ATSS — Smart & Secure
ATSS — الحلول والخدمات المتقدمة للاتصالات ATSS — Advanced Telecom Solutions & Services إدارة تقنية المعلومات والأمن السيبراني IT & Cybersecurity Department

توقّف — هذه كانت رسالة تصيّد محاكاة

Stop — this was a simulated phishing email

الرسالة التي ضغطت على رابطها لم تكن حقيقية. أرسلتها إدارة تقنية المعلومات والأمن السيبراني في ATSS ضمن برنامج التوعية الأمنية، لقياس جاهزيتنا جميعاً أمام هجمات التصيّد الحقيقية.

The email you clicked was not real. It was sent by the ATSS IT & Cybersecurity Department as part of our Security Awareness Program, to measure how prepared we all are against real phishing attacks.

لا داعي للقلق. لم يُصب جهازك بأي ضرر، ولم يتم جمع أي من بياناتك. هذا التمرين تعليمي بحت، ولا يترتب عليه أي إجراء أو مساءلة تجاهك. No need to worry. Your device was not harmed and none of your data was collected. This exercise is purely educational — there is no penalty or disciplinary action attached to it.

؟ لماذا يهمّنا هذا؟ Why this matters

التصيّد الإلكتروني هو الطريق الأول الذي يسلكه المهاجمون للدخول إلى شبكات المؤسسات. ضغطة واحدة على رابط خبيث قد تؤدي إلى سرقة بيانات الدخول، أو تشفير الملفات ببرمجيات الفدية، أو تسريب معلومات العملاء. أنظمة الحماية تصدّ الكثير، لكن يبقى وعيك أنت هو خط الدفاع الأخير والأهم.

Phishing is the number one way attackers get into corporate networks. A single click on a malicious link can lead to stolen credentials, ransomware encrypting your files, or a leak of customer data. Security controls stop a lot — but your awareness remains the last and most important line of defence.

1 العلامات التي كان يمكن أن تكشفها The red flags you could have spotted

راجع الرسالة مرة أخرى وستجد هذه المؤشرات:

Look at the email again and you will find these indicators:

المرسلSENDER

نطاق بريد غير مألوف

Unfamiliar sender domain

الاسم الظاهر قد يبدو موثوقاً، لكن العنوان الفعلي بعد علامة @ لا يعود لـ atss.sa. تحقّق دائماً من العنوان الكامل لا من الاسم المعروض.

The display name may look trusted, but the actual address after the @ does not belong to atss.sa. Always check the full address, not the display name.

الاستعجالURGENCY

ضغط زمني أو تهديد

Time pressure or threat

عبارات مثل «خلال 24 ساعة» أو «سيتم تعليق حسابك» مصمّمة لتدفعك للتصرف قبل التفكير. الجهات الرسمية لا تهدّد بهذا الأسلوب.

Phrases like "within 24 hours" or "your account will be suspended" are designed to make you act before you think. Legitimate parties do not pressure you this way.

الرابطLINK

رابط مموّه

Disguised link

نص الرابط شيء ووجهته الحقيقية شيء آخر. مرّر المؤشر فوق الرابط (دون ضغط) وستظهر لك الوجهة الفعلية أسفل الشاشة.

The link text says one thing, its real destination is another. Hover over it (without clicking) and the true destination appears at the bottom of the screen.

الطلبREQUEST

طلب بيانات دخول

Asking for credentials

لن تطلب منك إدارة تقنية المعلومات في ATSS كلمة المرور أو رمز التحقق عبر البريد أو الهاتف — إطلاقاً، ولأي سبب.

ATSS IT will never ask you for your password or MFA code by email or phone — ever, for any reason.

الصياغةWORDING

تحية عامة أو أخطاء لغوية

Generic greeting or language errors

«عزيزي المستخدم» بدل اسمك، أو ركاكة في الصياغة والتنسيق، مؤشر متكرر على رسائل التصيّد الجماعية.

"Dear user" instead of your name, or awkward wording and formatting, is a common sign of bulk phishing.

المرفقATTACHMENT

مرفق غير متوقّع

Unexpected attachment

فاتورة أو مستند لم تطلبه، خصوصاً بصيغ HTML أو ZIP أو ملفات Office تطلب «تفعيل المحتوى» — لا تفتحه.

An invoice or document you did not request, especially HTML, ZIP, or Office files asking you to "enable content" — do not open it.

2 ماذا تفعل في المرة القادمة What to do next time

✓ افعل

✓ Do

  • توقّف وتمهّل قبل الضغط على أي رابط.
  • مرّر المؤشر فوق الرابط لفحص وجهته الحقيقية.
  • تحقّق من عنوان المرسل كاملاً.
  • اتصل بالمرسل عبر قناة معروفة إذا كان الطلب مالياً أو حساساً.
  • أبلغ عن الرسالة المشبوهة فوراً.
  • Pause before clicking any link.
  • Hover over links to inspect the real destination.
  • Verify the sender's full email address.
  • Call the sender through a known channel if the request is financial or sensitive.
  • Report the suspicious email immediately.

✕ لا تفعل

✕ Don't

  • لا تُدخل كلمة المرور في صفحة وصلت إليها من رابط بريد.
  • لا توافق على طلب تحقق ثنائي (MFA) لم تبدأه أنت.
  • لا تفتح المرفقات غير المتوقعة.
  • لا تعِد توجيه الرسالة المشبوهة إلى زملائك.
  • لا تتجاهلها بالحذف فقط — أبلغ عنها.
  • Don't enter your password on a page reached from an email link.
  • Don't approve an MFA prompt you did not initiate.
  • Don't open unexpected attachments.
  • Don't forward the suspicious email to colleagues.
  • Don't just delete it — report it.

كيف تُبلغ عن رسالة تصيّد حقيقية

How to report a real phishing email

استخدم زر Report Phishing في Outlook إن كان متاحاً، أو أعد توجيه الرسالة كمرفق إلى فريق الأمن السيبراني. إبلاغك المبكر يحمي زملاءك.

Use the Report Phishing button in Outlook if available, or forward the email as an attachment to the Cybersecurity team. Reporting early protects your colleagues.

cyber_security@atss.sa
إذا سبق أن أدخلت كلمة مرورك في رسالة مشبوهة، غيّرها فوراً وأبلغنا في نفس اللحظة.
If you have already entered your password on a suspicious page, change it immediately and tell us right away.