⚠️ TRAINING DEMO — This is a simulated example of a phishing page. No data is sent anywhere. For security awareness training only.

🎣 What a phishing page looks like

Below is a simulated phishing page. Red annotations show what attackers exploit and what employees should notice.

🚩 RED FLAG: Fake URL
https://linkedin-verify-account.com/secure-login
Not linkedin.com — attackers register lookalike domains. Always check the full domain.
🎭 Simulated Fake Login Page

Your account requires verification. Please sign in to confirm your identity.

⚠️ Urgency language — designed to make you act without thinking
⚠️ These fields send your credentials to the attacker's server, not LinkedIn
By signing in you agree to our Terms of Service
⚠️ Looks identical to the real site — attackers copy HTML/CSS exactly
👁️ What happens silently before you type anything
✓ Your IP address logged → approximate location identified
✓ Browser & OS fingerprinted → device identified
✓ Canvas fingerprint generated → unique device ID created (persists across incognito)
✓ Screen size, language, timezone captured
✓ Time of visit, referrer URL logged
✗ None of this requires you to click "Sign in"

🎓 Key takeaways for employees

🚩 Red Flags Checklist → ← Main Demo