The Phishing Lab
Messages to check. Phishing or legitimate? You decide.
Risks to financial safety and security
DM
DI Marsh

Welcome to the lab. Eight messages have been pulled from the tray for you today: emails, texts, a WhatsApp or two. Some are phishing attempts. Some are the real deal. Your job: work through them one by one. Mark each as fraud or cleared, and where it's fraud, tag the evidence. I'll be here between cases. The batch changes every time. Come back tomorrow, you'll see different ones.

What you'll be doing

  • Examine each message carefully, the way a real investigator would.
  • Decide: is it phishing (a scam) or legitimate (real)?
  • If you mark it as phishing, tag the red flags: the specific clues that gave it away.
  • Get the verdict, learn what you missed, then on to the next case.
8Cases per round
3Channels
20Case library

Why this matters

Fraud in the UK reached £1.2bn in 2024 with over 3 million recorded cases. The single most important skill you can build isn't memorising every scam type. It's noticing: the dodgy domain, the manufactured urgency, the generic greeting from a bank that knows your name. By the end of this lab, you'll have seen the patterns enough times to spot them in the wild.

How a case works
Four steps. Same pattern every time.

Step one. Read the exhibit

Each case opens with the message itself, displayed as it would arrive in real life. An email looks like an email; a text looks like a text. Read it carefully. What's the sender claiming? Are there any details that feel off?

Step two. Give your verdict

Decide: is this a phishing attempt, or is it legitimate? Two big buttons. No going back, so take your time. About a third of the cases are real, so don't false-flag a genuine bank alert.

Step three. Tag the evidence (if it's phishing)

Mark a message as phishing and you'll go into tagging mode. The message stays exactly as it was, with nothing helpfully highlighted. Click any phrase that looks suspicious to you. If you've spotted a real red flag, it gets pinned. If you've clicked something innocent, the word shakes briefly to tell you it's not a tell. Stuck? After a while, a hint link appears at the bottom of the tag bar.

Step four. Read the dossier

You'll see whether your verdict was right, which flags you spotted and which you missed, and a short explanation of why each detail matters. Then on to the next case.

Case files closed
DI Marsh has read the dossier
0
out of 8

Investigation complete

DM
DI Marsh

Good work. Take a look at what you noticed and what slipped past.

The case-by-case

# Case Your call Correct? Evidence

The four rules to take away

Check the domain

Real organisations use clean, predictable domains. hsbc.co.uk not hsbc-bank-uk.support. The single highest-value tell in any phishing case.

Urgency is a tactic

"Verify within 24 hours" or "only 3 spots left" exists to bypass your judgement. Real businesses don't need to threaten you to act.

Generic greetings betray

Your bank knows your name. Your delivery company knows your name. "Dear Valued Customer" is a giveaway.

Never act from the link

If something looks important, open the app or type the website yourself. Never enter details by clicking a link in a message.