Chris Clicked the Link. Then Everything Went Sideways.
Chris and his boss, David Levinson, aren’t exactly on speaking terms.
Their interactions are… tense.
Short emails. Passive-aggressive comments. Occasional sarcasm with a CC to HR.
So when Chris got a blunt message from “David”, Chris didn’t think twice. He clicked.
Nothing happened.
Until it did.
Within minutes, malware installed silently in the background.
It logged keystrokes. Monitored activity. Began scanning for network access points.
Chris thought he’d opened a document.
He’d opened a door.
The email wasn’t from David.
The tone was spot-on, but the address was subtly wrong: d.levinson@exec-teams.com
This wasn’t just any phishing email: it was spear phishing, tailored to the target.
Attackers didn’t need to hack the firewall.
They just needed to know one thing:
➡️ Chris doesn’t like his boss.
They weaponised frustration, pressure, and authority to make the message feel real, because when emotions are high, attention to detail drops.
Most security training tells people:
🚫 Don’t click suspicious links.
🚫 Don’t download unknown attachments.
But in real life?
Suspicious links don’t look suspicious.
And attachments often come wrapped in emotion.
That’s why at DCT Security, we don’t just tell people what to do: we show them what really happens.
Our training platform, goDeep, uses immersive stories to help people understand both the tech and the trick behind modern cyberattacks.
In Chris’ Scam List, we bring these stories to life: showing how small mistakes lead to big problems.
See how goDeep turns thinking like this into training your team will actually remember.