To successfully phish corporate users, simply tell them at the end of the flow that this has been a phishing exercise and they should be more cautious next time but that they need not change their passwords this time since it was only a test…

