How I Simulated a Phishing Campaign as a Security Analyst: Mastercard Forage Experience
Most people think phishing is obvious. “I’d never fall for that,” they say. Then they click the link anyway.
How I Simulated a Phishing Campaign as a Security Analyst: Mastercard Forage Experience

Most people think phishing is obvious. “I’d never fall for that,” they say. Then they click the link anyway.
I recently completed the Mastercard Cybersecurity Virtual Experience on Forage. Two tasks: design a phishing simulation, then figure out which departments needed security awareness training. Simple on paper. More interesting in practice.
Task 1: Designing a Phishing Email
The task started with a sample phishing email that was, frankly, embarrassing. Sender address was @gmail.com instead of @mastercard.com. The name was spelled “mastercards” with an extra s. Grammar was a mess.
The job was to make it actually convincing.
This matters more than it sounds. You can’t train employees to spot phishing if your simulations are obvious garbage. Real attackers spend time on this. The simulation has to match.
Here’s what I changed:
The sender domain. The original used Gmail, which is an instant giveaway. A realistic simulation uses a lookalike domain like mastercard-support.com or security-mastercard.com. Something that passes a two-second glance.
The body. The original read like it was written in a hurry by someone who doesn’t speak English as a first language. Mastercard is a massive company with a comms team. Their IT emails don’t look like that. I rewrote it to sound like a routine IT request: calm, professional, nothing that would raise flags.
Here’s what I drafted:
Hello (Employee Name),
As part of our commitment to keeping your account secure, we’re requesting that you update the password for your corporate email account.
This is a routine security measure to help protect your account and company resources. Please take a moment to reset your password using the secure Password Portal below.
CTA: {{Update Password}}
If you have recently updated your password or believe this notification was sent in error, please contact the IT Service Desk immediately.
Regards,
Mastercard IT Support
What makes this work: mild urgency without panic, a plausible reason, and an opt-out clause (“if you already did this, ignore it”) that makes it feel more legitimate, not less. That opt-out is a real technique. It reduces suspicion.
Task 2: Who Actually Needs Training
Simulating the attack is step one. Step two is using the data.
The numbers showed HR clicking at 75% and Marketing at 38%. Both are bad, but for different reasons.
HR deals with onboarding links, payroll portals, benefits portals, and document requests constantly. A phishing email asking them to “verify employee information” fits right into their normal day. They’re a high-value target at basically every organization, not just here.
Marketing is different. Their job involves external vendors, campaign tracking links, and click-through rates. Clicking links is literally what they do. That habit becomes a vulnerability.
The training for each has to be different.
For HR: scenario-based sessions that mirror what they actually receive. Fake payroll update requests, fake DocuSign links, fake onboarding verifications. Recognition has to happen in context. Abstract “be careful with emails” posters don’t move the needle.
For Marketing: link hygiene. Hover before clicking, check the actual destination URL, be skeptical of anything that doesn’t route through a known platform. Short and practical.
And then you rerun the simulation after training and check whether the numbers dropped. If HR is still at 60%, the training failed, not the people.
Why This Sticks With Me
Security awareness programs are one of those things that sound soft but have real dollar amounts attached to them. A single successful phishing attack on an HR employee can mean credential access to payroll systems, employee PII, benefit accounts. The cost of a training program is nothing compared to that.
What this exercise made clear is that phishing works because it looks routine. The email I designed doesn’t look dangerous. That’s the point. Teaching people to pause even for two seconds before clicking is harder than it sounds, and it’s a real skill.
If you’re trying to break into cybersecurity, this Forage program is worth an afternoon. It’s free. The tasks are practical. And building a phishing simulation from scratch is a better interview talking point than most people expect.
메타데이터
- post_id
- 07dc7bf3c94d
- slug
- how-i-simulated-a-phishing-campaign-as-a-security-analyst-mastercard-forage-experience-07dc7bf3c94d
- url
- https://medium.com/@partha2005mr/how-i-simulated-a-phishing-campaign-as-a-security-analyst-mastercard-forage-experience-07dc7bf3c94d
- canonical_url
- https://medium.com/@partha2005mr/how-i-simulated-a-phishing-campaign-as-a-security-analyst-mastercard-forage-experience-07dc7bf3c94d
- author_url
- https://medium.com/@partha2005mr
- status
- ok
- fetched_at
- 2026-07-09 16:18:44