Phishing simulation

Simulations that teach, not just measure

A click-rate report by itself doesn't change behavior. Every Cyberwareness simulation ends with a specific, immediate teachable moment, so the lesson lands at the exact second it matters most.

Example scenarios

All names, companies, and domains below are fictional. No real brand or live malicious link is ever used. Every simulation is currently delivered by email - the SMS, WhatsApp, voice, and QR scenarios below are email simulations written around those real-world attack patterns, not messages sent over those channels.

Email

Fake IT password reset

"Your password expires in 24 hours. Click here to keep access." Sent from a lookalike IT helpdesk domain.

Red flags: External lookalike domain, generic greeting, 24-hour urgency, mismatched link destination.

Email (Nigeria)

Vendor invoice bank-detail change

A known vendor appears to email that their bank details have changed due to an internal audit, ahead of this month's invoice.

Red flags: Unprompted bank-detail change, no phone confirmation offered, a slightly altered vendor domain.

Email (US)

CEO gift-card request

An "executive" asks a finance or assistant staffer to urgently buy gift cards for a client thank-you, from a wrong domain extension.

Red flags: Bypassing normal purchasing process, gift-card codes requested, urgency plus personal favor framing.

Email (WhatsApp-style scenario, Nigeria)

Family-emergency message

A message claiming to be from a relative in urgent trouble, asking for money or an OTP to be shared immediately.

Red flags: New or unknown number, urgency, request to share an OTP or send money without a verification call.

Email (voice-call script)

Deepfake CEO voice call

A dramatized, recorded simulation of a cloned executive voice instructing an urgent payment or access change, never a real cloning attempt.

Red flags: Urgent, unusual request; pressure to skip verification; no second-channel confirmation offered.

Email (QR-style)

"Quishing" poster

A QR code placed in a break room or parking area claiming to offer a prize or survey, leading to a fake login page.

Red flags: Unsolicited QR code in a public space, prize or urgency framing, request for a login after scanning.

How a simulation run works

  1. 1

    Pick a template and audience

    Choose from a rotating library, including Nigeria and US-flavored scenarios, targeted to a role or the whole company.

  2. 2

    Run it safely

    Fictional sender, fictional domain, no live link, and no real data ever collected from anyone who interacts with it.

  3. 3

    Teach in the moment

    A click, reply, or callback immediately shows the specific red flag missed and links to the relevant short lesson.

See a sample simulation in your demo

Book a free demo and we'll walk through a live example end to end, including the reporting view.

Frequently asked questions

Are your phishing simulations safe to run?

Yes. Every simulation uses fictional brand names, banks, and domains; there are no real company logos and no live or functional malicious links. Any "link" or "number" in a simulation points only to our own tracking and landing page, never to a real external destination.

What happens when someone clicks or responds to a simulation?

They see an immediate, specific teachable moment explaining exactly what red flag they missed and linking to the relevant short lesson, so the learning happens in the moment, not weeks later in a report.

How often do simulations run?

Simulations are rotated through the 12-month microlearning calendar alongside short lessons, roughly 1-2 per month, so no employee sees the same template twice in a year.

Do you track click rates and reporting rates?

Yes. Every simulation you run shows sent, clicked, and reported rates broken out by department, so you can compare each run against the ones before it and show real behavior change over time, not just completion checkmarks.