This Was a Phishing Simulation by the Data and Technology Division
This was a phishing awareness exercise. This was not a real security
threat, but rather a training opportunity to help you identify and
avoid actual phishing attempts in the future. If you entered any
credentials, know that they are not used for anything and your
account is NOT compromised.
If you are seeing this notice, it means that you interacted with a
simulated phishing email. Use this as a learning opportunity — not a
judgment.
🚨 Red Flags You Should Have Noticed
Sender & Domain
Lookalike Sender Domain:
Real AWS security alerts come from @amazon.com or
@aws.amazon.com. This email came from a domain
designed to look plausible but is not an official AWS domain.
Passing Authentication Is Not Enough:
This email passed SPF, DKIM, and DMARC. Attackers can and do set up
legitimate authentication for their own domains. A passing authentication
check does not mean the sender is trustworthy — it only means the domain
owner authorized the send.
Suspicious Account Activity Claims
Placeholder Account ID:
The account ID 123456789012 is a template
placeholder. Real AWS alerts show your actual account ID or alias.
Geographically Implausible Login:
A login from Beijing, China would be highly
unusual for our organization. Real security alerts include IP addresses,
ISP details, and precise timestamps — this one had none of that.
Generic Device Details:
"Chrome on Windows" lacks version numbers,
device identifiers, or browser fingerprints that AWS actually tracks.
Pressure Tactics
Artificial Link Expiration:
The "24 hours" expiration creates urgency and
discourages verification. Real AWS security alerts don't typically expire
links on a short timer.
False Reassurance:
The phrase "If this was you, no action is needed"
is designed to lower your guard while still nudging you toward the link.
Links & Destinations
Mismatched Button URL:
Hovering over "Review Account Activity" would
have shown a URL that is not an Amazon or AWS domain. Always hover before
clicking.
Mismatched Landing Page URL:
After clicking, the browser's address bar showed a non-AWS domain — not
aws.amazon.com. The page looked like AWS, but
the URL did not match.
Polished Design Building False Trust:
The email and landing page used professional styling and real AWS brand
colors to appear legitimate. Polished design alone is not proof of
legitimacy — attackers invest in good design too.
Landing Page Red Flags
Credential Harvesting Form:
The fake AWS login page captured username and password. Real login pages
for AWS would be on an AWS-owned domain.
Unusual User Type Selection:
Real AWS sign-in does not ask you to choose between "Administrator" and
"Employee" before login. This is a technique to harvest a wider range of
credentials.
Marketing Sidebar Mismatch:
The sidebar advertised features like "Single sign-on integration" and
"24/7 security monitoring" that are not part of the AWS sign-in experience.
🛡️ How to Protect Yourself
🔍 Verify the Sender Domain
Check the full sender address, not just the display name. Legitimate AWS emails come from @amazon.com or @aws.amazon.com.
⏰ Don't Rush
Urgency and expiration timers are common phishing tactics. Slow down and verify before acting.
🔗 Hover Before Clicking
Hover over any link to see where it actually goes. If the destination doesn't match the sender, don't click.
🌐 Check the Address Bar
After clicking, look at the URL. If it doesn't match the brand on the page, close the tab.
📞 Verify Through Official Channels
When in doubt, navigate to the service directly in your browser rather than using the link in the email.
📚 Know How Real Alerts Look
Familiarize yourself with how AWS and other services actually communicate security alerts, so you can spot fakes.