You sign in to a work portal, fetch the six-digit code from your Authenticator app, and get on with your day. An hour later your phone buzzes again — a sign-in approval you did not start. This simulation puts you in that exact moment.
You are on a call and someone asks you to show them the problem. Everything you have open is about to be offered up, including things that are none of their business.
Someone asks you to send over a record about a real person. It is a reasonable-sounding request, and it is exactly the kind that needs four quick checks first.
You are about to send a file to a colleague. Autocomplete has picked a name, and a document is already attached. Both are worth a second look before it leaves your outbox.
The phone rings. The person sounds calm, professional, and genuinely helpful, and they need your password to fix something. This is the most human version of an attack there is.
You are out of the office and need to get online. There are several networks, a portal asking for a code, and a pop-up that appears at exactly the wrong moment.
Two QR codes, one poster, one email. One is genuinely ours; the other wants your bank details. The only difference you can see is the address it opens.
A message lands that wants you to act right now. Nothing here is real and no link goes anywhere — you can poke at everything safely and find out what you would actually do under a little pressure.
You sit down at a front-desk computer and find it still logged in as a colleague, with their email open. What you do next matters for both of you.
You need to send an order file to an outside partner. The share dialog offers you a fast option and a safe option, and they look almost the same.
Something has gone wrong and you need to tell someone. The hard part is not the form — it is knowing what belongs in it and what does not.
A supplier you genuinely work with emails to say their bank details have changed, and the invoice is due. This is the most expensive scam that reaches an ordinary inbox.