COOKIE NOTICE

You've won a free coffee ☕

Congrats — you're one of today's lucky visitors. Accept cookies below to continue and claim your reward.

By continuing, you agree to our totally real and definitely normal cookie policy.*

There's no coffee. 🙃

But in the time it took you to read "You've won a free coffee," this page already learned the following about you — just from the click.

⏱ time on this page: 0.0s

LIVE DATA COLLECTED0 items

What a real scam page could get if you gave it more permission:

And a "verify your location for pickup" prompt gets your exact GPS coordinates, not just your general area.

One more: sites also ask for a blanket "accept" on cookies/permissions — which quietly unlocks a deeper fingerprint than anything above.

How to actually protect yourself

  • Check the domain before you click — this page lives at a domain built to look suspicious on purpose.
  • Unexpected prizes, QR codes on flyers/parking meters, and "urgent" links are the classic bait.
  • Device and browser info leaks to any site you visit — that part isn't avoidable, just don't hand over more (email, location, passwords) to sites you don't trust.
  • When in doubt, type the company's real URL yourself instead of tapping a link or QR code.

Here's the follow-up.

A few hours later, "IT Security" emails you — personalized with exactly the details this page collected. This is a simulation: nothing was sent, and it isn't styled after any real company.

The manipulation tactics at work here

URGENCY

"Immediately" and a flagged sign-in create pressure to act before thinking.

PERSONALIZATION

Your actual device, OS, and location make it feel targeted and credible — all from data volunteered a few minutes ago.

AUTHORITY

Generic "Account Security" / shield branding borrows the visual language of legitimate IT systems without naming one.

LOOKALIKE LINK

The button text says "reset my password," but the real destination is a domain designed to be skimmed past, not read.