Week 1: How Do Organizations Get Hacked? (The Email Trap)

Module 1: The Anatomy of an Invisible Danger
Cybersecurity is not only about the dangers inside the screen. To break into strong systems, malicious actors most often exploit the simple mistakes of human nature.
🔎 Hands-On Lab: Phishing Analysis
In the simulation below, you can see how to spot the “red flags” in a fake phishing email.

🚨 1. Malicious Attachments and Ransomware
Attackers constantly change their software. The most common tactic is to send you a fake “Invoice,” “Shipping Document” or “Payment Receipt” marked as urgent.
How does it work? The email has an attachment that looks like a PDF but actually contains malicious code. The moment you click it, the files on your computer and on every company server you have access to are encrypted.
🕵️♂️ 2. Executive Impersonation (CEO Fraud)
Attackers do not send emails at random. They research the company hierarchy and reach out to you directly using your manager’s name.
To: Accounting / Finance
Subject: CONFIDENTIAL AND URGENT: New Supplier Payment “Hello, I am in a very important meeting right now and cannot answer calls. A transfer of 50,000 TL needs to be made urgently to the new supplier account attached.”
Be suspicious of every email that comes from a source you were not expecting and contains a link or an attachment. When you are not sure, check with your IT department. No IT staff member will ever ask you for your password by email! Author:

