Security awareness notice

You've been phished

You clicked a link in a simulated phishing email. This was a test run by the Carsome Cybersecurity team as part of our ongoing awareness program. Nothing has been compromised and no data has been lost. But if this had been a real attack, this one click could have been enough to give an attacker your account or your device. See what a real attack can cost

Applies to you
1

If this is your first click

Please review the three sections of awareness material using the navigation on the left, then complete the quiz. Work through each section and confirm as you go.

Applies to you
2+

If this is your second click or more

Punitive action will be taken. Your reporting manager and Human Resources will be notified.

Section 01

What is phishing

Phishing is the most common way attackers gain access to a company's systems. Understanding how these emails work is your best defense against them.

Phishing is a fake email or message that pretends to come from someone you trust, usually IT, a manager, a customer, or a well-known company. Its goal is to get you to give up your password, approve a payment, or open a malicious file. These emails are sent to many people at once, and the attacker only needs one person to respond.

Tactic 01

Sense of urgency

Tight deadlines, threats of account suspension, or warnings of lost access are used to rush you into acting before you stop to check.

Tactic 02

Impersonating someone you trust

The sender poses as IT support, a manager, a finance contact, or a courier, so the request feels normal and you are less likely to question it.

Tactic 03

Stealing your credentials

The goal is almost always the same: your login details, an approved payment, or a malicious attachment that gives the attacker access to your device.

Key points to remember
  • One stolen password can be enough to give an attacker access to company systems, shared drives, and internal messages.
  • On a phone, the sender address and links are often hidden or cut off. Be extra careful when checking email on mobile.
  • If a message is unexpected, rushed, or doesn't match the normal process, confirm it another way, a call or message to a known number before you act.
  • Taking a moment to verify is never a problem. A genuine request will still be valid after you have confirmed it.
Section 02

How to spot & report it

Select any numbered marker to see what gave it away as a fake.

⋮ Report as phishing
From Carsome IT <it-department@carsomes.com>
To you@carsome.com
Subject URGENT: Your password expires in 2 hours - Action Required

CARSOME

Dear User,

Our system has detect that your CARSOME email password will be expiring in 2 hours from now.

⚠ Immediate action required to avoid account suspension.
Failure to update your password within the specified time will result your account to be permanently locked.

Reset Password Now →

Regards,
IT Service Desk · CARSOME IT Department

Reporting procedure — Gmail

  1. Open the suspicious email.
  2. Select the three dots (⋮) in the top-right corner of the message.
  3. Select Report as Phishing.
Do not click any links and do not open any attachments first. Report the email exactly as you received it.
Section 03

Business risk

These are recent, real incidents at organizations in Malaysia and the region. In each one, the problem started with a single person acting on a fake message.

2025 · Malaysia Airports Holdings Berhad
USD 10M
Ransomware

Ten-hour disruption at KLIA

On 23 March 2025, systems at Kuala Lumpur International Airport were disrupted for more than ten hours, affecting flight information displays, check-in counters, and baggage handling, with staff reverting to manual operations. The Prime Minister confirmed a USD 10 million ransom demand, which the Government refused. The Qilin ransomware group later claimed responsibility. The initial access method has not been publicly disclosed.

2024 · Arup, Hong Kong office
USD 25.6M
Phishing & deepfake

A phishing email, then a fabricated video call

A finance employee received an email purporting to be from the group chief financial officer requesting a confidential transaction. The employee correctly suspected phishing and requested a video call to verify. Every other participant on that call was an AI-generated deepfake of a colleague he recognized. Reassured, he executed fifteen transfers totaling USD 25.6 million.

Source: CNN
2023–2025 · Malaysia, national figures
RM 7.5M
Business email compromise

Losses across Malaysian companies

Malaysia recorded losses exceeding RM 7.5 million to business email compromise between 2023 and the first half of 2025, alongside 64,778 phishing attempts directed at Malaysian companies, an average of more than 5,300 per month during 2024, and the third-highest volume in South-East Asia. Separately, MyCERT reported that phishing accounted for 68 percent of all fraud incidents reported in Q1 2025.

Relevance to Carsome
01

Customer and dealer data. Carsome holds personal, transactional, and payment information across multiple markets. A compromised account provides a direct route to that data.

02

Operational continuity. As demonstrated at KLIA, an intrusion affecting core systems is capable of forcing an organization into manual operations within hours, in full public view.

03

Regulatory obligation. The Personal Data Protection (Amendment) Act 2024 introduced mandatory breach notification and a required Data Protection Officer, both effective 1 June 2025. Equivalent obligations apply in the other markets in which we operate.

04

Verification must extend beyond email. The Arup case demonstrates that a video call is no longer sufficient confirmation of identity. Verify unexpected financial or access requests through a known contact number and established process.

05

This is a local threat, not a distant one. Malaysian companies are subject to thousands of phishing attempts every month, and phishing accounts for the majority of all fraud incidents reported nationally.

Section 04

Quiz

Complete the short quiz below to finish this exercise. A passing mark of 14/15 is required. Your response is recorded by the Cybersecurity team.

Final step. Answer every question and submit the form below. The passing mark is 14/15 — if you do not pass, you are required to retake the quiz. If the quiz does not load, open it in a new tab.

Acknowledgement

By confirming, you record that you have reviewed all three sections and completed the quiz.

✓ Acknowledgement recorded. Thank you for completing this exercise.