Response desk

Choose Alex’s next action. The feedback is for learning; it does not award CTFd points.

What should Alex do?

A · Complete the verification before 5:00 p.m.

This would expose the work password and current authenticator code to the page operator. A code could be used quickly to attempt a sign-in. Urgency and personal details do not establish authorization.

B · Reply to M02 and ask whether the request is real

The reply goes to the address supplied by the same message. A deceptive sender could simply confirm their own request. Use a separate, previously trusted contact route.

C · Stop and contact the help desk using the saved directory

This provides independent verification. Preserve M02 and report it through the approved channel. Do not supply the password or code, and do not use the questionable message’s contact details.

V01 · Verification result

Read the help-desk response after independent contact

“We did not send M02. There is no travel revalidation deadline for Alex. The sender domain and destination are not approved Northbridge services. Please preserve the original message and report it through the bookmarked employee portal.”

This response was obtained through the trusted directory, not by replying to M02.

If Alex already entered information

Review the incident response

Immediately notify the real help desk through the trusted route and explain what was entered and when. Stop interacting with the page. Use the known legitimate portal to change the exposed password, following IT instructions. IT should revoke active sessions, review sign-ins and account changes, and reset affected authentication methods as needed.

Do not assume an expired code or a password change alone ends every session. Preserve the message and timeline. If the password was reused elsewhere, change it there too through each service’s trusted route.

Complete your investigation

Use your notes to name the message, explain the address mismatch, trace three public clues, describe the attempted harm, and recommend a safe response.

Finish with one privacy change: for example, delay posting trip dates until after returning, restrict roster access, or reduce public personal details. Less exposure can reduce targeting, but receiving phishing is never the recipient’s fault.

CYBER.ORG Phishing Challenge • Copyright © 2026 Cyber Innovation Center • All Rights Reserved. Not for Distribution.