@actualham every ”security training “ is like “do exactly what you should never do”
Where I work the the url in the emails seem to have numeric values for that particular phishing email as well as the targeted user.
I’m tempted to write some code that loops through all possible values and do a http GET.