This page is part of an authorised exercise
You reached this page by searching for Aster Vale Register onboarding, or by following a link that led here. Aster Vale Technology does not exist. Neither does the product.
This site was created by your own security team as part of an authorised awareness exercise. Nothing has been installed, nothing has been compromised, and you have not done anything wrong.
What this was testing
Search engines are a trusted interface. When a result appears at the top of the page for a term that looks internal and specific, most people treat that ranking as a signal of legitimacy — the page must be genuine, or it would not rank first.
It is not a signal of anything. Ranking first for an unusual phrase requires only that a page exists, is indexed, and that nothing else competes for the phrase. Anyone can do it, for any phrase, in a matter of days.
This is the mechanism behind SEO poisoning: an attacker publishes pages targeting terms a specific group is likely to search — an internal tool name, a vendor onboarding process, a niche error message — and waits. The victims arrive on their own, believing they found the page rather than that the page found them.
Why it works
- Searching feels active. Clicking a link in an unexpected email feels like a risk. Searching for something you needed feels like your own idea, and the result inherits that trust.
- Specific terms have no competition. The rarer the phrase, the easier it is to rank first for it. Internal-sounding terms are the easiest of all.
- The page looked ordinary. It had a plausible product, plain writing and no urgency. Nothing about it triggered suspicion, because nothing about it was unusual.
What a real attack would have done here
This page showed you a debrief. A real one would have shown a login form matching your organisation's branding, and captured whatever you typed — including a multi-factor code, which can be relayed in real time.
There was never a password field on this site, at any point, on any page.
What to do differently
- Reach internal tools by bookmark, not by search. If you find yourself searching for an internal system, that is the moment to stop and use a known-good link instead.
- Check the domain before you type anything. Especially where credentials are involved. A convincing page is easy; a convincing domain you already trust is not.
- Treat a search result's position as meaningless. Ranking reflects indexing and competition, not legitimacy.
- Report it when something feels off. Reports are what turn one person's near-miss into everyone's early warning — and nobody gets in trouble for reporting.
Your data
This exercise recorded that this page was visited and, if a campaign reference was present in the link, which one. No password, username, email address or personal information was requested, captured or stored — there was nowhere on this site to enter any. Exercise records are deleted when the exercise closes.
Questions about this exercise: contact your internal security team through a known-good channel.
If you arrived here looking for genuine guidance on an internal system, please contact your IT service desk using a known-good channel rather than following links from search results.