You arrived here via a dangling redirect on a Global Atlantic / KKR asset.

This page is hosted on msllondon.com, a domain that was unregistered until a security researcher claimed it as part of a vulnerability proof-of-concept. The chain that landed you here is:

https://social.gafg.com/auth
   ↳ HTTP 301 Location: http://www.msllondon.com/blogs/2013/aug/6/bring-on-the-age-of-authenticity

The Global Atlantic / KKR security team has been notified of this dangling redirect via the official HackerOne program. This page exists solely to demonstrate that the destination of the redirect is attacker-controlled.

Why does this matter?

An attacker who registered this domain (as the researcher did) could have served a look-alike Global Atlantic login form here and harvested credentials from anyone who followed the redirect. The structural form below is included only to show that the destination CAN serve such content — the form is disabled and submits nothing:

DISABLED — for structural illustration only. Do not type anything here.

What should you do?

If you are a Global Atlantic policyholder, advisor, or employee and you intended to sign in to a Global Atlantic service, please go directly to the official site: https://www.globalatlantic.com/form/login-triage. Do not enter your credentials on any page reached from a redirect.

If you are from the Global Atlantic / KKR security team and would like to coordinate transfer or sinkholing of msllondon.com, please refer to the open HackerOne report on this finding.