// KNOWLEDGE BASE

LEARN THE SIGNALS

PHISHING

Fraudulent messages designed to manipulate you into taking an unsafe action.

SPEAR PHISHING

Targeted phishing built with personal or organizational context.

SMISHING

Social engineering delivered through SMS or messaging apps.

QUISHING

QR codes used to hide a destination or move an attack onto a phone.

BEC

Business email compromise uses trusted business relationships and authority.

MFA FATIGUE

Repeated authentication prompts attempt to wear down the target.

LOOKALIKE DOMAINS

Small domain changes can make an attacker appear familiar.

HTTPS ≠ TRUST

Encryption protects a connection; it does not prove the site is legitimate.

OSINT

Public information can supply the context needed for convincing pretexts.

AI IMPERSONATION

Generative AI can improve language, personalization, voice and visual impersonation.

URGENCY

Artificial deadlines reduce the time people spend verifying a request.

SAFE VERIFICATION

Use a known, independent channel rather than contact information supplied by the suspicious message.

// TRAINING_METHODOLOGY.TXT□ ×

How PHREAKSAFE approaches awareness

Challenges are designed around evidence, context, and proportionate response. The goal is not to teach that every unexpected message is malicious; it is to build habits such as independent verification, domain inspection, authentication safety, careful data handling, and resistance to urgency or authority pressure.

Legitimate scenarios are deliberately mixed throughout the same categories as suspicious ones. Some legitimate, high-consequence requests still require independent verification, so neither “trust everything” nor “report everything” is a winning strategy.