🎯 YOU JUST COMPLETED A PHISHING SIMULATION TEST

This Was a Phishing Simulation by the Data and Technology Division

This was a phishing awareness exercise. This was not a real security threat, but rather a training opportunity to help you identify and avoid actual phishing attempts in the future. If you entered any credentials, know that they are not used for anything and your account is NOT compromised.


If you are seeing this notice, it means that you interacted with a simulated phishing email. Use this as a learning opportunity — not a judgment.

If you have any questions or concerns, please contact Tyler Rainey, Director, Data and Technology at tyrainey@ccrpc.org.

🚨 Red Flags You Should Have Noticed

Sender & Domain

Lookalike Sender Domain: Real AWS security alerts come from @amazon.com or @aws.amazon.com. This email came from a domain designed to look plausible but is not an official AWS domain.
Passing Authentication Is Not Enough: This email passed SPF, DKIM, and DMARC. Attackers can and do set up legitimate authentication for their own domains. A passing authentication check does not mean the sender is trustworthy — it only means the domain owner authorized the send.

Suspicious Account Activity Claims

Placeholder Account ID: The account ID 123456789012 is a template placeholder. Real AWS alerts show your actual account ID or alias.
Geographically Implausible Login: A login from Beijing, China would be highly unusual for our organization. Real security alerts include IP addresses, ISP details, and precise timestamps — this one had none of that.
Generic Device Details: "Chrome on Windows" lacks version numbers, device identifiers, or browser fingerprints that AWS actually tracks.

Pressure Tactics

Artificial Link Expiration: The "24 hours" expiration creates urgency and discourages verification. Real AWS security alerts don't typically expire links on a short timer.
False Reassurance: The phrase "If this was you, no action is needed" is designed to lower your guard while still nudging you toward the link.

Links & Destinations

Mismatched Button URL: Hovering over "Review Account Activity" would have shown a URL that is not an Amazon or AWS domain. Always hover before clicking.
Mismatched Landing Page URL: After clicking, the browser's address bar showed a non-AWS domain — not aws.amazon.com. The page looked like AWS, but the URL did not match.
Polished Design Building False Trust: The email and landing page used professional styling and real AWS brand colors to appear legitimate. Polished design alone is not proof of legitimacy — attackers invest in good design too.

Landing Page Red Flags

Credential Harvesting Form: The fake AWS login page captured username and password. Real login pages for AWS would be on an AWS-owned domain.
Unusual User Type Selection: Real AWS sign-in does not ask you to choose between "Administrator" and "Employee" before login. This is a technique to harvest a wider range of credentials.
Marketing Sidebar Mismatch: The sidebar advertised features like "Single sign-on integration" and "24/7 security monitoring" that are not part of the AWS sign-in experience.

🛡️ How to Protect Yourself

🔍 Verify the Sender Domain

Check the full sender address, not just the display name. Legitimate AWS emails come from @amazon.com or @aws.amazon.com.

⏰ Don't Rush

Urgency and expiration timers are common phishing tactics. Slow down and verify before acting.

🔗 Hover Before Clicking

Hover over any link to see where it actually goes. If the destination doesn't match the sender, don't click.

🌐 Check the Address Bar

After clicking, look at the URL. If it doesn't match the brand on the page, close the tab.

📞 Verify Through Official Channels

When in doubt, navigate to the service directly in your browser rather than using the link in the email.

📚 Know How Real Alerts Look

Familiarize yourself with how AWS and other services actually communicate security alerts, so you can spot fakes.