You've been phished
You clicked a link in a simulated phishing email. This was a test run by the Carsome Cybersecurity team as part of our ongoing awareness program. Nothing has been compromised and no data has been lost. But if this had been a real attack, this one click could have been enough to give an attacker your account or your device. See what a real attack can cost
If this is your first click
Please review the three sections of awareness material using the navigation on the left, then complete the quiz. Work through each section and confirm as you go.
If this is your second click or more
Punitive action will be taken. Your reporting manager and Human Resources will be notified.
What is phishing
Phishing is the most common way attackers gain access to a company's systems. Understanding how these emails work is your best defense against them.
Phishing is a fake email or message that pretends to come from someone you trust, usually IT, a manager, a customer, or a well-known company. Its goal is to get you to give up your password, approve a payment, or open a malicious file. These emails are sent to many people at once, and the attacker only needs one person to respond.
Sense of urgency
Tight deadlines, threats of account suspension, or warnings of lost access are used to rush you into acting before you stop to check.
Impersonating someone you trust
The sender poses as IT support, a manager, a finance contact, or a courier, so the request feels normal and you are less likely to question it.
Stealing your credentials
The goal is almost always the same: your login details, an approved payment, or a malicious attachment that gives the attacker access to your device.
- One stolen password can be enough to give an attacker access to company systems, shared drives, and internal messages.
- On a phone, the sender address and links are often hidden or cut off. Be extra careful when checking email on mobile.
- If a message is unexpected, rushed, or doesn't match the normal process, confirm it another way, a call or message to a known number before you act.
- Taking a moment to verify is never a problem. A genuine request will still be valid after you have confirmed it.
How to spot & report it
Select any numbered marker to see what gave it away as a fake.
CARSOME
Dear User,
Our system has detect that your CARSOME email password will be expiring in 2 hours from now.
⚠ Immediate action required to avoid account suspension.
Failure to update your password within the specified time will result your account to be permanently locked.
Regards,
IT Service Desk · CARSOME IT Department
Reporting procedure — Gmail
- Open the suspicious email.
- Select the three dots (⋮) in the top-right corner of the message.
- Select Report as Phishing.
Business risk
These are recent, real incidents at organizations in Malaysia and the region. In each one, the problem started with a single person acting on a fake message.
Ten-hour disruption at KLIA
On 23 March 2025, systems at Kuala Lumpur International Airport were disrupted for more than ten hours, affecting flight information displays, check-in counters, and baggage handling, with staff reverting to manual operations. The Prime Minister confirmed a USD 10 million ransom demand, which the Government refused. The Qilin ransomware group later claimed responsibility. The initial access method has not been publicly disclosed.
A phishing email, then a fabricated video call
A finance employee received an email purporting to be from the group chief financial officer requesting a confidential transaction. The employee correctly suspected phishing and requested a video call to verify. Every other participant on that call was an AI-generated deepfake of a colleague he recognized. Reassured, he executed fifteen transfers totaling USD 25.6 million.
Losses across Malaysian companies
Malaysia recorded losses exceeding RM 7.5 million to business email compromise between 2023 and the first half of 2025, alongside 64,778 phishing attempts directed at Malaysian companies, an average of more than 5,300 per month during 2024, and the third-highest volume in South-East Asia. Separately, MyCERT reported that phishing accounted for 68 percent of all fraud incidents reported in Q1 2025.
Customer and dealer data. Carsome holds personal, transactional, and payment information across multiple markets. A compromised account provides a direct route to that data.
Operational continuity. As demonstrated at KLIA, an intrusion affecting core systems is capable of forcing an organization into manual operations within hours, in full public view.
Regulatory obligation. The Personal Data Protection (Amendment) Act 2024 introduced mandatory breach notification and a required Data Protection Officer, both effective 1 June 2025. Equivalent obligations apply in the other markets in which we operate.
Verification must extend beyond email. The Arup case demonstrates that a video call is no longer sufficient confirmation of identity. Verify unexpected financial or access requests through a known contact number and established process.
This is a local threat, not a distant one. Malaysian companies are subject to thousands of phishing attempts every month, and phishing accounts for the majority of all fraud incidents reported nationally.
Quiz
Complete the short quiz below to finish this exercise. A passing mark of 14/15 is required. Your response is recorded by the Cybersecurity team.
Final step. Answer every question and submit the form below. The passing mark is 14/15 — if you do not pass, you are required to retake the quiz. If the quiz does not load, open it in a new tab.
Acknowledgement
By confirming, you record that you have reviewed all three sections and completed the quiz.