Phishing simulation

Build controlled bait campaigns to measure and train your team's behavior, over email, QR Code or SMS.

Overview

The phishing module sends simulated bait to employees and measures who opens, who clicks and who reports, all with no real risk. The results feed the Human Risk Score and trigger targeted training for the people who need it most.

List of phishing campaigns in the qlture dashboard
Phishing → Campaigns: click rate, sent count, who clicked and who reported, all per campaign.

Every campaign picks a vector (delivery channel):

Vector Channel Tracking Doc
Email Email with link/attachment Per target this page
QR in email QR Code embedded in the email Per target Quishing
QR poster Printed physical poster Anonymous (collective) Quishing
SMS Text message Per target Smishing

Anatomy of a campaign

Phishing campaign editor
The campaign editor: vector selector at the top, the four steps on the left and the live preview on the right.

The campaign editor walks you through four steps:

  1. Bait: the email subject and body, or the composer for the channel you chose. Use the placeholders below.
  2. Landing is the page the target sees after clicking, for example a fake login or an immediate educational page.
  3. Audience — who receives it: everyone, groups, departments or specific users.
  4. Schedule: when to send, plus the campaign window.

Placeholders

In the bait body you have tokens that the platform substitutes per target:

  • {{link}} — the recipient’s individual trackable link.
  • {{qrcode}} — a trackable QR Code (for quishing campaigns).

Each target gets a unique token, so open, click and report tracking is individual.

What gets measured

For each target, over the course of the campaign:

  • Sent → Opened (tracking pixel in the email) → Clicked (the link/QR) → Reported (if the person flagged the bait).
flowchart LR
  S[Sent] --> A[Opened]
  A --> C[Clicked]
  A --> R[Reported]
  C --> L[Educational page]
  classDef good fill:#3ddc97,stroke:#3ddc97,color:#070a0e;
  classDef bad fill:#ff3d71,stroke:#ff3d71,color:#ffffff;
  class R good
  class C bad

Reporting is the desired behavior (green); clicking is what you want to reduce (red).

Results screen for a phishing campaign
Campaign results: the funnel (sent → opened → clicked → reported), click rate vs. target, breakdown by department and status per employee.

Reporting is the desired behavior, and it connects to PhishER, which handles the emails employees actually report.

SMS and posters have leaner tracking: SMS has no open pixel and no report; the poster is anonymous by nature. Each channel doc covers this in detail.

Sender profiles

You configure reusable sender profiles (like SMTP profiles): domain, sender and provider. The campaign chooses which profile to use. SMS has its own profiles with provider selection; see Smishing.

Email sender profiles in the qlture dashboard
Phishing → Senders: sending profiles reusable across campaigns.

Pick a channel

  • Quishing — QR Code in the email or on a physical poster.
  • Smishing — bait over SMS.
  • PhishER — what to do when an employee reports a real email.

Points and achievements
Quishing (QR Code phishing)