Interactive Walkthrough

See BaitShield in action

A realistic, six-step simulation of the full workflow covering campaign setup, phishing email delivery, real-time tracking, results dashboard, and AI security analysis. Everything runs locally in your browser. No sign-up, no real emails sent, nothing connects to a backend.

2-minute walkthrough 100% client-side No data collected
BaitShield Demo

Campaign Setup

Ready to Launch
Q2-2026 · LHDN Tax Penalty Notice
Q2-2026
Finance Department (25 employees)
LHDN Tax Penalty Notice
Fake LHDN Payment Portal
Immediate (send now)

Email Preview

16 May 2026, 9:00 AM
🚨 LHDN Notice: Tax Penalty of RM 15,500.00. Immediate Action Required

Dear Taxpayer,

Our records indicate that your company has an outstanding tax penalty of RM 15,500.00 due to late submission of Form CP204 for Year of Assessment 2025.

Failure to settle this amount within 7 working days will result in:

  • Additional 10% penalty surcharge
  • Legal proceedings under Section 103(3) of the Income Tax Act 1967
  • Travel restriction (Section 104)
Pay Penalty & View Notice

This is an automated notice from Lembaga Hasil Dalam Negeri (LHDN). Do not reply to this email.

This link is tracked by BaitShield. Click = recorded as "phished".

Sending Campaign

Live
Initializing...

Live Tracking

Monitoring
25
Sent
0
Opened
0
Clicked
0
Submitted Creds

Campaign Results

25
Emails Sent
18
Opened (72%)
7
Clicked (28%)
3
Submitted (12%)
Campaign Date 16 May 2026 · 9:00 AM
Total Employees 25 · Finance Department
Campaign Duration 9h 12m tracked

Department Breakdown

Accounts Payable
3/5 clicked
Treasury
2/7 clicked
Financial Planning
1/6 clicked
Audit & Compliance
1/7 clicked

AI Analysis

Campaign Analysis: Q1-2026 LHDN Tax Penalty Notice

Risk Assessment: HIGH

Your organisation's phish rate of 28% significantly exceeds the industry benchmark of 4.6%. Key findings:

  • Accounts Payable is the most vulnerable sub-department (60% click rate)
  • 3 employees submitted actual credentials, which would be a full account compromise in a real attack
  • The "urgency + government penalty" template was highly effective. Employees did not verify sender domain (Ihdn-gov-my.live vs lhdn.gov.my)
  • Audit & Compliance performed best (14%), likely due to prior training

Recommended Actions:

  1. Immediate: Mandatory security quiz for all 7 clickers
  2. This week: Finance-specific awareness training on invoice fraud
  3. Monthly: Re-test with different template (delivery/logistics next)
  4. Policy: Implement dual-approval for payments > RM 5,000

Awareness Training

Selecting topic...
Government Impersonation Phishing
Auto-selected by AI based on the LHDN Tax Penalty campaign. Teaches employees to spot fake government notices, verify domains, and resist urgency tactics.
5 questions ~4 minutes BM / EN Passing: 4/5
Q1 of 5

You receive an email from [email protected] claiming you owe RM 15,500 in tax penalty and must pay within 7 days. What is the safest action?

0
Recipients
All clickers + submitters
Schedule
Immediate dispatch
Reminder
+24h if not completed
Compliance
Logged for audit
See Pricing

Like what you see?

Join the BaitShield waitlist to be the first to deploy this in your organisation.