Shiner OpsLEARN

KEEP THIS CLOSE

Something feel off?
Here’s your next step.

You don’t need to prove it’s phishing to ask for help.

Your company’s reporting channel

Sign in to see your company’s configured contact. If a contact has not been provided, use the established IT or supervisor contact in your company directory.

This training website is not an incident-reporting inbox. Do not submit passwords, MFA codes, work documents, or operational access codes here.

Download the one-page response guide ↓
1

Only clicked?

Stop interacting with the page. Report the message and tell IT what you opened, when, and on which device. Do not revisit the link to investigate.

2

Shared or approved?

Contact IT immediately if you entered information, shared a code, approved MFA, or granted app access. Secure the affected account through a known-safe route and follow IT’s instructions.

3

Installed or paid?

Contact IT and the responsible manager immediately. For a payment, involve your payment team and bank through known channels. Follow established containment procedures; do not alter operational or safety-critical systems yourself.

A useful first report

“At about 10:15, I opened a link in a message titled Revised Work Order on my work laptop. I entered my work password but did not approve an MFA prompt. I need help securing the account.”

Describe the type of information shared. Never include the actual password or code in the report.

Course references

This is an original Shiner Ops course informed by public guidance. It is not a Microsoft, CISA, or FBI certification.

Content reviewed October 2, 2026 · Edition 2026.1

Back to learning →