Congrats — you're one of today's lucky visitors. Accept cookies below to continue and claim your reward.
By continuing, you agree to our totally real and definitely normal cookie policy.*
But in the time it took you to read "You've won a free coffee," this page already learned the following about you — just from the click.
⏱ time on this page: 0.0s
And a "verify your location for pickup" prompt gets your exact GPS coordinates, not just your general area.
One more: sites also ask for a blanket "accept" on cookies/permissions — which quietly unlocks a deeper fingerprint than anything above.
A few hours later, "IT Security" emails you — personalized with exactly the details this page collected. This is a simulation: nothing was sent, and it isn't styled after any real company.
We detected a sign-in from a device we don't recognize. If this was you, no action is needed — but if you don't recognize this activity, please secure your account immediately.
For your protection, we recommend resetting your password now.
Reset my passwordLink destination: passwordreset.notphishing.lol/verify — not your real account provider's domain.
"Immediately" and a flagged sign-in create pressure to act before thinking.
Your actual device, OS, and location make it feel targeted and credible — all from data volunteered a few minutes ago.
Generic "Account Security" / shield branding borrows the visual language of legitimate IT systems without naming one.
The button text says "reset my password," but the real destination is a domain designed to be skimmed past, not read.