Skip to content
Drevni Solutions
All case studies

Nonprofit organization

A phishing email arrived and nobody clicked

The problem

An employee at a nonprofit received an email claiming to be from a well-known external vendor, purportedly from a contact the organization had worked with years prior. The email included attachments. Something felt off, so she forwarded it to us before opening anything.

I have not opened these files yet, in case they contain a virus. Can you confirm, real or scam?
The client, in their own words

What we did

We responded within minutes. The sender’s email address did not match the legitimate domain of the company it claimed to be from. The contact it referenced had not worked there in years. We confirmed it was a phishing attempt and instructed the client to mark it as phishing without opening any attachments.

Her instinct to ask first was not luck. Security awareness training is part of what we deliver for this client: short, recurring lessons and simulated phishing emails that teach people to slow down when a familiar name arrives with an unexpected attachment. That is exactly the pattern she was looking at, and exactly what she did.

The outcome

Nothing was clicked. Nothing was executed. No credentials were stolen, no malware was installed. The threat was stopped before it started, because the person closest to it had been taught to recognize the pattern and had somewhere to turn the moment she did.

Why it matters

Phishing works because it only takes one click. Training your team to pause, and giving them someone to call who answers fast, stops more attacks than any tool working alone.

Let's make your IT quiet.

One conversation tells you where you stand and what to fix first. No pressure, no jargon.

Prefer to talk now? (415) 692-3380 · sales@…