PhishingAwarenessSMEs

Phishing simulations: 12 role-based scenarios

Generic phishing no longer trains anyone. Here are 12 role-based scenarios you can launch tomorrow, with the pretext, channel, and intended lesson.

Hakim Djelili7 min read

A “generic” phishing campaign sent to the whole company rarely trains anyone. In contrast, role-based scenarios reveal real responses and train the people who genuinely need it. Here are 12 ready-to-use scenarios, arranged in 4 categories of 3, with their pretexts, channels, and lessons.

Method

How to read these 12 scenarios

4

Roles targeted

HR, Finance, IT, Executives

3

Scenarios per role

From the most conventional to the most elaborate

20-40%

Typical click rate

For a well-designed targeted scenario

Target 1: HR

Human resources: 3 scenarios

1Email

Fake malicious CV

Pretext

A fictitious applicant applies for a role genuinely advertised on LinkedIn, attaching a PDF named “CV_Marie_Dupont.pdf” that contains a malicious macro.

Trapped action

Open the attachment to assess the applicant before the proposed interview.

Why it works

HR teams open an average of 50+ CVs per week. Repetition reduces vigilance, and the recruitment context makes opening the file seem legitimate.

2Email

Employee bank details change request

Pretext

An email appearing to come from an employee (from a near-identical external address) asks HR to update their bank details for the next payroll, with the details attached.

Trapped action

Update the bank details in the payroll system.

Why it works

The urgency before payroll and apparent familiarity with a colleague bypass the dual-approval procedure.

3WhatsApp / SMS

Fake HR platform

Pretext

A text message in the name of the health insurer or training provider announces a mandatory employee account update before a deadline.

Trapped action

Click a link to a fake login page that collects credentials.

Why it works

The mobile channel sits outside the usual scope of technical controls such as email anti-phishing filters.

Target 2: Finance

Accounting and finance: 3 scenarios

4Email

Fake supplier invoice

Pretext

An invoice arrives from a real company supplier (identified through public information), with a discreet change of bank details at the bottom of the document.

Trapped action

Pay the invoice using the new bank details shown.

Why it works

The supplier's brand is familiar and the document looks routine. This is the most common transfer scam affecting French SMEs.

5Email + Phone

CEO fraud

Pretext

An email from the “CEO” asks the accountant to prepare an urgent, confidential transfer to complete an acquisition. A fake lawyer follows up by phone to confirm it.

Trapped action

Make a transfer of €80k to €200k without the usual management approval.

Why it works

A combination of authority, confidentiality, urgency, and two channels. It remains the costliest scam for SMEs (median: €165k).

6Email

“Draft financial statements” Excel attachment

Pretext

An email from the “statutory auditor” sends an Excel file for approval before the quarterly close. The file contains a macro that downloads an infostealer.

Trapped action

Enable macros when opening the Excel document.

Why it works

Closing period means stress and a sustained workload. Time pressure encourages people to enable macros without thinking.

Target 3: IT / CIO

Technical teams: 3 scenarios

7Email

Fake Microsoft 365 ticket

Pretext

A Microsoft 365-branded email warns of a synchronisation failure on an admin account and links to a counterfeit login page.

Trapped action

Sign in on the fake Microsoft 365 admin page.

Why it works

Admins receive technical alerts every day. Microsoft branding is widely imitated using valid SSL certificates.

8Email

Fake GitHub / GitLab pull request

Pretext

A pull request notification mentions the name of a developer known to the team and links to a fake code review page.

Trapped action

Sign in to the fake GitHub page with work credentials.

Why it works

GitHub notifications all look alike. The attacker exploits the habit of “taking a quick look between two tasks”.

9Phone (vishing)

Fake Microsoft / Cisco support

Pretext

A fake support engineer calls to announce urgent work on an incident detected on a firewall. They request remote access through AnyDesk.

Trapped action

Install AnyDesk and give the access code to the “engineer”.

Why it works

Junior IT staff do not always remember to verify the caller through the supplier's official channels.

Target 4: Executives

Executive committee and senior leaders: 3 scenarios

10LinkedIn

Fake investor request

Pretext

A LinkedIn message from a fake foreign investment fund proposes a meeting and includes a presentation PDF containing a payload.

Trapped action

Open the presentation PDF sent as an attachment.

Why it works

Ego and a business opportunity bypass caution. Corporate anti-phishing tools rarely filter LinkedIn.

11SMS / WhatsApp

Fake message from the accountant

Pretext

A text from an unknown number, signed with the accountant's name, requests an urgent transfer for a tax adjustment and includes a payment link.

Trapped action

Click the payment link and enter bank details.

Why it works

Executives use mobile devices heavily for work. An unknown number does not cause suspicion if the message is signed correctly.

12Email

Summons from an official authority

Pretext

An email impersonating the DGSI, URSSAF, or CNIL announces a summons or inspection and links to a “secure portal” where the case file can be downloaded.

Trapped action

Sign in to the “secure portal” with work credentials.

Why it works

Official authority triggers a reflexive response. Confidentiality prevents the executive from immediately discussing it with the team.

Implementation

The 4-stage method

  1. Step 1

    Scope the exercise with HR

    Confirm the scope, provide prior internal communication, obtain employee representative committee approval, and choose scenarios by role.

  2. Step 2

    Launch the campaign

    Stagger delivery over 2 to 3 weeks to prevent employees warning one another. Track clicks, entries, and reports.

  3. Step 3

    Immediately debrief employees who were caught

    Use an educational landing page (never blame people) and a short 5-minute training module focused on the missed scenario.

  4. Step 4

    Report to the executive committee and plan the next cycle

    Compare indicators with the previous campaign, identify roles at risk, and plan the next wave in 3 to 6 months.

Measure

The 4 indicators to track

  • Click rate on the malicious link (long-term target < 5%, primary indicator)
  • Rate of credential entry or attachment opening (target < 1%)
  • Active reporting rate through the “Report phishing” button in the email client (target > 30%)
  • Average time between receipt and reporting (target < 15 minutes)

Common mistakes

What undermines a campaign

  • Unrealistic or overly generic pretexts (“Nigerian prince”) that teach nobody and cause disengagement
  • No educational debrief: the simulation becomes a public humiliation
  • Public individual sanctions: they destroy any reporting culture
  • Only one campaign per year: the effect is gone after 6 months as learning fades
  • No measurement of the active reporting rate, the only indicator that really matters
Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call