weakestlink

← All courses

Nano-lesson · usually takes 2–3 minutes

The myth of the harmless click

For you, who has seen it all before — and therefore clicks “just to have a look”. Why that trick has become dangerous.

For those of you who've seen it all before

You don't take the bait. You read sender addresses, check links and have spotted more scam emails than most. That's exactly why this course is for you — because the habit many experienced people have is clicking "just to have a look". Without typing anything. Without logging in. Completely harmless, right? It used to be. Not any more.

Three reasons the click alone is enough

  • The link is tagged with your name. Links in scam emails today are unique per recipient. One click tells the scammer: "the address works, and the person behind it clicks". That puts you at the top of the list for the next, sharper attempt.
  • The click can redeem a one-time ticket. Some links carry a code that does something the instant they're opened — confirms a sign-up, approves a request, signs off on a document. "But I didn't type anything" — no, but the click was the action.
  • Your phone is no safe haven. On mobile a page can, in rare cases, exploit holes in the browser without you doing more than opening it — and the screen is too small to show you the full address. "I'll just open it on my phone, it's safer" is exactly backwards.

Notice the code at the end?

Protocolhttp:// Domaincompany-document.info /open?id=YOUR-NAME-8841Path
Protocol
The way the page is retrieved (http or https).
Domain
The actual place the page lives. This is the part you need to read.
Path
The specific page on the domain.

id=YOUR-NAME-8841 isn't decoration — it points to you. If you click, the scammer records who opened it, when and from which device. The "I'll just look without doing anything" test doesn't exist: the click is the record.

The copycat page that patches through to the real one

Modern fake login pages are no longer stiff copies. They work like a patch-through: everything you see is pulled live from the real site — including your genuine MFAMulti-factor authentication (MFA/2FA): an extra step beyond your password — such as a code or a tap on your phone — so a thief can't log in with the password alone. approval. You log in, everything works, you land in the right place. And the scammer sits in the middle, now logged in as you. MFA doesn't stop this — it can't protect you from logging in yourself through the scammer's pipe.

Do this

if you happened to click — or you logged in via a link and something felt off — tell IT straight away. Speed beats embarrassment, every time.

The strongest use of your experience

You can see them. So use that where it matters: report instead of looking. Your report warns everyone who got the same email — including those who can't see what you can. Clicking "to check" only gives you an answer; reporting protects your whole workplace.

Remember

Your experience is valuable — use it on report@weakestlink.io, not on the click.

What the research says

Patch-through attacks that intercept logins despite MFA grew 146% in a single year. And a study of 19,500 employees showed that neither experience nor annual training on its own lowers the click rate noticeably — what does is the system around you: fast reporting and shared warnings. No one is immune. Not even the best.

Microsoft Digital Defense Report 2024 · Ho et al., IEEE S&P 2025.

Question 1 of 3

You've seen through a scam email in ten seconds. Now you're curious: where does the link actually lead? What do you do?

Question 2 of 3

You clicked a link and logged in — the MFA app prompted you as normal, and you landed in the right place. Can you be sure everything's OK?

Question 3 of 3

A colleague often asks you whether an email is genuine. Today you caught a scam email yourself. What's the strongest use of your experience?

Well done!

You've completed one of the foundation courses — the ones everyone gets for free.

With a free login:

  • Your points, progress and course certificate are saved.
  • You get courses tailored to your role — not just the foundation courses.
  • We send training exactly when you need it — for example, as a follow-up to a phishing test.