Some of you may have suspected, but within the last week this site has been "man in the middle" when accessed from within the company network. Verify this by viewing the site certificate in the browser, get the SHA1 fingerprint and check that against the public internet SHA1 using a site like www.grc.com/fingerprints.htm.
Funny thing is they did it wrong, probably used a self signed cert, because you have to add a security exception now. Maybe that was intentional from a well meaning network engineer.
Don't post here from the company network!