ZENITH PREP ACADEMY
IT Security
Colleagues who clicked 0 | Security awareness exercise
Security awareness test

You've been phished.

This was a controlled simulation — no real data was captured and no systems were affected.

You clicked a link in a simulated phishing email and attempted to open a fake document. In a real attack, this single action could have compromised your credentials, exposed student data, or installed malware on a ZPA device.

  • Fake domain The sender used @gmail.com, not an official @zenithprepacademy.com address. Anyone can create a Gmail account with any name.
  • Urgency Phrases like "as soon as possible today" are designed to make you act without thinking. Real leadership gives context.
  • Vague request No document name, no project context, no reason you specifically need to review it. Legitimate internal comms are specific.
  • Hidden link The shortened bit.ly URL conceals the actual destination. ZPA never sends internal documents through third-party link shorteners.
  • Unsolicited You weren't expecting this document. Unsolicited requests for action — especially with links — are a core phishing pattern.

✓ No harm done. This was only a test. No data was collected, no systems were affected, and you are not in any trouble. This exercise exists to help our whole team stay sharp and protect our students' information.

If you receive a suspicious email in the future, do not click — report it to the IT Security team immediately. Verify unexpected requests directly with the sender through a separate channel (phone or Slack), not by replying to the email.