ACORD/ASG Simulated Phishing Campaign - 5 Scanned the QR Code
Now here's the actual email we sent. Take 30 seconds to spot the 6 red flags:
1️⃣ [EXT] tag in the subject – The "[EXT]" label means this came from outside ACORD. Take extra time with any [EXT] email — it's from an outside source and may not be legit.
2️⃣ Odd sender – "IT <it@acordsolutions.com>" looks close, but ask yourself: have I gotten an email from this address before? An unfamiliar or unexpected sender is a warning sign.
3️⃣ External CAUTION banner – That yellow "originated from outside the organization" warning backs up flag #1.
4️⃣ The QR code – Be very cautious with QR codes from an unknown or external source. Unlike a link you can hover over, a QR code hides where it really takes you, so its legitimacy is tough to check. If you weren't expecting it, don't scan it.
5️⃣ Fake deadline – "Complete by end of week" pressures you to act before thinking.
6️⃣ Vague sign-off – "IT Operations," no name, no way to verify.
The rule: It's not about never clicking or scanning — it's about knowing the difference between a legit email and a fake one. When something feels off and you're not sure, that's when you hit the Phish Alert Button and let us take a look.
When to use it: The Phish Alert Button is for emails that look like they're trying to steal your info or money. For everyday spam or annoying sales emails, just delete them (or right-click → Junk to block the sender) — no need to report those.
Comments
0 comments
Please sign in to leave a comment.