Alignment: LO3 / A3 Objective: Preserve useful evidence and start containment without destroying the incident timeline.
Use only the simulated data supplied in this folder. Do not test live suspicious links, accounts, phone numbers or payment routes.
- Start an incident log with date, time, timezone and reporter.
- Preserve the original message, sender identifiers, URLs, screenshots and transaction references.
- Record actions already taken, including clicks, downloads, credentials entered and transfers.
- If compromise is suspected, isolate the affected device without factory-resetting it.
- Use a separate trusted device to contact the bank and protect accounts.
- Change exposed credentials in priority order and revoke active sessions.
- List affected people, systems, data and financial accounts.
- Package evidence with neutral filenames and a chain-of-custody note.
Incident timeline, evidence register and initial containment record.
The chronology is complete, evidence remains unaltered, and containment actions are distinguished from eradication.
Which observable fact most changed your decision, and which uncertainty remains?