Featured
# Cybersecurity Awareness Month
# Programme
# Workshop
Built In A Day: What Happened When We Stopped Planning and Started Building

Ant Davis
All Content

Mette Luntama ¡ Jul 27th, 2026
This Phish of the Week features a personalized Adobe Summit invitation with mismatched event dates and a countdown timer that pressures recipients into signing in through a fake Google pop-up.
# Phish of the Week
# Phishing
Comment

Ant Davis ¡ Jul 27th, 2026
The third piece in the Borrowed series, applying ideas from outside security to awareness practice. Marketing solved audience segmentation decades ago, but security awareness still sends the same simulation to every department regardless of what an attacker would actually want from that team. This piece applies real segmentation, by risk exposure, technical fluency, and workflow, to phishing simulations and comms.
# Phishing
Comment

Mette Luntama ¡ Jul 20th, 2026
Attackers repurpose a legitimate email marketing platform to deliver a Fastway Couriers impersonation, funneling recipients toward a fake customs duty payment and financial theft.
# Phish of the Week
# Phishing
Comment

Ant Davis ¡ Jul 13th, 2026
The first piece in a new series, Borrowed, applying ideas from outside security to awareness practice. Most phishing reporting buttons would fail as a product feature: buried clicks, unclear labels, no feedback loop, and design that unintentionally recreates the exact deceptive patterns UX research has spent over a decade cataloguing. This piece treats the report button as a conversion funnel rather than an IT afterthought, breaking down where people actually drop off and what fixing it looks like in practice.
# Programme
1

Mette Luntama ¡ Jul 13th, 2026
A fake prescription notice uses a QR code to launch a device code phishing flow, giving attackers Microsoft account access without ever needing to steal the recipient's password.
# Phish of the Week
# Phishing
Comment

Ant Davis ¡ Jul 6th, 2026
Security awareness has a visual and tonal dialect that people have learned to ignore. This post is about why that happens, what Octopus Energy did about it in their own low-interest category, and what a purple puppet called George taught me about building something that outlasts you.
3

Mette Luntama ¡ Jul 6th, 2026
This multi-stage HR impersonation attack uses a realistic training quiz to build credibility before funneling the target into a dynamically branded Microsoft credential harvester.
# Phish of the Week
# Phishing
Comment

Maxime Cartier ¡ Jul 1st, 2026
The leading authority on game design, Yu-kai Chou, connects with Hoxhunt's VP of Human Risk, Maxime Cartier for practical insights into applying gamification to level-up security awareness engagement.
Most security awareness programs struggle with the same challenge: how do you create lasting security habits when employees don't want more training?
Chapters:
01:06 - Introduction
-
04:49 - What does Gamification mean?
-
08:19 - The Eight Core drives that motivate human behaviors, and the ones that are underused in Security Awareness
-
16:45 - White Hat vs. Black Hat techniques: how to find the right balance?
-
21:53 - The Concerns Maxime Hear All The Time about Gamification
-
22:10 - Concern #1: Gamification is great but it doesn't work for older employees.
-
25:59 - Concern #2: We're too serious for this
-
29:31 - Concern #3: Rewards attract the wrong people
-
33:22 - Concern #4: People get bored eventually
-
35:46 - The power and danger of streak mechanisms
-
39:10 - Yu Kai's new book: 10,000 hours of play
-
52:35 - Next steps for viewers
-
Yu-kai's Octalysis Framework has influenced products and engagement systems used by more than 1.5 billion people worldwide and has shaped the design philosophy behind organizations including Google, Microsoft, LEGO, Salesforce, and Hoxhunt.
Together, Yu-kai and Maxime will explore how the same behavioral principles that keep people engaged in games for years can be applied to cybersecurity awareness training, phishing simulations, and human risk management programs.
# Gamification
Comment

Ant Davis ¡ Jun 30th, 2026
A free, browser-based tool that turns "I need more help" into a number, a chart, and a sentence a CISO can repeat back to their boss. Here's why we built the Capacity Case Calculator and how to actually use it.
# Data
3

Mette Luntama ¡ Jun 29th, 2026
This spoofed incoming message failure alert uses sender address impersonation and a Google domain open redirect to deliver a prefilled Microsoft credential harvester.
# Phish of the Week
# Phishing
Comment

