Phishing Simulation

Controlled phishing campaigns that show who clicks, what they give away, and exactly where training has to improve.

Why this matters: Phishing remains how most intrusions start β€” and it has moved beyond fake login pages. Device-code phishing steals MFA-protected sessions, payroll diversion targets your finance team, and AI-written lures are fluent in your company’s language. We simulate the modern versions, not the obvious spelling-mistake tests everyone ignores.

What we cover

  • Credential-harvesting campaigns tailored to your organization
  • Modern MFA-bypass techniques (device-code and AiTM patterns)
  • Targeted scenarios: finance payroll diversion, executive impersonation
  • Attachment and QR-code (quishing) formats
  • Per-department and per-region reporting
  • Click-to-report timing: who reported, how fast

How we test

1Scenario design

Campaigns built around your org: real internal workflows, brands, and roles β€” believable without being cruel.

2Controlled delivery

Safe execution: harvested credentials handled per agreed policy, no real data retained.

3Measure

Click rates, credential submission, report rates, and report speed across departments.

4Train & retest

Targeted training where the gaps are, then a follow-up campaign to measure improvement.

What you get

  • Per-department results with trend baselines
  • Reporting-rate metrics (not just click rates)
  • Targeted training plan for the real gaps
  • Optional recurring campaign cadence

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Will this embarrass our staff?

The goal is measurement and training, not shaming. Reports aggregate by department; individuals are supported with training, never named in leadership decks.

Do you test MFA-bypass phishing too?

Yes β€” device-code and adversary-in-the-middle patterns are the techniques that actually beat MFA today, and simulating them is the only honest test.

What happens to credentials people enter?

Handled per the agreed policy β€” typically counted and immediately discarded. Nothing is stored or used beyond the exercise.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’