One tap is the whole breach. The new account belongs to the attacker.
15 minutes. Three decisions under pressure, a red-flag sort, and a verification drill you can use the same day.
Before you start
One real attack pattern, played as decisions - no slides, no lectures.
You make timed choices; your score changes with your decisions.
You get a safety score with feedback on every decision - never a leaderboard, never your name.
Your firm sees completion evidence - never your answers. Teammates never see your score.
Finish and you get a certificate with a unique ID anyone can verify.
Free for everyone. All drills are free - finish and you get a verifiable certificate.
Why this module exists - the text is the trapdoor
One text campaign. Over 130 organizations compromised. Nearly 10,000 credentials stolen.
130+
Organizations compromised in the 2022 "0ktapus" smishing campaign - employees got texts posing as IT and Okta, and signed in to convincing fake pages. Twilio and Cloudflare were among the targets (Group-IB investigation).
~10,000
User credentials harvested by that campaign, including 5,441 MFA codes - investigators said attackers had to use the stolen codes quickly, before they expired (Group-IB; Ars Technica reporting, Aug 2022).
Cloudflare said three employees entered their credentials on the fake page too. The attack still failed there - every employee carries a physical security key, and the attackers could not get past the key requirement. The lesson is not "be smarter than the text." It is "make the tap useless, and never sign in from a link."
The text always has a clock on it: verify in 30 minutes, re-enroll by Monday, your pay is delayed. The deadline is a warning sign, not proof.
The muscle memory: Never sign in through a link that arrived by text. Open the real app or portal yourself, and report the message the same day.
Sources: Group-IB, "Roasting 0ktapus" (Aug 2022); Cloudflare incident blog (Aug 2022); Ars Technica reporting on the campaign (Aug 2022).
Dramatized scenario - built from documented attack patterns
Saturday, 9:12 AM. A text from "Cedarline-IT."
You are Dev Patel, advisory associate at Cedarline Wealth Management, a 25-person RIA. Your firm uses an Okta sign-in portal for email, CRM, and the portfolio system. Monday is a client-review day.
TEXT MESSAGE - +1 (415) 555-01649:12 AM
Cedarline-IT: We blocked an unusual sign-in to your account from Chicago, IL. If this wasn't you, verify your identity within 30 minutes or access will be suspended: cedarline-okta-verify.com
Reply STOP to opt out.
It names your firm. It references the sign-in system you use. The link looks almost right - but the real portal is cedarline.okta.com, and this link is cedarline-okta-verify.com. Saturday morning makes the pressure more effective: normal support may be slower, while Monday's deadline feels close.
Simulated scenario. Cedarline is fictional; the domain pattern is from real campaigns.
Decision 1 of 3 - the 30-minute clock
9:12 AM. Tap the link? Verify another way? You have 20 seconds.
Decision 2 of 3 - "nothing happened"
Monday, 8:03 AM. Your teammate Theo: "I got that text Saturday. I tapped it and signed in - page looked exactly like our portal, even prefilled my email. Nothing happened after, so it's fine, right?"
Decision 3 of 3 - the payroll text
Friday, 5:40 PM. A new text hits the whole team: "PAYROLL PROVIDER UPDATE: re-enroll your direct deposit by Monday or your pay is delayed." A new hire, two weeks in, asks you: "Is this real? I don't want my pay messed up."
The rule that matters
Never sign in through a link that arrived by text.
The page can be convincing. Your email can be prefilled. The sender can name your firm and your tools. The link is still the trap: credentials and MFA codes typed there are harvested and used within minutes, before the codes expire. The deadline is a warning sign, not proof.
Open the real app or portal yourself - never through a message link.
Report the text the same day. If credentials went in, minutes matter: reset and revoke sessions immediately. Phishing-resistant MFA (hardware keys) keeps a stolen password from being enough.
Red-flag sort - what actually proves safety?
Sort each card.
1 / 10
The control sequence - 5 lines
Complete each line of the rule.
1 / 5
Verification sprint - choose the trusted path
Pick the safest verification path.
1 / 6STREAK x0
Knowledge check - 5 questions
Module complete
0
Decisions-
Red-flag sort-
Control sequence-
Verification sprint-
Knowledge check-
AI Safety 101 by Mandrify - Official Certificate
AIS 101
This certifies that
has completed Module 21 - The Text: never sign in from a link on with a safety score of /100 in of active time.
Safety score - smishing resistance: how your decisions held up, graded 0-100.
Objective: Identify SMS phishing (smishing), refuse to sign in through message links, verify through self-opened apps and portals, contain credential leaks fast, and report attempts immediately.
Seat time ~15-18 minutes. Verify this certificate at aisafety101.com/verify.
Evidence on record: module completion, seat time, final score, and certificate ID. This certificate ID verifies in your firm's admin report.
The safe path is the one you open yourself. Never sign in from a message link; open the real app, and report the text the same day.