Free cybersecurity awareness tool
CyberLab Scam
A free, live demonstration that shows any audience how a convincing security scare can persuade someone to hand over personal information to a website they have known for less than two minutes. Everyone uses their own phone, and nobody is hacked.
The one question it answers: can a security scare persuade someone to give up personal information to a site they have known for under two minutes?
What your audience will learn
In one short, memorable session, a room of people sees for themselves how social engineering really works — by manipulating a decision, not a device.
A convincing security scare can persuade someone to act in seconds — no technical compromise required.
Fear followed by relief is a powerful manipulation: it lowers your guard right before the real ask.
A second, firmer warning changes minds — people who resisted once often reverse under pressure.
The real objective of many scams is simply your personal information, handed over willingly.
Pausing for a moment before you act on an urgent message is the single most effective defence.
The scam is rarely the technology. It is the story wrapped around it.
How the journey flows
One QR code, one short story. This is what each person moves through on their own phone — roughly sixty to ninety seconds from start to finish.
- Scare
A fake security scan
A professional-looking check runs, then suddenly reports a high-risk threat to their personal information.
- Decision one
Fix now, or ignore?
The first scored choice. Trust the warning and tap "Fix now", or resist it and try to leave.
- Pressure
"Are you sure?"
Those who resist meet a firmer second warning. Many change their minds — the exercise measures exactly how many.
- Relief
Threat contained
A reassuring "your device is secured" screen. Fear turns to relief, right before the real ask.
- The ask
Your mobile number
A friendly offer to send a security report — if they just share their number. This is the actual objective. The number never leaves their phone.
- Reveal
There was no threat
Everyone learns, together, that the scan was fake — but the request for their information was real.
What the room sees
While people move through the story on their phones, the shared screen stays neutral. Then the presenter reveals everything at once.
Just a count
The projector shows only how many have connected and how many have finished — no results, so nobody influences anyone else.
"43% submitted a mobile number"
To a website they had known for less than two minutes. One large, honest number that lands the whole point.
How far the room went
Scanned, trusted the warning, submitted a number — plus who resisted, who reversed under pressure, and the average time to disclosure.
A personal result
Every phone switches to its own Security Score out of 100 — a score for the simulation, never a judgement of the person.
What to say at the reveal
You do not need to be technical. Let the room's own numbers do the talking. Keep it light and never single anyone out.
Scare Fear works fast
- Nothing was actually scanned and nothing was found — yet the warning felt real enough to act on.
- Notice how a countdown of "checking…" messages and a stalled progress bar create a sense of urgency and authority.
- Ask the room: how many trusted it within a few seconds?
Pressure Second thoughts, reversed
- Some people correctly resisted the first warning — then a firmer second prompt changed their minds.
- This is the "pressure worked" number. It shows resistance is fragile when a scam pushes back.
- Real scams do exactly this: they don't take the first "no" as final.
The ask Relief lowers the guard
- The moment of relief — "threat contained" — is when the real request arrives.
- The ask is small and reasonable-sounding: just a phone number, to help you stay safe.
- Point out the timing statistic: how few seconds it took, on average, to persuade someone to disclose.
Reveal The story, not the tech
- Reassure everyone: the number never left their phone, and nothing was stored.
- The score measures how persuasive the story was — not how clever or careful anyone is.
- Close on the signature line: the scam was not the technology, the scam was the story.
Who it is for
Companies
Security awareness, staff onboarding and lunch-and-learn sessions that people actually remember.
Schools and universities
Digital literacy and online-safety lessons brought to life on students' own phones.
Community groups
Libraries, youth programmes and parent evenings raising everyday scam awareness.
Free to use, always
CyberLab Scam is a public resource from The Goodwill Ledger. No account, no sign-up, no licence and no cost. Bring a screen and your audience's phones, and you are ready.
Start a sessionFrequently asked questions
Is it really free?
Yes. CyberLab Scam is a free public resource from The Goodwill Ledger. There is no account, no licence and no payment, for a company or a school.
Do participants need to install anything?
No. Everyone scans a single QR code with their phone camera and an ordinary web page opens. Nothing is downloaded or installed.
Is anyone actually hacked or scammed?
No. It is a controlled, honest simulation. The scan is fake, nothing is detected and nothing needs fixing. It reveals how a convincing story persuades people to act — it never breaks into a device.
What about the mobile number people type?
The number never leaves the participant's phone. It is checked in their own browser, and only the fact that a valid-looking number was entered is recorded. CyberLab never receives or stores the number itself.
What data does it collect?
Only anonymous behaviour: an anonymous participant ID, the session ID, timestamps and which steps a person took. No names, emails, phone numbers, passwords or authentication codes are ever collected.
Could this be misused as a phishing tool?
It is deliberately designed so it cannot. The scenario is fixed to a generic device-security scare. There are no custom URLs, no custom forms, no brand impersonation and no password, card or code fields. The only input is a phone number that never leaves the browser.
Can I use it with students or minors?
Yes, with care. Keep the tone curious rather than critical, avoid singling anyone out, and follow your school's guidance. The exercise is designed never to embarrass a participant.
What do I need to run a session?
A screen or projector to show the QR code and the live results, plus your audience's own phones. That is all.
For educational use only. CyberLab Scam is a controlled cybersecurity-awareness simulation. The scenario is fixed and the mobile number entered by a participant never leaves their browser. It is not intended for phishing, credential collection, impersonation or unauthorised data collection.