Phishing & training

The two core programmes: simulate realistic attacks, then close the gaps with training.

Phishing simulations

The campaign wizard

Create a simulation from Phishing → New Campaign. The wizard walks you through six steps:

  1. Template — pick a scenario from the library (see below).
  2. Attack type — choose the mechanic (link, credential page, attachment, reply-to, or QR).
  3. Recipients — target individuals, groups, or departments.
  4. Language — English, French, or Arabic (defaults to your app locale).
  5. Schedule — send now or park it for a future time (see Automation).
  6. Review & launch — preview the exact email and victim landing page, then send.

Prefer to build your own? Enterprise plans include the Campaign Builder — a drag-and-drop composer for a fully custom phishing email, with the same tracking, QR and landing-page wiring done automatically.

The template library

AfriPhish ships 18 template families with 349 localized variants, each written natively in English, French, and Arabic (with right-to-left rendering for Arabic). Families are organised by scenario, and every variant carries brand-accurate copy — African brands (mobile money, local banks, marketplaces, telecoms, tax authorities) alongside global ones (DHL, Microsoft, Netflix).

Families span scenarios such as banking, mobile money, delivery & logistics, HR & payroll, IT & productivity, invoice/BEC, government & tax, file sharing, recruitment, e-commerce, utilities, telecom, subscriptions, travel, social, energy/industrial, regulators, and email security & gateways.

The newest family, Email Security & Gateways, impersonates the very tools employees are trained to trust — Trend Micro, Symantec, Proofpoint, Mimecast, Barracuda, Cisco Secure Email and Microsoft Defender — with quarantine-digest, "release this message" and "report a suspicious email" lures. Since staff learn to click the tool that protects their mailbox, these are among the highest-catch scenarios.

Real brand logos

For added realism, simulations embed the impersonated brand's real logo, fetched by domain at send time and inlined into the email (so it renders even when remote images are blocked). When a brand's logo can't be fetched, the template falls back to an original, brand-accurate mark — so a simulation always looks right and never depends on an external image load.

The five attack types

Every variant is built around a specific mechanic, shown as a badge in the wizard:

TypeWhat the recipient sees
LinkA tracked link to click
CredentialA branded landing page that harvests a (fake) login
AttachmentA tracked attachment to open
Reply-toA lure that invites a reply (a social-engineering style; see the note below)
QRA QR code to scan (quishing), rendered inline in the email

Reply-to is a lure type, not a tracked outcome. The reply-to variant sets a reply address to make the message feel human, but AfriPhish does not capture or score inbound replies. Use it to train awareness of reply-based social engineering; measure results on the other funnel signals.

The funnel

Each recipient is tracked through the chain, and every step is a distinct signal:

email opened → link clicked → attachment opened → credentials submitted → reported

Opening a simulated attachment is tracked separately from clicking the main link, so your metrics stay precise. These outcomes feed each person's risk score.

Campaigns and series

  • A campaign targets a set of recipients once. Drafts are editable; the status moves to Campaign Sent once every recipient's email is dispatched.
  • A series runs campaigns automatically on a recurring schedule (weekly, monthly, quarterly), optionally auto-enrolling anyone caught into training. Recurring firing depends on scheduling being configured — see Automation & scheduling.

WhatsApp channel

Campaigns can be delivered over WhatsApp instead of email, carrying the tracked link through a Meta-approved template.

Requires WhatsApp Business setup. The WhatsApp channel needs a validated Meta WhatsApp Business account and approved message templates. Until those are in place it's inert — email delivery is the default and always available.

Training

Modules

Training modules combine slides, a narrated video, and a graded quiz, available in EN/FR/AR. Learners must pass the quiz to complete a module. Assign modules manually to users or groups, set due dates, and track completion and scores.

For IT & Security teams

Beyond the awareness modules for general staff, AfriPhish ships a dedicated IT & Security training track — advanced courses (CIS Controls, PCI DSS, GDPR, DDoS defense, email security, Active Directory, firewalls and more) for IT engineers and SecOps, surfaced in their own section of the training catalogue.

Country & regulation targeting

Modules can be tagged with target countries and a regulation, so you can assign the right course for the laws that apply to each audience. Legal and data-protection courses must name at least one country. See Reports & compliance.

Assign training with a no-login link

Assigned training can be taken from a signed, no-login link — the recipient opens it and completes the course without an account. The link is single-use once the module is passed, so a completed assignment can't be replayed. This is how phished users and external staff complete remedial training with zero friction.

The phished-to-trained loop

Turn on auto-enrolment (or use a coaching rule) so anyone caught by a simulation is automatically assigned remedial training. The loop from "got phished" to "learned why" closes without manual work.

Push to your LMS (Pro+)

Already run an LMS? Push training records out via xAPI, or export any module as a SCORM 1.2 package. See Integrations.


Next: Coaching & interventions.