Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Phishin’ Impossible: Reinventing Cybersecurity Awareness Training
Articles Attacks Phishing Training & Education

Phishin’ Impossible: Reinventing Cybersecurity Awareness Training

Dilki RathnayakeBy Dilki RathnayakeJune 5, 2023Updated:August 24, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Inspired e-Learning’s  new cybersecurity awareness training game, Phishin’ Impossible, takes a novel approach in teaching employees about cyber threats. Players assume the role of a white hat hacker tasked with crafting convincing scam emails to fool unsuspecting staff. Players learn how cybercriminals operate and how to protect themselves by spending time in a hacker’s shoes. 

After a brief introduction, players are tasked with crafting a phishing email to fool recipients into clicking a malicious link. If they succeed, they’ll be offered the opportunity of a lifetime; a job with the notorious white hat hacking group “Infamous Phun.” 

Once initiated, players begin working their way through Infamous Phun’s ranks, starting as a “Rookie” and, depending on their performance, finishing up as a “Guru” hacker.

It’s here that things get serious. The world’s largest tech firm, Armstrong Tech, recruits Infamous Phun to send phishing emails to their staff and report back with the findings. The player’s mission? Craft a convincing phishing email targeting every single one of Armstrong’s employees. 

Each mission offers players a choice of sender addresses, subject text, and body text. After every decision, the game provides feedback, explaining why players’ choices were right or wrong. 

Once this mission is complete, players move onto their next task: craft a fake email convincing an employee to arrange a money transfer in the CEO’s absence:

The fourth and final mission is the most audacious yet. Players are tasked with phishing the Big Boss himself, Jackson Armstrong. Armstrong prides himself on his cyber-savvy but has one fatal flaw – his dog. To successfully fool the CEO, players will need to exploit his weakness. It all comes down to this.

The beauty of Phishin’ Impossible is that it doesn’t feel like cybersecurity awareness training. Just as players trick unsuspecting staff into clicking malicious links, the game tricks players into learning about phishing scams. It has an engaging narrative, appealing imagery, and valuable information. Phishin’ Impossible isn’t just an educational tool; it‘s a welcome break for employees who spend their days staring down the barrel of a spreadsheet. 

What’s more, the ranking system motivates you to replay the game. It’s long been established that cybersecurity awareness training only works when consistent, and Phishin’ Impossible is endlessly repeatable. If you only reach the “Freshman Hacker” rank the first time, you want to replay the game until you become a “Guru Hacker.” When you do, you reaffirm the lessons you learned in the first playthrough. 

Unlike other cybersecurity awareness training offerings, Phishin’ Impossible doesn’t simply pepper players with emails and ask them to identify the fake ones. Instead, players are placed firmly in the driver’s seat, crafting phishing emails to truly understand how cybercriminals think. 

Over the years, there have been many attempts to make staff training “fun,” but almost all have fallen flat. Phishin’ Impossible is not one of them. Think back to when you were at school. Remember how exciting it was when you walked into a classroom with laptops set up for you? You’d spend the lesson learning without even realizing it. Phishin’ Impossible gives you that same feeling. 

Dilki Rathnayake
Dilki Rathnayake

Dilki Rathnayake is a cybersecurity content writer and the Managing Editor at Information Security Buzz, with a BSc in Cybersecurity and Digital Forensics. She is skilled in computer network security and Linux system administration. Dilki has also led awareness programs and volunteered for communities promoting best practices for online safety.

  • Dilki Rathnayake
    The new rules of war have no rules
  • Dilki Rathnayake
    AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks
  • Dilki Rathnayake
    Out of Office, Not Out of Mind: Staying Cyber-Smart Over the Holidays
  • Dilki Rathnayake
    The Real Purpose of the UK’s Online Safety Act: An Expert Explains

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}