Trusted by 200+ security teams

Your employees get phished. Train them before attackers do.

PhishIQ runs AI-generated attack simulations across email, voice calls, SMS, QR codes, calendar invites, and chat messages — then turns every interaction into a learning moment. Real attacks are multi-vector. Your training should be too.

14-day free trialNo credit card requiredM365 ready

Security teams at these organizations run PhishIQ

Fortune 500 Healthcare
Global FinTech
US Federal Agency
EMEA Manufacturer
APAC Telecom
Big 4 Consulting
62%
average reduction in phish click rate
3.4x
increase in employee reporting
<2 min
median time to report suspicious email
21+
AI-generated attack templates

Phishing isn't a technology problem.
It's a people problem.

91% of cyberattacks start with a phishing email. Firewalls and filters catch a lot — but the ones that get through land in your employees' inboxes. The question isn't if a phishing email will reach your people. It's whether they'll recognize it when it does.

Attacks are getting smarter

AI-generated phishing emails bypass traditional filters with perfect grammar and personalized context.

Email isn't the only vector

QR codes in lobbies, fake OAuth prompts, MFA fatigue attacks — the threat surface keeps expanding.

Compliance needs evidence

Auditors want proof your people are trained. Spreadsheets and annual click-throughs don't cut it anymore.

Platform

Everything you need to turn employees into your strongest defense layer

AI Engine

AI-generated attack simulations

Our template engine generates realistic phishing emails across 21+ patterns — from CEO wire-transfer requests to fake SharePoint notifications. Four difficulty levels. Five department personas. Every template feels like the real thing because it's built on the same techniques real attackers use.

Adaptive difficultyPersona targeting21+ attack patternsSpear phishing
AI Template Generator
Microsoft 365 — Password ExpiryDifficulty: Hard
Your password expires in 24 hours. Click below to update your credentials and avoid account lockout...
CEO — Urgent Wire TransferSpear Phishing
I need you to process this payment before end of day. I'm in a meeting and can't call. Use the attached instructions...
HR — Benefits Open EnrollmentDifficulty: Medium
Open enrollment closes Friday. Review and confirm your benefits selections to avoid losing coverage...
Beyond Email

QR codes, OAuth, MFA — not just inbox attacks

Most platforms stop at email. We simulate the full threat surface: QR code phishing in lobbies and cafeterias, fake OAuth consent screens, MFA push-fatigue attacks, and malicious browser extensions. Because attackers don't limit themselves to email, and your training shouldn't either.

QR code phishingOAuth consent attacksMFA fatigue simulationBrowser extensions
Attack Vectors
QR Phishing
5 scenarios
OAuth Consent
Fake app prompts
MFA Fatigue
Push bombing
Credential Harvest
8 landing pages
Real-Time

Live threat map and SOC console

Watch campaigns unfold in real time. The threat map plots clicks and credential captures across your global offices as they happen. The SOC console gives your analysts a purpose-built view — not a recycled admin dashboard with a different label on it.

Geographic visualizationLive activity feedSOC-readyInstant alerts
Live Threat Map
12.4
Events/sec
3 campaigns
Active
2 critical
Alerts
Adaptive Training

Training that responds to behavior

Clicked a phishing link? You're immediately enrolled in targeted micro-training. Reported it correctly? You earn points on the leaderboard. PhishIQ adapts to each employee — the repeat clickers get more coaching, the security champions get harder challenges.

Auto-enrollmentGamified learningBehavioral scoringLeaderboards
Adaptive Learning Path
SC
Sarah Chen
Completed phishing basics
Shield Bearer
Score: 92
MT
Mike Torres
Auto-enrolled after click
In Training
Score: 45
LP
Lisa Park
Advanced module unlocked
Phish Spotter
Score: 88
Risk Analytics

Human risk scores that actually mean something

Every employee gets a dynamic risk score based on clicks, credential submissions, report speed, and training completion. Slice it by department, location, or manager. Track trends over quarters. Give your CISO a number they can take to the board — not a 40-page PDF nobody reads.

Dynamic risk scoringDepartment benchmarkingTrend analysisBoard-ready reports
Risk Score Dashboard
23
Critical risk users
847
Low risk users
Finance
72
Engineering
31
Sales
58
Legal
24
M365 Native

Built for Microsoft 365 from day one

Azure AD SSO. Automatic user sync via Microsoft Graph. An Outlook add-in that puts "Report Phishing" right in the ribbon. No clunky SCIM connectors, no CSV imports, no third-party middleware. If you run M365, PhishIQ just works.

Azure AD SSOAuto user syncOutlook add-inGmail add-on
Microsoft 365 Integration
Azure AD Sync
1,247 users synced
Last sync: 2 min ago
Outlook Add-in
Report Phishing button installed
Active
Teams Webhook
#security-alerts channel
Connected
SSO
Azure AD SAML 2.0
Enabled

Attack Surface

12 attack vectors. One platform.

Attackers don't limit themselves to email. Your simulations shouldn't either. PhishIQ covers every vector your employees will face in the wild.

Email Phishing

AI-generated emails across 21+ patterns with adaptive difficulty and persona targeting.

Coming Soon

Deepfake Vishing

AI-cloned voice calls that simulate managers or vendors. Real-time interactive conversations — not pre-recorded scripts.

Coming Soon

SMS / Smishing

Simulated text message attacks — package delivery scams, fake MFA codes, IT support alerts. The vector 76% of orgs are hit by but only 32% train for.

QR Code Phishing

Physical and digital QR codes in lobbies, emails, and signage. Five pre-built scenarios with scan tracking and mobile preview.

Coming Soon

Calendar Invite Attacks

Phishing disguised as meeting invitations in Outlook and Google Calendar. Exploits the trust people place in their own calendar.

Coming Soon

Teams & Slack Phishing

Simulated attacks via internal messaging. Employees trust chat more than email — attackers know that.

OAuth Consent Attacks

Fake app permission screens that trick users into granting access to their account data.

MFA Fatigue Attacks

Push notification bombardment that wears down employees until they hit 'Approve.' Tests your last line of defense.

Coming Soon

Callback Phishing

Emails that prompt employees to call a fake support number. Bypasses email filters entirely since the payload is a phone number.

Coming Soon

Multi-Vector Chained Attacks

Single campaigns that chain email + SMS + voice call into one coordinated storyline. Because real attackers don't stick to one channel.

Credential Harvesting

Eight realistic landing page clones — M365 login, SharePoint, VPN portal, HR benefits, and more.

Coming Soon

Browser Extension Exploits

Simulated malicious extension installs that test whether employees blindly grant browser permissions.

Intelligence

Roadmap

Automated, adaptive, always current

Where we're headed next. PhishIQ will connect to real-world threat intelligence, adapt to each employee, and answer your questions in plain English.

01

Threat-Intel-Synced Templates

When your email filter detects a new phishing style in the wild, PhishIQ auto-generates a matching simulation template within hours. Your training is always synchronized with what attackers are doing right now — not what they were doing last quarter.

Live Threat Feed
2m ago
New DocuSign impersonation wave
Template generated
18m ago
SVG attachment payload variant
Under review
1h ago
Calendar invite credential steal
Campaign ready
3h ago
Fake Zoom SSO redirect
Deployed to 3 campaigns
02

Continuous Drip-Feed Simulation

Stop running quarterly campaigns that everyone sees coming. PhishIQ drip-feeds simulations to individual employees on randomized schedules — daily, weekly, or custom cadences. Training becomes ambient, not an event. Employees can't warn each other because everyone gets different attacks at different times.

Simulation Schedule (This Week)
Mon
Tue
Wed
Thu
Fri
EmailVoiceSMSQRCalendar
03

Ask PhishIQ — Natural Language Analytics

Type a question in plain English and get an instant answer with charts. "What should I brief the board on?" "Which department improved most this quarter?" "Show me repeat clickers in Finance." Your CISO doesn't need to learn a dashboard — the dashboard learns what they need.

Ask PhishIQ
"What trends should I brief the board on this quarter?"
Key findings for Q1 2026:
Overall phish rate dropped from 11.2% to 4.1% (-63%)
Finance dept improved most: 23% to 6% click rate
Voice phishing (vishing) has highest failure rate at 31%
12 repeat offenders need escalated training

Business Impact

Roadmap

Speak the language your board understands

Where we're investing next. Dollar-denominated risk, insurance evidence, and compliance automation — coming to PhishIQ soon.

Coming Soon
$4.88M
avg. cost of a phishing breach (IBM 2025)

Dollar-Denominated Risk Dashboard

Translate click rates into financial exposure. "$2.3M annualized phishing risk in Finance" hits different than "32% click rate" in a board meeting. PhishIQ maps human risk scores to actual dollar figures using industry breach cost data.

Coming Soon
10-20%
insurance premium reduction with documented training

Cyber Insurance Evidence Packs

Auto-generated PDF reports showing training effectiveness, risk reduction trends, and compliance coverage — formatted specifically for insurance underwriters. Organizations with documented training programs see 10-20% premium reductions. PhishIQ packages the evidence so you don't have to.

Coming Soon
6
compliance frameworks with auto-generated evidence

Compliance Framework Packs

Pre-mapped training modules for HIPAA, PCI-DSS, CMMC 2.0, NIST 800-171, GDPR, and SOC 2. Each module generates audit-ready evidence tied directly to specific control requirements. CMMC Phase 2 assessments start November 2026 — 220,000 contractors need this.

Coming Soon
40-60%
improvement in retention vs. one-time training

Spaced Repetition Engine

Training timed to the Ebbinghaus forgetting curve. Employees see refreshers right before they'd forget — not on an arbitrary quarterly schedule. Research shows 40-60% better retention compared to one-time training sessions.

How It Works

From setup to measurable risk reduction in under a week

01

Connect your directory

Plug in Azure AD or upload a CSV. PhishIQ auto-syncs users, departments, locations, and managers. Takes about 5 minutes.

02

Build or generate campaigns

Pick from 21+ AI-generated templates or write your own. Set the difficulty, choose your audience, schedule the send. A/B test variants if you want data on what tricks your people.

03

Watch, measure, respond

Track opens, clicks, credential captures, and reports in real time. The SOC console surfaces high-risk activity. Slack and Teams alerts keep your team in the loop without tab-switching.

04

Train the ones who need it

Employees who click get auto-enrolled in targeted micro-training. Those who report correctly earn points. Risk scores update dynamically. Over time, your phish rate drops and your report rate climbs.

Comparison

How we compare to the market

Based on publicly available feature lists and pricing from leading phishing simulation vendors. We built the features security teams actually need — without the enterprise markup.

FeaturePhishIQ
Legacy Leader
Large content library
Email Security Suite
Bundle-focused
Adaptive Platform
Gamification-first
AI-powered template generationAdd-on
QR code phishing simulationsLimitedLimited
OAuth / MFA fatigue landing pagesLimited
Real-time threat map & SOC console
Behavioral risk scoringBasic
Gamified training + leaderboardsBasic
Native Outlook & Gmail add-ins
Azure AD SSO + auto-sync
A/B campaign testing
Executive reporting & audit logsBasic
Self-hosted / on-prem option
Deepfake voice phishing (vishing)Q3 2026Limited
SMS / smishing simulationsQ3 2026Limited
Calendar invite phishingQ3 2026
Teams / Slack message phishingQ3 2026Limited
Multi-vector chained attacksQ4 2026
Callback phishing simulationsQ3 2026Add-on
Continuous drip-feed modeQ3 2026
Threat-intel-synced templatesQ4 2026
Natural language analytics (Ask AI)Q4 2026
Dollar-denominated risk dashboardQ4 2026
Cyber insurance evidence packsQ4 2026
Compliance framework packs (6+)Q3 2026Basic
Spaced repetition engineQ3 2026
Typical cost (per user/year)$12–32$18–39$24+$58+

Comparison based on publicly available information as of March 2026. Competitor columns represent typical capabilities across market categories, not specific vendors. Actual features may vary by plan and vendor.

Pricing

Transparent pricing. No surprise add-ons.

Every plan includes unlimited simulations. Pay per user, billed annually. Volume discounts at 500+ seats.

Starter

For teams getting started with phishing simulation.

$12per user / year
Start Free Trial
  • Unlimited email phishing campaigns
  • 10 pre-built templates
  • Email open & click tracking
  • Basic risk scoring
  • Training library (core modules)
  • CSV user import
  • Email support
Most Popular

Professional

Multi-vector simulation for security-conscious orgs.

$22per user / year
Start Free Trial
  • Everything in Starter, plus:
  • AI template generator (21+ patterns)
  • QR code phishing (5 scenarios)
  • A/B campaign testing
  • Full LMS with gamification
  • Outlook & Gmail add-ins
  • Slack & Teams webhooks
  • Azure AD sync
  • Department risk benchmarking
  • SMS / smishing simulationsSoon
  • Calendar invite phishingSoon
  • Callback phishingSoon
  • Continuous drip-feed modeSoon
  • Spaced repetition schedulingSoon
  • Priority support

Enterprise

Full attack surface coverage, real-time ops, and compliance.

$32per user / year
Start Free Trial
  • Everything in Professional, plus:
  • OAuth & MFA fatigue simulations
  • Live threat map & SOC console
  • Executive reporting & audit logs
  • Azure AD SSO (SAML)
  • Self-hosted / on-prem option
  • Dedicated account manager
  • Deepfake voice phishingSoon
  • Teams & Slack message phishingSoon
  • Multi-vector chained attacksSoon
  • Threat-intel-synced templatesSoon
  • Ask PhishIQ (NL analytics)Soon
  • Dollar-denominated risk dashboardSoon
  • Cyber insurance evidence packsSoon
  • Compliance packs (6 frameworks)Soon

Need 10,000+ seats or on-prem deployment? Talk to our team for custom pricing.

What Security Teams Say

From security teams in the trenches

We ran our previous vendor for three years and our click rate plateaued at 12%. Six months after switching to PhishIQ, we're at 4.2%. The adaptive difficulty and multi-vector coverage is the difference.

RN
Rachel Nguyen
CISO, Series D FinTech

The QR code simulations caught us off guard — in a good way. 38% of our office staff scanned a fake 'WiFi portal' QR code. That's exactly the kind of blind spot we needed to find.

JO
James Okafor
Director of Security Ops, Healthcare Provider

My auditors asked for evidence of phishing training across 14 global offices. I exported one report from PhishIQ and we were done. That used to take my team a full week.

PS
Priya Sharma
GRC Lead, Manufacturing Conglomerate

Your next phishing attack is already being crafted.
Make sure your people are ready.

Start a free 14-day trial. Run your first campaign in under an hour. No credit card. No sales call required.