Anyone can fall for a phishing scam. The Phishingator service from the CESNET association offers safe training
Interview with Aleš Padrta, Head of the CESNET Forensic Laboratory
CESNET has been conducting simulated phishing tests since 2017. These initial tests gradually evolved into the Phishingator service, which today enables organizations to create their own simulated campaigns and educate users in a secure environment. We spoke with Aleš Padrta about how the service came to be, what has changed over the past nine years, why it makes sense to supplement training with hands-on experience, and why any one of us can fall victim to phishing.
Why do you think phishing is so effective?
Phishing is designed to trigger a quick, instinctive reaction in us. It can play on fear, time pressure, curiosity, or even the fear of missing out on something. I experienced this myself back when I was working at the university. We repeatedly received fraudulent emails claiming that the recipient owed money and was facing debt collection proceedings. The details were supposedly in the attachment. I explained to dozens of users that it was a scam. And then the same email arrived for me.
Of course, I knew it was fake. But at that moment, thoughts started racing through my head: the bailiff, losing my apartment, what would happen to my cat… You know exactly what’s going on, and yet your instinct compels you to click. There’s a huge difference between evaluating such a message from a distance and receiving it directly yourself.
What can help us prepare for such a situation?
Theoretical training helps us recognize phishing, but it doesn’t fully prepare us for a situation where such a message actually lands in our inbox. That’s exactly why it makes sense to supplement it with so-called simulated phishing. This allows us to practice a similar situation in a safe and controlled environment, where any mistakes we make have no consequences.
Who might fall for simulated phishing?
Any one of us. Sometimes we simply succumb to the pressure of the moment. You arrive at work tired, you’re dealing with a sick pet, you’re thinking about the weekend, or you’re just trying to quickly take care of some paperwork before your first cup of coffee. And it’s precisely at that moment that a message arrives that catches your attention or worries you.
That’s why, in my opinion, it’s not right to view the results of a phishing campaign as a list of people who made a mistake. What’s important is that next time, they’ll be able to recognize a fraudulent message.
Can reactions to simulated phishing still surprise you?
After all these years, very little surprises me anymore. We’ve encountered all kinds of reactions. But one campaign really stuck with me. We prepared a message for a client that offered the chance to receive up to 5,000 crowns extra per month from a European “productivity fund.” The target group consisted of roughly 110 people. Ten, twenty, forty, eighty, a hundred people gradually entered their login credentials… In the end, there were around 190. Of course, that didn’t add up for us. It turned out that a secretary had forwarded the message to all employees in good faith. She thought it would be a shame if they missed out on the money. And when your assistant forwards a similar email with a recommendation that you respond to it, its credibility increases significantly.
To make the messages seem credible, we base our campaign preparation on the specific organization’s environment, publicly available information, and current events. In Pilsen, for example, just before St. Martin’s Day, we offered the first hundred people who signed up a free St. Martin’s goose dinner at the university cafeteria. Here at CESNET, during a 40-degree heat wave, an email arrived urging employees to confirm their eligibility for “heat-related leave” in the HR system.
Have you noticed a shift in how people react to phishing during repeated campaigns?
Yes, and it’s quite significant. In the first campaign, about 20% of recipients typically fall for our simulated phishing attempt. When we repeat it six months later, for example, that number drops to just 2–5%. The positive impact is thus evident at first glance. It’s also interesting that some campaigns take on a life of their own within organizations long after they’ve ended. For example, people have been telling the story about the St. Martin’s Day goose for many years now. Even a story like that serves as a reminder that phishing exists and that people need to be cautious.
What do simulated campaigns offer an organization, and how can it apply the results in practice?
Personal experience helps users better defend against phishing. More resilient employees, in turn, contribute to the security of the entire organization. At the same time, the campaign shows the organization where it stands at that moment. The results can be used in risk analysis and in deciding whether the current level of risk is acceptable or whether additional measures are needed, such as further user training. Regularity is also important. Attention naturally wanes over time, so it makes sense to revisit simulated phishing, perhaps once a year.
When you compare phishing messages from 2017 with those of today, what has changed the most?
When it comes to actual phishing emails, they’ve changed significantly. Our relatively complex language no longer shields us from the rest of the world, so gone are the days of poor Czech and salutations like “dear customer.” Today, perfect translations can be achieved using translation tools and artificial intelligence. It’s also possible to gather information about the target recipients online—for example, on social media or from a company’s website—and thus easily craft a more targeted email. So users have it a bit harder now than they used to. However, it’s still possible to spot a scam if they don’t let themselves get too stressed out.
How did you at CESNET actually get into simulated phishing?
At the time, we were providing penetration tests focused primarily on assessing the technical condition of IT infrastructure. But customers began coming to us with a logical question: “Okay, our technical equipment has been tested, but what about the people operating it? Can our IT staff, administrators, and users resist manipulation?” Based on their suggestion, we therefore developed the Phishing Tests service. We wanted the name itself to make it clear that this is similar to penetration testing, only this time focused on people.
It gradually became clear that sending users a single practice phishing email without any context wasn’t enough. So we added an introductory training session on what phishing is and how to recognize it. This resulted in a comprehensive package: theoretical preparation, a practice phishing email sent directly to users’ inboxes, and a follow-up evaluation with a final report for the client.
Have you used Phishingator for these campaigns yet?
Not yet. But even back then, we needed a technical solution that would allow us to send out test messages and evaluate the results. So we used an in-house system made up of various components. We tracked who the message was sent to and whether it bounced back as undeliverable. We also recorded whether the user replied to it, visited the linked page, or entered anything on it. We were able to distinguish whether the information entered was valid login credentials or, for example, just a funny message to the supposed cybercriminals.
It worked for our purposes. But it certainly wasn’t a tool we could give to customers for them to use on their own.
So what led you to develop Phishingator itself?
Once again, it was our customers who led us to it. They told us: “We can handle the theoretical training on our own. We’re in an academic setting, and we have plenty of talented educators. But sending out simulated phishing messages and evaluating the results is technically complex. We’d like to run these campaigns more often, and we don’t want to wait for our turn every time.” And that’s when the basic idea was born: let’s give organizations a tool they can use to prepare simulated phishing campaigns on their own.
And how did that idea turn into a finished tool?
That’s where Martin Šebela comes in. At the time, I was still working part-time at the university. One day, I was sitting in my office answering emails when someone knocked. A student appeared in the doorway and said: “Hello, I’m Martin Šebela. I’m interested in phishing, and the department told me you’re the expert here. Could I send out some phishing emails as part of my term paper?” One thing led to another, and after some time, his bachelor’s thesis, Phishingator, was born, building on this idea.
It took about two more years before Martin joined CESNET, and his bachelor’s thesis evolved into a full-fledged open-source tool. Today, we also offer it as a service—Software as a Service.
How does Phishingator work today?
Currently, 24 customers use it (ranging from universities to research institutions). We customize the setup for each customer at the beginning. For example, we upload a list of users and prepare practice login pages that mimic the appearance of the real ones. After that, customers can create campaigns on their own. And importantly, they can do so without any restrictions. At CESNET, our primary focus is on educating users and raising security awareness. That’s why we don’t have a licensing model where you “pay for every email sent” or “pay for every user.” The service has a fixed monthly fee, and organizations can then create campaigns according to their needs.
Do you still remember Phishingator’s first customer?
Of course. It was the Aviation Research and Test Institute (VZLÚ). The first deployment always brings something you can’t anticipate in advance, no matter how hard you try. But thanks to the enthusiasm on both our side and VZLÚ’s, we managed to overcome all the difficulties, and the institute still uses Phishingator to this day.
What new features have been added to Phishingator, and what are your plans for the future?
We’re continuously developing Phishingator. Since the original version, for example, we’ve added the ability to include parameters in messages, such as the recipient’s email address, first and last name, or the current date. We also have more options for customizing the appearance of the phishing link. And let’s not forget that, in addition to plain-text emails, Phishingator can also send HTML messages. This allows us to use tables, colors, “click here” links, and everything else users are accustomed to seeing in regular emails.
Martin is currently working on the ability to insert a QR code into messages instead of a link—in other words, simulating what’s known as “quishing.” In the future, we’d like Phishingator to be able to send SMS messages as well, simulating “smishing.” We’d also like to focus on other channels of electronic communication. We’ll see what users want and where the world is headed in a few years.
Where can interested parties learn more about Phishingator?
Just get in touch with us. We’d be happy to schedule an online meeting with them. And on October 1, we’ll also be featuring Phishingator at a workshop as part of the CESNET e-Infrastructure Conference. We’ll discuss what Phishingator has learned over the past year, current trends in phishing, and user experiences. The on-site workshop is already at capacity, but we’ll also be streaming it online, so anyone can join.
Thank you for the interview.