⚠
Security awareness notice

You've been phished

You clicked a link in a simulated phishing email. This was a test run by the CARSOME Cybersecurity team as part of our ongoing awareness program. Nothing has been compromised and no data has been lost. But if this had been a real attack, this one click could have been enough to give an attacker your account or your device. Example of actual attack

Applies to you
1

If this is your first click

Please review the four modules of awareness material using the navigation on the left, then complete the quiz. Work through each module and confirm as you go.

Applies to you
2+

If this is your second click or more

Punitive action will be taken. Your reporting manager and Human Resources will be notified.

Section 01

What is phishing

Phishing is the most common way attackers gain access to a company's systems. Understanding how these emails work is your best defense against them.

Phishing is a fake email or message that pretends to come from someone you trust, usually IT, a manager, a customer, or a well-known company. Its goal is to get you to give up your password, approve a payment, or open a malicious file. These emails are sent to many people at once, and the attacker only needs one person to respond.

Tactic 01

Sense of urgency

Tight deadlines, threats of account suspension, or warnings of lost access are used to rush you into acting before you stop to check.

Tactic 02

Impersonating someone you trust

The sender poses as IT support, a manager, a finance contact, or a courier, so the request feels normal and you are less likely to question it.

Tactic 03

Stealing your credentials

The goal is almost always the same: your login details, an approved payment, or a malicious attachment that gives the attacker access to your device.

Key points to remember
  • One stolen password can be enough to give an attacker access to company systems, shared drives, and internal messages.
  • On a phone, the sender address and links are often hidden or cut off. Be extra careful when checking email on mobile.
  • If a message is unexpected, rushed, or doesn't match the normal process, confirm it another way, a call or message to a known number before you act.
  • Taking a moment to verify is never a problem. A genuine request will still be valid after you have confirmed it.
Section 02

How to spot it

Select any numbered marker to see what gave the email away as a fake.

⋮ More
From CARSOME IT <it-department@carsomes.com>
To you@carsome.com
Subject URGENT: Your password expires in 2 hours - Action Required

CARSOME

Dear User,

Our system has detect that your CARSOME email password will be expiring in 2 hours from now.

⚠ Immediate action required to avoid account suspension.
Failure to update your password within the specified time will result your account to be permanently locked.

Reset Password Now →

Regards,
IT Service Desk · CARSOME IT Department

Section 03

How to report it

If you spot a suspicious email, report it in Gmail. It takes three clicks — follow the numbered steps on the menu below.

10:39 AM (55 minutes ago) ☆ ☺ ↩ ⋮
↩ Reply
↪ Forward
💬 Share in chat
🗑 Delete
✉ Mark as unread
⊘ Block "it-department@carsomes.com"
ⓘ Report spam
🚩 Report phishing
⚠ Do not click any links or open attachments first. Report it exactly as received.
! Why reporting matters

The more people report, the faster it stops. Every report alerts our security team and feeds Google's filters. The team can then investigate, contain the threat, and block it across the company, while Gmail gets better at recognizing and blocking similar attacks. Your report protects colleagues who haven't received it yet.

1
Alerts the security team

CARSOME Cybersecurity is notified instantly, so they can investigate, contain the threat, and block it across the company before more people click.

2
Trains the filters

Each report helps Gmail recognize the same attack and block similar ones in future — for everyone.

3
Removes it from your inbox

The email is moved to Spam, so you won't click it later by mistake.

Section 04

Business risk

These are recent, real incidents at organizations in Malaysia and the region. In each one, the problem started with a single person acting on a fake message.

2025 · Malaysia Airports Holdings Berhad
USD 10M
Ransomware

Ten-hour disruption at KLIA

On 23 March 2025, systems at Kuala Lumpur International Airport were disrupted for more than ten hours, affecting flight information displays, check-in counters, and baggage handling, with staff reverting to manual operations. The Prime Minister confirmed a USD 10 million ransom demand, which the Government refused. The Qilin ransomware group later claimed responsibility. The initial access method has not been publicly disclosed.

2024 · Arup, Hong Kong office
USD 25.6M
Phishing & deepfake

A phishing email, then a fabricated video call

A finance employee received an email purporting to be from the group chief financial officer requesting a confidential transaction. The employee correctly suspected phishing and requested a video call to verify. Every other participant on that call was an AI-generated deepfake of a colleague he recognized. Reassured, he executed fifteen transfers totaling USD 25.6 million.

Source: CNN
2023–2025 · Malaysia, national figures
RM 7.5M
Business email compromise

Losses across Malaysian companies

Malaysia recorded losses exceeding RM 7.5 million to business email compromise between 2023 and the first half of 2025, alongside 64,778 phishing attempts directed at Malaysian companies, an average of more than 5,300 per month during 2024, and the third-highest volume in South-East Asia. Separately, MyCERT reported that phishing accounted for 68 percent of all fraud incidents reported in Q1 2025.

Relevance to CARSOME
01

Customer and dealer data. CARSOME holds personal, transactional, and payment information across multiple markets. A compromised account provides a direct route to that data.

02

Operational continuity. As demonstrated at KLIA, an intrusion affecting core systems is capable of forcing an organization into manual operations within hours, in full public view.

03

Regulatory obligation. The Personal Data Protection (Amendment) Act 2024 introduced mandatory breach notification and a required Data Protection Officer, both effective 1 June 2025. Equivalent obligations apply in the other markets in which we operate.

04

Verification must extend beyond email. The Arup case demonstrates that a video call is no longer sufficient confirmation of identity. Verify unexpected financial or access requests through a known contact number and established process.

05

This is a local threat, not a distant one. Malaysian companies are subject to thousands of phishing attempts every month, and phishing accounts for the majority of all fraud incidents reported nationally.

Section 05

Quiz

Complete the short quiz below to finish this exercise. A passing mark of 13/14 is required. Your response is recorded by the Cybersecurity team.

✎

Final step. Answer every question and submit the form below. The passing mark is 13/14 — if you do not pass, you are required to retake the quiz. If the quiz does not load, open it in a new tab.

Acknowledgement

By confirming, you record that you have reviewed all three sections and completed the quiz.

✓ Acknowledgement recorded. Thank you for completing this exercise.