A “generic” phishing campaign sent to the whole company rarely trains anyone. In contrast, role-based scenarios reveal real responses and train the people who genuinely need it. Here are 12 ready-to-use scenarios, arranged in 4 categories of 3, with their pretexts, channels, and lessons.
Method
How to read these 12 scenarios
4
Roles targeted
HR, Finance, IT, Executives
3
Scenarios per role
From the most conventional to the most elaborate
20-40%
Typical click rate
For a well-designed targeted scenario
Target 1: HR
Human resources: 3 scenarios
Fake malicious CV
Pretext
A fictitious applicant applies for a role genuinely advertised on LinkedIn, attaching a PDF named “CV_Marie_Dupont.pdf” that contains a malicious macro.
Trapped action
Open the attachment to assess the applicant before the proposed interview.
Why it works
HR teams open an average of 50+ CVs per week. Repetition reduces vigilance, and the recruitment context makes opening the file seem legitimate.
Employee bank details change request
Pretext
An email appearing to come from an employee (from a near-identical external address) asks HR to update their bank details for the next payroll, with the details attached.
Trapped action
Update the bank details in the payroll system.
Why it works
The urgency before payroll and apparent familiarity with a colleague bypass the dual-approval procedure.
Fake HR platform
Pretext
A text message in the name of the health insurer or training provider announces a mandatory employee account update before a deadline.
Trapped action
Click a link to a fake login page that collects credentials.
Why it works
The mobile channel sits outside the usual scope of technical controls such as email anti-phishing filters.
Target 2: Finance
Accounting and finance: 3 scenarios
Fake supplier invoice
Pretext
An invoice arrives from a real company supplier (identified through public information), with a discreet change of bank details at the bottom of the document.
Trapped action
Pay the invoice using the new bank details shown.
Why it works
The supplier's brand is familiar and the document looks routine. This is the most common transfer scam affecting French SMEs.
CEO fraud
Pretext
An email from the “CEO” asks the accountant to prepare an urgent, confidential transfer to complete an acquisition. A fake lawyer follows up by phone to confirm it.
Trapped action
Make a transfer of €80k to €200k without the usual management approval.
Why it works
A combination of authority, confidentiality, urgency, and two channels. It remains the costliest scam for SMEs (median: €165k).
“Draft financial statements” Excel attachment
Pretext
An email from the “statutory auditor” sends an Excel file for approval before the quarterly close. The file contains a macro that downloads an infostealer.
Trapped action
Enable macros when opening the Excel document.
Why it works
Closing period means stress and a sustained workload. Time pressure encourages people to enable macros without thinking.
Target 3: IT / CIO
Technical teams: 3 scenarios
Fake Microsoft 365 ticket
Pretext
A Microsoft 365-branded email warns of a synchronisation failure on an admin account and links to a counterfeit login page.
Trapped action
Sign in on the fake Microsoft 365 admin page.
Why it works
Admins receive technical alerts every day. Microsoft branding is widely imitated using valid SSL certificates.
Fake GitHub / GitLab pull request
Pretext
A pull request notification mentions the name of a developer known to the team and links to a fake code review page.
Trapped action
Sign in to the fake GitHub page with work credentials.
Why it works
GitHub notifications all look alike. The attacker exploits the habit of “taking a quick look between two tasks”.
Fake Microsoft / Cisco support
Pretext
A fake support engineer calls to announce urgent work on an incident detected on a firewall. They request remote access through AnyDesk.
Trapped action
Install AnyDesk and give the access code to the “engineer”.
Why it works
Junior IT staff do not always remember to verify the caller through the supplier's official channels.
Target 4: Executives
Executive committee and senior leaders: 3 scenarios
Fake investor request
Pretext
A LinkedIn message from a fake foreign investment fund proposes a meeting and includes a presentation PDF containing a payload.
Trapped action
Open the presentation PDF sent as an attachment.
Why it works
Ego and a business opportunity bypass caution. Corporate anti-phishing tools rarely filter LinkedIn.
Fake message from the accountant
Pretext
A text from an unknown number, signed with the accountant's name, requests an urgent transfer for a tax adjustment and includes a payment link.
Trapped action
Click the payment link and enter bank details.
Why it works
Executives use mobile devices heavily for work. An unknown number does not cause suspicion if the message is signed correctly.
Summons from an official authority
Pretext
An email impersonating the DGSI, URSSAF, or CNIL announces a summons or inspection and links to a “secure portal” where the case file can be downloaded.
Trapped action
Sign in to the “secure portal” with work credentials.
Why it works
Official authority triggers a reflexive response. Confidentiality prevents the executive from immediately discussing it with the team.
Implementation
The 4-stage method
Step 1
Scope the exercise with HR
Confirm the scope, provide prior internal communication, obtain employee representative committee approval, and choose scenarios by role.
Step 2
Launch the campaign
Stagger delivery over 2 to 3 weeks to prevent employees warning one another. Track clicks, entries, and reports.
Step 3
Immediately debrief employees who were caught
Use an educational landing page (never blame people) and a short 5-minute training module focused on the missed scenario.
Step 4
Report to the executive committee and plan the next cycle
Compare indicators with the previous campaign, identify roles at risk, and plan the next wave in 3 to 6 months.
Measure
The 4 indicators to track
- Click rate on the malicious link (long-term target < 5%, primary indicator)
- Rate of credential entry or attachment opening (target < 1%)
- Active reporting rate through the “Report phishing” button in the email client (target > 30%)
- Average time between receipt and reporting (target < 15 minutes)
Common mistakes
What undermines a campaign
- Unrealistic or overly generic pretexts (“Nigerian prince”) that teach nobody and cause disengagement
- No educational debrief: the simulation becomes a public humiliation
- Public individual sanctions: they destroy any reporting culture
- Only one campaign per year: the effect is gone after 6 months as learning fades
- No measurement of the active reporting rate, the only indicator that really matters
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call