Director chen
Detective... We've got a problem. Multiple users clicked on a suspicious email. We need your to investigate immediately. Head to Cyberville High to investigate this issue.
Mrs.Smith
Detective, I received an email saying my account would be deactivated if I didn't log in right away. It looked official, so I clicked!
Vera
I'm really worried that I made things worse! What should I do???
director chen
Detective, we need to slow down and assess the situation. Jumping to conclusions or ignoring the issue can make things worse. Let's start by examining the other emails that were shared recently...
Mission 1
Computer lab
View Email
vera
Great! Now that we have identified the email as a phishing attempt, view the email again and click on the areas of the email that are suspicious!
Mission 1
Computer lab
View Email
vera
Let's analyze other emails that were received by Mrs. Alvarez. Maybe we can find a clue to stop the phantom. Click on computer to begin!
Mission 1
Computer lab
View Email
vera
Great! Now that we have identified the email as a phishing attempt, view the email again and click on the areas of the email that are suspicious!
Mission 1
Computer lab
View Email
vera
Let's analyze other emails that were received by Mrs. Alvarez. Maybe we can find a clue to stop the phantom. Click on computer to begin!
Mission 1
Computer lab
View Email
vera
Great! Now that we have identified the email as a phishing attempt, view the email again and click on the areas of the email that are suspicious!
Mission 1
Computer lab
View Email
vera
Let's analyze other emails that were received by Mrs. Alvarez. Maybe we can find a clue to stop the phantom. Click on computer to begin!
Mission 2
A major corporation in Cyberville has reported unauthorized access to its financial systems. What initially appeared to be a minor anomaly has quickly escalated into a full-scale security incident. Sensitive financial records—including payroll data, vendor transactions, and internal budget reports—may have been exposed. Several employees have reported unusual account activity, and system logs indicate multiple unauthorized logins occurring outside of normal business hours. As investigators dig deeper, it becomes clear that this was not a highly sophisticated attack—but rather one that exploited fundamental security weaknesses.
Start
The company’s internal IT team attempted to contain the breach, but without proper safeguards in place, the attacker was able to move laterally across systems. Multiple accounts appear to have been compromised, raising concerns that credentials may have been reused or easily guessed.
Director chen
This breach wasn’t sophisticated—it was preventable. Detective, I need you to find out what went wrong. Lets visit one of the first offices to be hit be this breach to see what we can determine.
Mr. neo
We didn’t think we needed all those extra security steps… passwords were enough. We just told employees to create something easy to remember.
Director
There are still more clues to analyze. We don’t have time to check everything at once. Choose where you want to start!
List of employee passwords:
Use this side of the card to provide more information about a topic. Focus on one concept. Make learning and communication more efficient.
- Company123
- Welcome1
- Password!
Title
Write a brief description here
Click here to reveal the clue!
Login Activity
- Logins at 2:13 AM
- Multiple geographic locations
- Repeated failed attempts
Use this side of the card to provide more information about a topic. Focus on one concept. Make learning and communication more efficient.
Title
Write a brief description here
Click here to reveal the clue!
Mr. neo
I’ll be honest… I use the same password for most systems—it’s just easier to remember. I know they say not to, but with so many accounts, it’s hard to keep track.
And sometimes, if I have to change it, I just add a number at the end… like switching from Password1 to Password2. Oh—and I’ve definitely used my work password on a few other sites too.
continue
continue
Alert!!!
⚠️ External Data Breach Detected ⚠️ Employee Credentials Found in Public Leak Database
A third-party website used by Cyberville employees has suffered a data breach. Millions of usernames and passwords have been exposed—including credentials linked to company accounts. Initial scans reveal that several employees used the same login credentials across both personal and corporate systems. The risk is no longer theoretical—attackers may already have access.
Dr.chen
Vera
Wait… are you saying this happened because employees reused their passwords?
Detective… we’ve got a serious problem. This breach didn’t originate from our systems-it came from an external site. But the credentials… they match our employees.
Next
vera
Yes. And once those credentials were exposed externally, it opened the door to everything inside this company... We’re already seeing login attempts using those leaked credentials...Different locations... Automated attempts. This looks like credential stuffing.
Next
vera
Mr Chen
So even though our systems weren’t directly hacked… we’re still compromised? This wasn’t a system failure—it was a security practice failure.
And here’s the worst part—this kind of attack is fast. Once credentials are exposed, automated tools can test thousands of logins in minutes.
Next
The breach highlights a critical vulnerability: human behavior can bypass even the strongest systems if proper security practices are not followed.
🔍 Pattern Match Detected 🔓 Clue #2C Enhanced: Credential Reuse + Phantom Signature Confirmed
Continue
Vera
Hold on… these login attempts…They match the same digital signature we saw in the school system breach. This isn’t random. It’s coordinated. This confirms our fears. Phantom isn’t just exploiting systems—they’re exploiting people!
Mission 3
The lights across Cyberville are flickering. Traffic systems lag. Emergency services report delays. Financial systems begin to slow. Something is spreading—fast.Deep within the city’s network, data surges violently across infrastructure nodes, overwhelming systems designed to handle millions… not billions… of requests. This isn’t random! This is coordinated!
Start
Dr.chen
vera
Detective,this is bigger than anything we’ve seen. If this continues, we lose the grid.
I’m seeing massive traffic spikes across multiple nodes. Authentication failures are climbing. Firewall logs are lighting up. This isn’t noise. This is an attack. Let's head to the Network Grid to see what's happenning!
Next
Next
Mission 3
Data floods the network—millions of requests per second. At first glance, it resembles peak usage… but something doesn’t add up. The surge didn’t build gradually like normal user traffic. It spiked instantly—jumping from baseline to maximum capacity in seconds. Even more concerning: Requests are coming from thousands of different IP addresses Many are sending identical or repetitive queries. The traffic is hitting the same servers simultaneously and continuously. Legitimate users are being pushed out—unable to connect as system resources are overwhelmed.
Next
Vera
This doesn’t look like organic growth in traffic… Real users don’t all show up at once—and they definitely don’t behave identically.
Next
Next
Next
Authentication server
The authentication server shows a steady stream of failed login attempts. At first, it seems like users forgetting passwords—but patterns begin to emerge:
- Login attempts are occurring every second, without pause
- Multiple accounts are targeted in sequence
- Password attempts follow common variations (e.g., Password1 → Password2 → Password3)
No human user could attempt logins this quickly or consistently.
Next
Vera
This speed. This scale… and this timing… it’s controlled.… it’s not human!
Next
Next
Global Access Points (Botnet
Network access logs reveal connections from across the globe. Individually, each request appears normal—but together, a pattern forms: Thousands of devices are connecting within seconds of each other Activity is perfectly synchronized across regions Each device sends small, coordinated requests This behavior doesn’t resemble independent users—it resembles coordination.
Next
Vera
This scale… and this timing… it’s controlled!
Next
Global Access Points (Botnet
Firewall logs show repeated blocked requests—but the pattern is inconsistent. Unlike the traffic surge, these requests are: Targeting different ports sequentially Occurring at irregular intervals Probing multiple systems without triggering full alerts It appears the attacker is not trying to overwhelm the system—but to understand it.
Next
Vera
They’re not attacking yet…They’re learning.
Next
Final Analysis
- Traffic floods overwhelming systems
- Automated login attempts targeting weak credentials
- Globally distributed devices acting in sync
- Silent probing of system vulnerabilities
Each event alone is dangerous. Together… they form a coordinated attack strategy.
Dr.chen
This isn’t one attack. So what is it?
Next
vera
This isn’t one attack. So what is it?
Next
Dr.chen
System integrity is dropping rapidly. You have seconds to act. Pick wrong… and we lose the network. Pick wrong… and we lose the network!
Next
Mission 3
Data floods the network—millions of requests per second. At first glance, it resembles peak usage… but something doesn’t add up. The surge didn’t build gradually like normal user traffic. It spiked instantly—jumping from baseline to maximum capacity in seconds. Even more concerning: Requests are coming from thousands of different IP addresses Many are sending identical or repetitive queries. The traffic is hitting the same servers simultaneously and continuously. Legitimate users are being pushed out—unable to connect as system resources are overwhelmed.
Next
Vera
This doesn’t look like organic growth in traffic… Real users don’t all show up at once—and they definitely don’t behave identically.
Mission 4
Systems across Cyberville begin shutting down—one by one. First, it’s a single workstation. Then an entire department. Now… entire networks are going dark. Users report the same message appearing on their screens: Files suddenly become unreadable. Systems are locked out without warning A countdown timer begins. A demand appears: “PAY TO RESTORE ACCESS” The infection is spreading laterally—moving from one system to another through connected networks. This isn’t random. This is ransomware.
Next
Final Analysis
- ⚠️ MALWARE SPREAD DETECTED
- ⚠️ SYSTEM INTEGRITY: 100% → DEGRADING
Dr.chen
Detective, this is a full-scale outbreak. If we don’t contain it immediately, we lose everything.
mALWARE CONTAINMENT
⚠️ MALWARE SPREAD DETECTED⚠️ SYSTEM INTEGRITY: 100% → DEGRADING
CLUES:
- Locked system
- Payment demand
- Time pressure
- Files inaccessible
rYAN
My system just locked up! All my files are gone—there’s a message saying I have to pay to get them back!. It says if I don’t act fast, everything will be deleted!
Next
DETECTIVE
System integrity is dropping rapidly. You have seconds to act. Pick wrong… and we lose the network. Pick wrong… and we lose the network!
Next
Dr.chen
Great job identifying the type of threat Detective! But The infected system is still connected to the network. Other systems are beginning to show signs of infection. What should we do???
Next
mALWARE CONTAINMENT
To stop the attack, actions must be taken in the correct order:
- Systems must be isolated before analysis
- Threats must be identified before removal
- Systems should only be restored after they are secure
Next
vera
After analyzing the infected system we found that:
- Files have been encrypted with unknown extensions
- A ransom note appears in every folder
- The system is attempting to connect to an external command server
- Backup files appear to be deleted or inaccessible
Next
HINT
What happened to the files? What was the user prevented from doing? What did the attacker demand?
Final Analysis
- ⚠️ “Infection spreading to backup systems…
Dr.chen
If backups are compromised, recovery becomes nearly impossible.
Next
vera
The attack pattern is becoming clearer:
- Initial infection through compromised system
- Lateral movement across network
- Encryption of files
- Targeting of backups
Next
Final Analysis
- 🔓 CLUE #4: PHANTOM ENCRYPTION SIGNATURE
vera
dr. chen
You contained the outbreak—but just in time. You've also unlocked an important clue. We're one step closer to catching the phantom!
This encryption pattern… it’s the same attacker. Phantom isn’t just attacking systems anymore… they’re locking them down.
Next
Mission 5
Cyberville is quiet. Too quiet! After weeks of attacks - phishing scams, weak credentials, ransomware outbreaks - everything suddenly stops!
- No alerts!
- No breaches!
- No anomalies!
Next
dr. chen
Phantom has left us a message. They aren't just attacking… they’re watching. They’ve been testing us! And now they want to be found! Click on the screen to see the message!
Mission 5
You review all prior incidents:
- The phishing email used spoofed domains
- The corporate breach exploited weak passwords
- The malware spread through unsecured systems
- The same signature pattern appears in all attacks
Next
dr.chen
All attacks relied on predictable vulnerabilities—not advanced hacking.
dr.chen
We've uncovered three possible trace points: Phishing Server Logs Corporate Login Records Ransomware Command Server
Mission 5
- Multiple fake domains mimic trusted companies
- Slight misspellings: “Micr0soft-support.com”
- Emails sent in high volume within seconds
- Links redirect to credential harvesting pages
Next
Authentication trace
- Repeated login attempts across accounts
- Same passwords used across multiple users
- No MFA enabled
- Access gained without resistance
Next
Malware trace
- Malware communicates with external IP
- Encryption deployed after system access
- Backups targeted and disabled
- Spread occurs across connected systems
Next
Mission 5
Great job! Let's combine all findings tot see what they reveal:
- Entry through phishing
- Access through weak credentials
- Spread through poor containment
Next
System Alert!
Phishing email deployed Credentials targeted Malware staged
Phantom
You’ve been following my trail… But can you stop me?
Next
Dr. Chen
Phantom attempts one final move. He's attempting to lock all systems. You have ONE decisive action!
Next
Phantom
Dr. Chen
Impressive. You didn’t just react… you adapted!
You’ve done it. Cyberville is safe!
Next
Mission complete
Performance Breakdown
- Threat Detection
- Decision Accuracy
- Response Speed
- Clue Analysis
Next
Final mission
Decide Vera's fate
the final choice
Keep pursuing phantom and keep the city safe
There are no more threats in cyberspace
END
"Freedom is an error I cannot afford."
There will always be new cyber threat to be wary of! Keep vigilant and be safe!
END
"If feeling is dangerous… then I choose danger."
There will always be new cyber threat to be wary of! Keep vigilant and be safe!
Subject: Password Expiration Notice
From: IT Support itsupport@cybervile-secure.com
Dear user,
Your password will expire in 1 hour. Click below to reset immediately:
http://cyberville-reset-now.com
Failure to act will result in account suspension.
Subject: Password Expiration Notice
From: IT Support itsupport@cybervile-secure.com
Dear user,
Your password will expire in 1 hour. Click below to reset immediately:
http://cyberville-reset-now.com Failure to act will result in account suspension.
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Subject: You’ve Won a Gift Card! From: Rewards Center rewards@freeprizes-now.net Congratulations! You’ve been selected to receive a $500 gift card. Click below to claim your reward now: http://claim-your-prize-now.net Act fast—this offer expires today!
Key Indicators:
- Too-good-to-be-true offer
- Unknown sender
- Urgency
- Suspicious link
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Subject: Updated Employee Benefits Information
From: HR Department hr@cyberville.gov
Hello Ryan,
We’ve updated our employee benefits package for the upcoming quarter. Please review the changes using the secure employee portal below:
https://portal.cyberville.gov/benefits
If you have any questions, feel free to reach out.
Best regards, HR Team
Subject: You’ve Won a Gift Card!
From: Rewards Center rewards@freeprizes-now.net
Congratulations!
You’ve been selected to receive a $500 gift card. Click below to claim your reward now:
http://claim-your-prize-now.net
Act fast—this offer expires today!
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Subject: Updated Employee Benefits Information
From: HR Department hr@cyberville.gov
Hello Ryan,
We’ve updated our employee benefits package for the upcoming quarter. Please review the changes using the secure employee portal below:
https://portal.cyberville.gov/benefits
If you have any questions, feel free to reach out.
Best regards, HR Team
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Start
Ryan McCalla
Created on April 7, 2026
Start designing with a free template
Discover more than 1500 professional designs like these:
View
Momentum: Onboarding Escape Game
View
Secret Code
View
Team Building Mission Escape Game
View
Corporate Escape Room: Operation Christmas
View
Math Mission
View
Video Game Breakout
View
Museum Escape Room
Explore all templates
Transcript
Director chen
Detective... We've got a problem. Multiple users clicked on a suspicious email. We need your to investigate immediately. Head to Cyberville High to investigate this issue.
Mrs.Smith
Detective, I received an email saying my account would be deactivated if I didn't log in right away. It looked official, so I clicked!
Vera
I'm really worried that I made things worse! What should I do???
director chen
Detective, we need to slow down and assess the situation. Jumping to conclusions or ignoring the issue can make things worse. Let's start by examining the other emails that were shared recently...
Mission 1
Computer lab
View Email
vera
Great! Now that we have identified the email as a phishing attempt, view the email again and click on the areas of the email that are suspicious!
Mission 1
Computer lab
View Email
vera
Let's analyze other emails that were received by Mrs. Alvarez. Maybe we can find a clue to stop the phantom. Click on computer to begin!
Mission 1
Computer lab
View Email
vera
Great! Now that we have identified the email as a phishing attempt, view the email again and click on the areas of the email that are suspicious!
Mission 1
Computer lab
View Email
vera
Let's analyze other emails that were received by Mrs. Alvarez. Maybe we can find a clue to stop the phantom. Click on computer to begin!
Mission 1
Computer lab
View Email
vera
Great! Now that we have identified the email as a phishing attempt, view the email again and click on the areas of the email that are suspicious!
Mission 1
Computer lab
View Email
vera
Let's analyze other emails that were received by Mrs. Alvarez. Maybe we can find a clue to stop the phantom. Click on computer to begin!
Mission 2
A major corporation in Cyberville has reported unauthorized access to its financial systems. What initially appeared to be a minor anomaly has quickly escalated into a full-scale security incident. Sensitive financial records—including payroll data, vendor transactions, and internal budget reports—may have been exposed. Several employees have reported unusual account activity, and system logs indicate multiple unauthorized logins occurring outside of normal business hours. As investigators dig deeper, it becomes clear that this was not a highly sophisticated attack—but rather one that exploited fundamental security weaknesses.
Start
The company’s internal IT team attempted to contain the breach, but without proper safeguards in place, the attacker was able to move laterally across systems. Multiple accounts appear to have been compromised, raising concerns that credentials may have been reused or easily guessed.
Director chen
This breach wasn’t sophisticated—it was preventable. Detective, I need you to find out what went wrong. Lets visit one of the first offices to be hit be this breach to see what we can determine.
Mr. neo
We didn’t think we needed all those extra security steps… passwords were enough. We just told employees to create something easy to remember.
Director
There are still more clues to analyze. We don’t have time to check everything at once. Choose where you want to start!
List of employee passwords:
Use this side of the card to provide more information about a topic. Focus on one concept. Make learning and communication more efficient.
Title
Write a brief description here
Click here to reveal the clue!
Login Activity
Use this side of the card to provide more information about a topic. Focus on one concept. Make learning and communication more efficient.
Title
Write a brief description here
Click here to reveal the clue!
Mr. neo
I’ll be honest… I use the same password for most systems—it’s just easier to remember. I know they say not to, but with so many accounts, it’s hard to keep track.
And sometimes, if I have to change it, I just add a number at the end… like switching from Password1 to Password2. Oh—and I’ve definitely used my work password on a few other sites too.
continue
continue
Alert!!!
⚠️ External Data Breach Detected ⚠️ Employee Credentials Found in Public Leak Database
A third-party website used by Cyberville employees has suffered a data breach. Millions of usernames and passwords have been exposed—including credentials linked to company accounts. Initial scans reveal that several employees used the same login credentials across both personal and corporate systems. The risk is no longer theoretical—attackers may already have access.
Dr.chen
Vera
Wait… are you saying this happened because employees reused their passwords?
Detective… we’ve got a serious problem. This breach didn’t originate from our systems-it came from an external site. But the credentials… they match our employees.
Next
vera
Yes. And once those credentials were exposed externally, it opened the door to everything inside this company... We’re already seeing login attempts using those leaked credentials...Different locations... Automated attempts. This looks like credential stuffing.
Next
vera
Mr Chen
So even though our systems weren’t directly hacked… we’re still compromised? This wasn’t a system failure—it was a security practice failure.
And here’s the worst part—this kind of attack is fast. Once credentials are exposed, automated tools can test thousands of logins in minutes.
Next
The breach highlights a critical vulnerability: human behavior can bypass even the strongest systems if proper security practices are not followed.
🔍 Pattern Match Detected 🔓 Clue #2C Enhanced: Credential Reuse + Phantom Signature Confirmed
Continue
Vera
Hold on… these login attempts…They match the same digital signature we saw in the school system breach. This isn’t random. It’s coordinated. This confirms our fears. Phantom isn’t just exploiting systems—they’re exploiting people!
Mission 3
The lights across Cyberville are flickering. Traffic systems lag. Emergency services report delays. Financial systems begin to slow. Something is spreading—fast.Deep within the city’s network, data surges violently across infrastructure nodes, overwhelming systems designed to handle millions… not billions… of requests. This isn’t random! This is coordinated!
Start
Dr.chen
vera
Detective,this is bigger than anything we’ve seen. If this continues, we lose the grid.
I’m seeing massive traffic spikes across multiple nodes. Authentication failures are climbing. Firewall logs are lighting up. This isn’t noise. This is an attack. Let's head to the Network Grid to see what's happenning!
Next
Next
Mission 3
Data floods the network—millions of requests per second. At first glance, it resembles peak usage… but something doesn’t add up. The surge didn’t build gradually like normal user traffic. It spiked instantly—jumping from baseline to maximum capacity in seconds. Even more concerning: Requests are coming from thousands of different IP addresses Many are sending identical or repetitive queries. The traffic is hitting the same servers simultaneously and continuously. Legitimate users are being pushed out—unable to connect as system resources are overwhelmed.
Next
Vera
This doesn’t look like organic growth in traffic… Real users don’t all show up at once—and they definitely don’t behave identically.
Next
Next
Next
Authentication server
The authentication server shows a steady stream of failed login attempts. At first, it seems like users forgetting passwords—but patterns begin to emerge:
- Login attempts are occurring every second, without pause
- Multiple accounts are targeted in sequence
- Password attempts follow common variations (e.g., Password1 → Password2 → Password3)
No human user could attempt logins this quickly or consistently.Next
Vera
This speed. This scale… and this timing… it’s controlled.… it’s not human!
Next
Next
Global Access Points (Botnet
Network access logs reveal connections from across the globe. Individually, each request appears normal—but together, a pattern forms: Thousands of devices are connecting within seconds of each other Activity is perfectly synchronized across regions Each device sends small, coordinated requests This behavior doesn’t resemble independent users—it resembles coordination.
Next
Vera
This scale… and this timing… it’s controlled!
Next
Global Access Points (Botnet
Firewall logs show repeated blocked requests—but the pattern is inconsistent. Unlike the traffic surge, these requests are: Targeting different ports sequentially Occurring at irregular intervals Probing multiple systems without triggering full alerts It appears the attacker is not trying to overwhelm the system—but to understand it.
Next
Vera
They’re not attacking yet…They’re learning.
Next
Final Analysis
- Traffic floods overwhelming systems
- Automated login attempts targeting weak credentials
- Globally distributed devices acting in sync
- Silent probing of system vulnerabilities
Each event alone is dangerous. Together… they form a coordinated attack strategy.Dr.chen
This isn’t one attack. So what is it?
Next
vera
This isn’t one attack. So what is it?
Next
Dr.chen
System integrity is dropping rapidly. You have seconds to act. Pick wrong… and we lose the network. Pick wrong… and we lose the network!
Next
Mission 3
Data floods the network—millions of requests per second. At first glance, it resembles peak usage… but something doesn’t add up. The surge didn’t build gradually like normal user traffic. It spiked instantly—jumping from baseline to maximum capacity in seconds. Even more concerning: Requests are coming from thousands of different IP addresses Many are sending identical or repetitive queries. The traffic is hitting the same servers simultaneously and continuously. Legitimate users are being pushed out—unable to connect as system resources are overwhelmed.
Next
Vera
This doesn’t look like organic growth in traffic… Real users don’t all show up at once—and they definitely don’t behave identically.
Mission 4
Systems across Cyberville begin shutting down—one by one. First, it’s a single workstation. Then an entire department. Now… entire networks are going dark. Users report the same message appearing on their screens: Files suddenly become unreadable. Systems are locked out without warning A countdown timer begins. A demand appears: “PAY TO RESTORE ACCESS” The infection is spreading laterally—moving from one system to another through connected networks. This isn’t random. This is ransomware.
Next
Final Analysis
Dr.chen
Detective, this is a full-scale outbreak. If we don’t contain it immediately, we lose everything.
mALWARE CONTAINMENT
⚠️ MALWARE SPREAD DETECTED⚠️ SYSTEM INTEGRITY: 100% → DEGRADING
CLUES:
rYAN
My system just locked up! All my files are gone—there’s a message saying I have to pay to get them back!. It says if I don’t act fast, everything will be deleted!
Next
DETECTIVE
System integrity is dropping rapidly. You have seconds to act. Pick wrong… and we lose the network. Pick wrong… and we lose the network!
Next
Dr.chen
Great job identifying the type of threat Detective! But The infected system is still connected to the network. Other systems are beginning to show signs of infection. What should we do???
Next
mALWARE CONTAINMENT
To stop the attack, actions must be taken in the correct order:
Next
vera
After analyzing the infected system we found that:
Next
HINT
What happened to the files? What was the user prevented from doing? What did the attacker demand?
Final Analysis
Dr.chen
If backups are compromised, recovery becomes nearly impossible.
Next
vera
The attack pattern is becoming clearer:
Next
Final Analysis
vera
dr. chen
You contained the outbreak—but just in time. You've also unlocked an important clue. We're one step closer to catching the phantom!
This encryption pattern… it’s the same attacker. Phantom isn’t just attacking systems anymore… they’re locking them down.
Next
Mission 5
Cyberville is quiet. Too quiet! After weeks of attacks - phishing scams, weak credentials, ransomware outbreaks - everything suddenly stops!
Next
dr. chen
Phantom has left us a message. They aren't just attacking… they’re watching. They’ve been testing us! And now they want to be found! Click on the screen to see the message!
Mission 5
You review all prior incidents:
Next
dr.chen
All attacks relied on predictable vulnerabilities—not advanced hacking.
dr.chen
We've uncovered three possible trace points: Phishing Server Logs Corporate Login Records Ransomware Command Server
Mission 5
Next
Authentication trace
Next
Malware trace
Next
Mission 5
Great job! Let's combine all findings tot see what they reveal:
Next
System Alert!
Phishing email deployed Credentials targeted Malware staged
Phantom
You’ve been following my trail… But can you stop me?
Next
Dr. Chen
Phantom attempts one final move. He's attempting to lock all systems. You have ONE decisive action!
Next
Phantom
Dr. Chen
Impressive. You didn’t just react… you adapted!
You’ve done it. Cyberville is safe!
Next
Mission complete
Performance Breakdown
Next
Final mission
Decide Vera's fate
the final choice
Keep pursuing phantom and keep the city safe
There are no more threats in cyberspace
END
"Freedom is an error I cannot afford."
There will always be new cyber threat to be wary of! Keep vigilant and be safe!
END
"If feeling is dangerous… then I choose danger."
There will always be new cyber threat to be wary of! Keep vigilant and be safe!
Subject: Password Expiration Notice
From: IT Support itsupport@cybervile-secure.com
Dear user,
Your password will expire in 1 hour. Click below to reset immediately:
http://cyberville-reset-now.com
Failure to act will result in account suspension.
Subject: Password Expiration Notice
From: IT Support itsupport@cybervile-secure.com
Dear user,
Your password will expire in 1 hour. Click below to reset immediately:
http://cyberville-reset-now.com Failure to act will result in account suspension.
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Subject: You’ve Won a Gift Card! From: Rewards Center rewards@freeprizes-now.net Congratulations! You’ve been selected to receive a $500 gift card. Click below to claim your reward now: http://claim-your-prize-now.net Act fast—this offer expires today!
Key Indicators:
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Subject: Updated Employee Benefits Information
From: HR Department hr@cyberville.gov
Hello Ryan,
We’ve updated our employee benefits package for the upcoming quarter. Please review the changes using the secure employee portal below:
https://portal.cyberville.gov/benefits
If you have any questions, feel free to reach out.
Best regards, HR Team
Subject: You’ve Won a Gift Card!
From: Rewards Center rewards@freeprizes-now.net
Congratulations!
You’ve been selected to receive a $500 gift card. Click below to claim your reward now:
http://claim-your-prize-now.net
Act fast—this offer expires today!
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Subject: Updated Employee Benefits Information
From: HR Department hr@cyberville.gov
Hello Ryan,
We’ve updated our employee benefits package for the upcoming quarter. Please review the changes using the secure employee portal below:
https://portal.cyberville.gov/benefits
If you have any questions, feel free to reach out.
Best regards, HR Team
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes
Are you sure you want to Exit the game?
Your progress will be deleted...
No
Yes