Simulation
Can your team spot this?
Two short, realistic examples you can try right now: an email a finance team meets before a payment run, and a QR code on a printed parking notice. Select what looks wrong, then see why it works. No sign-up.
Example 1
New bank details, before today's payment run
- from
- Nour Logistics <accounts@nour-logisticss.com>
- reply-to
- to
- you@yourcompany.co.uk
- date
- 1 Oct 2026, 10:42
Hi,
Please update our remittance details using the attached letter today, ahead of the payment run.
Many thanks,
Accounts, Nour Logistics
Tells found 0 of 4
- Lookalike domain. The real supplier is nour-logistics.com. Someone registered a near-identical one.
- The reply-to is a personal Gmail, not the company domain, so your reply would reach the attacker.
- Time pressure before a payment run is a classic push to make you skip your checks.
- An unexpected attachment that asks you to change bank details. Verify by calling the number already on file.
Select what looks wrong. No sign-up.
Example 2
City of Riverton
Parking Services
Outstanding parking fee
Our records show an unpaid fee for this vehicle. Scan the code below to pay within 24 hours and avoid a £65 penalty.
Scan to pay
Before you scan anything, ask where it goes.
Select the button to reveal the destination and the tells. No sign-up.
What good looks like
Practice, not a test
Vigil runs email and QR examples like these as realistic simulations. People practise in a safe setting, see why each lure works, and build the habit of checking the destination before they act. No blame, no catch-out.
Book a demo