Training demo. This page is intentionally built to teach phishing and QR-code risk. It does not submit, upload, store, fetch, track, or save credentials.
For a real app, keep this same privacy boundary: lesson inputs only exist in memory until the report is shown, then clear them.
Lesson 1
Can you trust what you see?

Start typing a demo email. The page will stop itself and reveal why a familiar login screen is not proof of safety.

Waiting for the first interaction…
The heading can change because this page controls it.
The logo can change because a logo is only an element on the screen.
Input fields belong to whoever controls the page.
A malicious version could keep going instead of stopping.
Session Data Receipt
What could have happened?

You’re safe: nothing was sent, stored, uploaded, or reused. This report is generated only from in-memory demo state.

Fake page could have collected

  • Email text typed into the field
  • Password if the user entered one
  • Button taps and timing
  • Device/browser basics visible to the page

If an attacker signed in

  • Gmail, Drive, Photos, Contacts, Calendar
  • Password resets for other accounts
  • Impersonation through email
  • Recovery settings or connected apps

This demo actually did

  • Real Google login: 0
  • Real password collected: 0
  • Data sent to server: 0
  • Stored after close: 0

Core lesson

  • Branding can lie
  • Security wording can lie
  • The safe part is verification
Lesson 2
A QR code can look safer.

After the fake-login lesson, this second stage claims a QR code is a more secure way to access the website. The twist: a QR code is only safer if it points to a real, verified login flow.

Secure Google Sign-In
Scan to securely access our website with Google