages are no longer stiff copies. They work like a patch-through: everything you see is pulled live from the real site — including your genuine MFAMulti-factor authentication (MFA/2FA): an extra step beyond your password — such as a code or a tap on your phone — so a thief can't log in with the password alone. approval. You log in, everything works, you land in the right place. And the scammer sits in the middle, now logged in as you. MFA doesn't stop this — it can't protect you from logging in yourself through the scammer's pipe.
Do this
if you happened to click — or you logged in via a link and something felt off — tell IT straight away. Speed beats embarrassment, every time.
The strongest use of your experience
You can see them. So use that where it matters: report instead of looking. Your report warns everyone who got the same email — including those who can't see what you can. Clicking "to check" only gives you an answer; reporting protects your whole workplace.
Remember
What the research says
Patch-through attacks that intercept logins despite MFA grew 146% in a single year. And a study of 19,500 employees showed that neither experience nor annual training on its own lowers the click rate noticeably — what does is the system around you: fast reporting and shared warnings. No one is immune. Not even the best.
Microsoft Digital Defense Report 2024 · Ho et al., IEEE S&P 2025.
Question 1 of 3
You've seen through a scam email in ten seconds. Now you're curious: where does the link actually lead? What do you do?
✓ Correct!
The link is tagged with you: the click itself tells the scammer your address is active — a private window or mobile changes nothing. Your report warns everyone who got the same email.
Question 2 of 3
You clicked a link and logged in — the MFA app prompted you as normal, and you landed in the right place. Can you be sure everything's OK?
✓ Correct!
A patch-through connects you to the real site — everything looks right precisely because it IS the real site, seen through the scammer's pipe. If you logged in via a link and something feels off: tell IT.
Question 3 of 3
A colleague often asks you whether an email is genuine. Today you caught a scam email yourself. What's the strongest use of your experience?
✓ Correct!
Your click only gives you an answer — and records you with the scammer. If you forward it, you spread the trap itself. One report protects everyone — including those who wouldn't have asked.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.