Read articles about security awareness, risk management, behavior change, and more
How quishing is being used in attacks, what these threats look like in the wild and best practices for avoiding them.
Frost & Sullivan spotlighted Hoxhunt for transforming human risk in cybersecurity. Their report shows a 225% increase in phishing reporting and 3X fewer clicks.
Here's what real Hoxhunt customers say about the platform. A deep dive into simulations, reporting, quality of support and more.
Repeat phishing offenders aren’t the problem... static training is. Learn how we use adaptive simulations to convert clickers into security assets.
This playbook will guide you through the essential email security best practices you need to know to educate employees, mitigate risks, and protect your organization.
Your ultimate guide to the process behind social engineering training and all of the tips and know-how you need to ensure your training successfully changes behavior.
Gamified cyber security training is a scientifically proven method to boost user engagement and motivate them to change behavior and build cyber skills continuously.
Fantasy football can teach us how to learn stop worrying and love the art and chaos of starting a new leadership position.
Recent research published in the wall street was correct: bad phishing simulations produce bad results. So what now?
The CISO Fantasy Phish Bowl 2025 brings together some old friends and new joiners. There's one heavy absence: Shawn Bowen, to whom this year's Phish Bowl is dedicated. Here's to you, Shawn!
Phishing simulation best practices with real case results from Bird & Bird - ethical lures, instant feedback, and KPIs that drive reporting.
Best phishing simulation tools for enterprises (2025) - AI-powered, gamified platforms with multi-vector realism, SOC integrations, and risk dashboards.
Cybersecurity Awareness Month ideas that work: run a focused 10-day campaign, launch phishing simulations, boost MFA adoption, and use our 2025 toolkit.
Why cyber insurance needs human risk management platforms and so do you
Your ultimate guide on how to prevent phishing. Everything you need to know to implement best practices and set up training that measurably reduces risk.
Your ultimate guide to spam vs phishing. What the differences are, how to recognize them and all of the practical measures you can take to keep your organization safe.
What is an SOC report? What are the different types of SOC reports available? How do you obtain one? Your questions answered.
We'll look into the behaviors to watch out for, how to assess risk and all the strategies you need to tangibly reduce human risk across your organization.
Here's how to change the narrative around cybersecurity to get employees engaged.
How do you achieve cybersecurity behavior change? A breakdown of how science-based training transforms awareness into real-world risk reduction.
Learn how behavior-based cyber security training drives lasting employee behavior change. A breakdown of the key components, benefits, and why it’s essential for building a strong security culture.
Discover how Hoxhunt outperforms competitors in cybersecurity training. Based on real reviews, compare Hoxhunt's features, quality, and effectiveness to leading alternatives.
Empower your team to be a human firewall. Discover how training, vigilance, and smart habits protect against cyber threats.
Password protected attachments can evade spam filters and raise users' curiosity and trust
Updated from its 2021 version, the 2022 spoofed US Department of Transportation credential harvesting site is extremely effective
Pretexting a form of phishing that hooks victims with a simple but convincing message without malicious links.
Breaking the phishing attack kill chain requires understanding the three steps that drive its process, and the five most common effects of a successful attack.
Fax phishing uses fake email notifications spoofing e-fax services to trick people into entering sensitive data onto credential harvesting pages
The war in Ukraine has spawned two widespread types of phishing campaigns we're monitoring. Here are three ways to spot them.
We train our users to always hover over links in emails and to validate the domain where the links points to. This can’t be trusted if you are using Microsoft Edge to view your emails in Office 365.
Vishing attacks are spiking, and they’re powered by AI voice clones and social engineering. Here's how to prevent vishing with real-world tactics and simulation-based training.
From Spear-Phishing, to Credential Harvesting, To Possible Ad Fraud. Keep Reading To Find Out How This Story Unfolded and How You Can Avoid Getting Caught.
We're seeing an uptick in social engineers targeting social media accounts
Now that cookies are on their way out, a much sneakier way of identifying you is on its way in.
Years later, pop-ups are back, this time serving a different purpose... stealing your info.