How It Really Happened

How It Really Happened: "Phish & Ships"

Phishing
Ninjio AWARE Season 11 Episode 8
July 31, 2026

Phish & Ships

Security Topic: Reporting Suspicious Emails

NINJIO Season 11: Episode 08

Data Dave’s (Jon Lovitz) vacation unravels when a phishing-driven breach drains his long-saved loyalty points, all because a cruise line employee deleted a suspicious email instead of reporting it. With the help of intern, Lorna, he traces the attack to the SparkleChasers hacking group and realizes the breach – and the stolen data – could have been prevented. The incident becomes his rallying cry: deleting suspicious emails hides the danger, but reporting them stops attacks before they spread.

Teachable Takeaways

  • Report suspicious emails before deleting them to increase protection for other people who could receive the same attack.
  • If you think you may have clicked a suspicious link, report it immediately. Fast reporting can limit the damage.
  • Knowing your company’s process for reporting suspicious emails is important and can help protect everyone.

Additional Reading

  1. They don’t care’: ShinyHunters strike again as hackers claim to have pinched 7.5 million Carnival cruise emails  – TechRadar
  2. Carnival confirms ShinyHunters cruised off with 6M customer records after April breach – The Register
  3. Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise – Microsoft
  4. Phishing and MFA exploitation: Targeting the keys to the kingdom – CISCO Talos
  5. Gmail fraud: A new cyber fraud email which bypasses Google’s security protocols; Know how it works and safeguard your money – The Economic Times
  6. What to do when you click on a suspicious link – CISCO Talos
  7. How do I report a suspicious email, Teams message, or file to Microsoft? – Microsoft
  8. Carnival Corporation Data Breach Exposes Millions of Passenger Records – Orion Policy Institute

About NINJIO

NINJIO reduces human-based cybersecurity risk through engaging training, personalized testing, and insightful reporting. Our multi-pronged approach to training focuses on the latest attack vectors to build employee knowledge and the behavioral science behind human engineering to sharpen users’ intuition. The proprietary NINJIO Risk Algorithm™ identifies users’ social engineering vulnerabilities based on NINJIO Phish3D phishing simulation data and informs content delivery to provide a personalized experience that changes individual behavior.

Ready to reduce your organization’s human risk?