Phishing Quiz 2026: 15 Real Questions to Test Your Team
Author :
Deepak Saini
Aug 11, 2026
The 2026 Phishing Quiz: 15 Real-World Questions That Reveal How Prepared You Really Are
Here's an uncomfortable number to start with: across more than 22,000 confirmed breaches analyzed in Verizon's 2026 Data Breach Investigations Report, a human action — a click, a callback, a moment of trust — was involved in 62% of them. Phishing alone accounted for 16% of initial access, and when you widen the lens to voice calls, texts, and social platforms, attackers reached people outside the inbox nearly as often as inside it.
Meanwhile, the FBI's Internet Crime Complaint Center logged $3.05 billion in confirmed losses from business email compromise in 2025 alone, from fewer than 25,000 reported cases. That's not spam. That's targeted, patient, well-written fraud aimed at a single employee on a single afternoon.
So here's the question this quiz is really asking: if one of these messages landed in your inbox, texts, or voicemail this week, would you catch it? Not eventually — in the ten seconds before you'd normally click.
Fifteen questions. Real scenarios. No trick answers — just the same judgment calls attackers are betting you'll get wrong.
Why a Phishing Quiz Still Matters When AI Writes the Scams
For years, the advice was simple: look for typos and bad grammar. That advice is now actively dangerous. Generative AI has closed the quality gap between a scam email and a legitimate one — the 2026 DBIR's collaboration with Anthropic on threat-actor data found phishing involved in 44% of AI-assisted intrusions, raising the floor for unskilled attackers rather than inventing new tricks.
The channel has widened too. The 2026 DBIR measured voice and SMS phishing at scale for the first time and found phone-based lures produced roughly 40% more successful clicks than email. Your spam filter doesn't cover your phone — and attackers have noticed.
How to use this quiz: read each scenario the way you'd actually meet it — fast, mid-workday, slightly distracted. Pick an answer before scrolling to the explanation, which tells you not just what's right but why. Tally your score at the end.
The Quiz: 15 Questions
Question 1: The "Urgent" Invoice
An email from your CFO's exact address arrives at 4:52 PM Friday: "Need this vendor invoice paid before close of business — can't talk, on a flight. Wire details attached." What's the single biggest red flag?
A) It arrived on a Friday
B) There's an attachment
C) Urgency combined with unavailability for verification
D) The word "wire" was used
Answer: C. The tell is time pressure paired with an excuse not to confirm another way — a combination that exists to stop you calling. Legitimate urgent requests survive a 30-second callback. Fraudulent ones don't.
Question 2: The Login Page That Isn't
You click a link to "verify your Microsoft 365 password" and land on a page that looks pixel-perfect — right logo, right layout, right colors. What should you check before typing anything?
A) Whether the page loads fast
B) The full domain in the address bar, read right to left from the first single slash
C) Whether there's a padlock icon
D) The page's spelling and grammar
Answer: B. A padlock only means the connection is encrypted — attackers get free HTTPS certificates too, and visual polish is trivial to clone. The domain is what's hard to fake: microsoft-login-secure.com is not Microsoft. Read it right before the first single "/" — that's the real host.
Question 3: The Text From "Your Delivery Service"
A text reads: "Your package could not be delivered. Update your address here: [link]. Reply STOP to opt out." You weren't expecting a package. What is this?
A) A legitimate courier notification
B) Smishing — SMS-based phishing designed to harvest payment or personal details
C) A wrong-number text you can ignore
D) Spam that's harmless if you don't click
Answer: B. Textbook smishing — the "reply STOP" line borrows real spam-compliance language to feel routine. Delete without clicking, and check delivery status only by typing the courier's known URL yourself.
Question 4: The Voice on the Phone
A call that sounds exactly like your IT director — voice, tone, even a verbal habit you recognize — asks you to read back a one-time passcode "to fix a login issue." What's happening?
A) It's definitely your IT director — voices can't be faked that well
B) Possibly a voice-cloning (vishing) attack; a real one-time passcode request should never happen over a phone call
C) It's fine as long as they knew your employee ID
D) You should read the code only if they sound stressed, since that proves urgency is real
Answer: B. Voice cloning from a few seconds of public audio is now cheap and fast. The rule that beats "trust your ears": no legitimate IT process asks you to read a passcode out loud. That survives even a perfect clone.
Question 5: The QR Code on the Parking Meter
A sticker over the parking meter's real QR code says "Scan to pay — new contactless system." You scan it and land on a payment page asking for your full card number and CVV. Safe?
A) Yes, QR codes can't carry malicious links
B) No — this is "quishing," and a sticker over the original code is the giveaway
C) Only unsafe if it asks for a password too
D) Safe if the payment page has a lock icon
Answer: B. QR codes are just links in a different wrapper. "Quishing" — swapping legitimate codes for malicious ones on meters, tables, and posters — is common enough that a sticker over an existing code is now a teachable red flag. Pay through the venue's official app instead.
Question 6: Phishing vs. Spear Phishing
What actually separates "spear phishing" from ordinary phishing?
A) Spear phishing only happens over email
B) Spear phishing is personalized to a specific target using researched details, while regular phishing is mass-blasted and generic
C) Spear phishing is illegal and regular phishing isn't
D) There's no real difference
Answer: B. Ordinary phishing casts a wide net with generic bait sent to millions. Spear phishing is researched: it might use your manager's real name, reference an actual project, or mimic your company's signature format — and it converts far better because it doesn't feel like a template.
Question 7: The Hover Test
Before clicking a link in an email that claims to be from your bank, what's the fastest useful check on desktop?
A) Right-click and scan for viruses
B) Hover over the link (without clicking) to preview the actual destination URL in your browser or email client
C) Forward it to a friend to check
D) Check if the email has a signature block
Answer: B. Hovering reveals the real destination before you commit — most email clients show it in a status bar or tooltip. A link displaying "yourbank.com" that points to a completely different domain is one of the most reliable, zero-cost checks available, and it takes under two seconds.
Question 8: The Invoice Attachment
An unfamiliar vendor emails a .zip attachment, "Invoice_July_Overdue.zip," and asks you to open it "urgently to avoid late fees." Safest move?
A) Open it since it's just an invoice
B) Scan it with antivirus, then open it
C) Don't open it — verify the vendor relationship independently first, since compressed executable-style attachments are a classic malware delivery method
D) Reply asking them to resend as a PDF
Answer: C. Compressed files smuggle malicious executables past basic email filtering, and "urgent unpaid invoice" is one of the oldest hooks in the book because it works. If you don't recognize the vendor, verify through a known contact before opening anything — don't trust antivirus alone to clear you.
Question 9: MFA Fatigue
You get 14 unrequested MFA push notifications in ten minutes. You approve none — but the 15th arrives with a text from an unknown number: "IT here, please approve, we're mid-fix." What should you do?
A) Approve it since IT confirmed it by text
B) Deny every request, then report the incident and change your password through official channels
C) Ignore it — it will stop eventually
D) Approve just one to make it stop
Answer: B. This is push-bombing: attackers already have your password and spam approvals hoping exhaustion gets one through. The "IT" text is part of the same attack, not confirmation — real IT verification happens through a channel you initiate. Deny everything and report immediately.
Question 10: Spotting AI-Written Phishing
Which of these is now the least reliable signal that an email is a phishing attempt?
A) A mismatched sender domain
B) A request for credentials or payment details
C) Poor grammar and spelling
D) Urgency and pressure to bypass normal process
Answer: C. Grammar used to be a reasonably reliable tell. It no longer is — AI writing tools have made polished, typo-free phishing emails trivial to produce. Domain mismatches, credential requests, and manufactured urgency remain far more durable signals than writing quality.
Question 11: The Recruiter Who Isn't
A LinkedIn "recruiter" offers a lucrative remote role, quickly moves the chat to WhatsApp, then asks you to install an "assessment tool" to complete a coding test. Red flag?
A) No — many legitimate interviews use take-home assessments
B) Yes — moving off-platform fast and requiring software installation before any formal interview is a known impersonation and malware-delivery pattern
C) Only if they ask for money
D) Only if the job title seems too senior for you
Answer: B. Legitimate recruiting rarely rushes candidates off a verified platform in the first message, and asking someone to install unknown software before any real screening is a pattern strongly associated with credential-stealing and malware campaigns targeting job seekers. Verify the recruiter and company independently before installing anything.
Question 12: Social Engineering, Broadly Defined
Which of the following counts as "social engineering"?
A) Only email-based scams
B) Only phone-based scams
C) Any manipulation tactic — email, text, call, in-person, or social media — that tricks a person into an action or disclosure, regardless of channel
D) Only attacks that use fear
Answer: C. Social engineering is the umbrella category; phishing, smishing, vishing, and quishing are channel-specific tactics under it. Roughly 4 in 10 social-engineering-related breaches in 2026 involved a channel other than email — "watch your inbox" is necessary but no longer sufficient advice.
Question 13: You Already Clicked
You clicked a phishing link and entered your work password before realizing something was off. What's your first move?
A) Wait to see if anything bad happens before doing anything
B) Change the password immediately and report it to your security team — don't wait for confirmation of harm
C) Just run an antivirus scan and move on
D) Only report it if you also entered financial information
Answer: B. Speed beats certainty here. Change the compromised password immediately — including anywhere else you reused it — re-verify MFA, and report the incident right away so your security team can check for follow-on activity like new mail rules or unusual logins. Waiting to "see if anything happens" gives an attacker a head start they don't need.
Question 14: Reporting vs. Deleting
True or false: quietly deleting a phishing email you spotted is just as good as reporting it.
A) True — if you didn't click, there's nothing to report
B) False — reporting lets security teams block the sender organization-wide and warn colleagues who may have received the same lure
Answer: B — False. Deleting a lure protects one person. Reporting it protects everyone else who got the same email and feeds the pattern data that makes future detection faster. The single highest-leverage habit in any phishing program isn't "don't click" — it's "report what you catch."
Question 15: The Trivia Question
What share of confirmed data breaches in the 2026 Verizon DBIR involved a human element — a click, a call, a mistake — somewhere in the chain?
A) Around 20%
B) Around 40%
C) Around 62%
D) Nearly 100%
Answer: C. 62%, ticking up slightly year over year even as technical controls improve — the core argument for continuous, realistic phishing testing rather than a once-a-year video. The weak point isn't the firewall; it's the ten seconds before someone decides whether to click.
How Did You Score?
0–5 correct — Time for a foundational refresh. Not a judgment — it's exactly the population attackers target first, because urgency, spoofed authority, and off-channel pressure are engineered to bypass instinct. Start with the checklist below and revisit this quiz in a month.
6–10 correct — Solid instincts, some gaps. You're catching the obvious ones but likely caught out by channel-shifting attacks — vishing, smishing, quishing — since most training still focuses on email alone. Revisit Questions 4, 5, and 9.
11–15 correct — Genuinely well-prepared. You're ahead of the median simulated phishing click rate, which industry testing puts at roughly 1–2% for email and meaningfully higher for phone-based lures. The next step isn't more quizzing — it's making sure your reporting habits (Question 14) are as sharp as your detection habits.
The Phishing Landscape in 2026: A Quick Field Guide
Phishing — fraudulent email designed to steal credentials, install malware, or extract payment.
Spear phishing — phishing personalized to one individual with researched, credible details.
Whaling — spear phishing aimed at executives or other high-value targets.
BEC — impersonating an executive, vendor, or partner to redirect a payment, often with no malware or link involved.
Smishing / Vishing / Quishing — the same tactic delivered by text, phone call, or malicious QR code.
MFA fatigue — spamming login approval requests until one is accidentally accepted.
AI-generated phishing — lures written with generative AI, removing the grammar errors people were trained to spot.
10 Red Flags Checklist
Urgency paired with an excuse not to verify by another channel
A sender domain that's close to, but not exactly, the real one
A request for credentials, one-time codes, or payment details
Unexpected attachments, especially compressed files
A shift from a verified platform (email, company chat) to an unverified one (personal text, WhatsApp)
Requests to install unfamiliar software before any formal process has occurred
A QR code that looks physically added or stickered over an original
Repeated, unprompted MFA push notifications
Emotional pressure — fear, opportunity, authority, or curiosity used to short-circuit judgment
Sudden formality or unusual phrasing from a contact who doesn't normally write that way
What to Do If You Clicked (or Think You Did)
Disconnect if malware is possible — pull the device off Wi-Fi before doing anything else.
Change the password immediately, on that account and anywhere else you reused it.
Re-verify or re-enable MFA rather than assuming it's still secure.
Report it to security or IT now, not after confirming damage.
Watch for follow-on activity — new mail rules, unfamiliar login alerts, unrequested password resets.
If money moved, contact your bank immediately and file with the FBI's IC3 (ic3.gov) — speed materially affects recovery odds.
Frequently Asked Questions
Is a phishing quiz actually useful, or a checkbox exercise? It works because it forces a decision under mild time pressure — the same condition attackers exploit. Passive training doesn't build that reflex the way an active quiz does.
How often should teams take a phishing quiz or simulation? Most practitioners recommend ongoing exposure — brief quizzes or simulated tests monthly or quarterly — rather than one annual session, since tactics shift faster than yearly cycles.
Can I get phished even if I don't enter any information? Yes. Opening an attachment or visiting a compromised page can trigger malware or confirm your email is active, increasing future targeting without you typing anything.
Is AI making phishing detection harder for humans? Yes, mainly by eliminating the grammar errors people were trained to spot. The durable signals now are behavioral — urgency, channel-shifting, verification bypass — not surface polish.
What's the real difference between phishing and ordinary spam? Spam is unsolicited and usually commercial; phishing specifically tries to deceive you into an action that benefits the attacker.
Does multi-factor authentication make phishing irrelevant? No. Push-bombing, real-time phishing proxies, and BEC attacks that never touch a login page can all bypass it. MFA reduces risk; it doesn't eliminate it.
The Real Test Isn't This Quiz
Fifteen questions in a calm setting, with time to think, is the easy version. The real version arrives mid-afternoon, from a name you recognize, asking for something that feels almost reasonable. The gap between those two versions is exactly what continuous, realistic phishing simulation is built to close.
ClearPhish runs that harder version — realistic, current, channel-spanning simulations plus the reporting workflows that turn one caught lure into protection for an entire team. If this quiz caught you off guard even once, that's not a personal failing. It's a sign the training needs to match what attackers are sending in 2026, not what they were sending five years ago.






