LabHub

Blog

AI Phishing Simulation & Security Awareness Training 2026 Deep Dive — KnowBe4, Hoxhunt, Cofense, Proofpoint Security Awareness, Infosec IQ, Mimecast Awareness, Sophos Phish Threat, NINJIO, CybSafe, Living Security

한국어English日本語

In his 1995 autobiography Kevin Mitnick wrote, "A single phone call always moved faster than any technical exploit." Thirty years later, the 2026 Verizon DBIR (Data Breach Investigations Report) still finds that roughly 68 percent of breaches involve a human element — social engineering, stolen credentials, simple mistakes.

What has changed is the cost of an attack.

In February 2024 an engineer at the Hong Kong office of British engineering firm Arup joined a video call with the head office CFO and several colleagues. Every participant was a deepfake. 25 million US dollars were wired out. The industry recognised it as a turning point.

This guide takes that turn head-on. Across 22 chapters — from KnowBe4 to GoPhish, from the NIST Phish Scale to Korean and Japanese national exercises — we tie together real tools, real incidents, and real URLs.


1. Why AI Phishing Simulation Is the 2026 Headline

Before GenAI, phishing was simple to spot. Awkward English: "Dear customer, your account has been suspended." The Korean and Japanese equivalents were even more obvious — clumsy machine translation, off-rhythm honorifics, ill-fitting Kanji.

From 2024 onward the picture changed. Reports from security research groups (SoSafe, Egress, IRONSCALES, among others) published in 2024 and 2025 consistently point to the same data.

This is the heart of it. The shift is not "AI now writes phishing as well as a human" but rather "one attacker can now target ten thousand people." That volumetric change pushed 2026 security awareness past a simple "watch your inbox" campaign and into a new paradigm built around behaviour change and human risk management.

[The 4 Layers of Security Awareness Training in 2026]
  1. Simulation         — Fake phishing emails, click-rate measurement (KnowBe4, Hoxhunt)
  2. Real-time learning  — Micro-learning modules at the moment of click (Hoxhunt, CybSafe)
  3. Behavioural analytics — High-risk user scoring (Living Security, Elevate)
  4. Threat intelligence  — Real campaign data feeding simulation updates (Cofense, Proofpoint)

Different tools fill different layers. KnowBe4 owns layers 1-2; Hoxhunt sits in 2-3; Cofense and Proofpoint dominate layer 4 alongside incident response.


2. KnowBe4 — Stu Sjouwerman and 40 Million Users

KnowBe4 (knowbe4.com) was founded in 2010 in Clearwater, Florida by Stu Sjouwerman. After selling Sunbelt Software, Stu built a company focused entirely on security awareness training. Kevin Mitnick joined as co-founder and Chief Hacking Officer in 2011 (he passed away in July 2023).

KnowBe4 wins on content library. "The Inside Man" is a self-produced drama series, and the volume of additional video and interactive modules is hard to believe coming from one company.

Pricing, as of May 2026.

Pricing varies by headcount, contract length (typically one to three years), and region. After the Vista take-private there have been some reports of price increases outside the US, but a Korean enterprise of about 1,000 employees still typically lands between 12 and 35 million KRW per year.


3. Hoxhunt — A Behavioural-Science Approach From Finland

Hoxhunt (hoxhunt.com) was founded in Helsinki, Finland in 2016 by Mika Aalto, Pyry Ahkavainen, and Ari Kesäniemi. Six years younger than KnowBe4, it arrived with a different philosophy.

Hoxhunt differentiators.

Hoxhunt outcome data is impressive. The company reports that after roughly a year, suspicious-email reporting rates reach the 50 percent range. Where KnowBe4 celebrates a low click rate, Hoxhunt celebrates a high report rate — two different behaviours.

Pricing is not publicly listed. Sources suggest 15 to 30 USD per user per year. Quote-based.


4. Cofense — Strong Incident Response Heritage

Cofense (cofense.com) was founded as PhishMe in 2007 by Aaron Higbee and Rohyt Belani. The company renamed itself Cofense in 2018.

Cofense sits in a different seat from KnowBe4 and Hoxhunt. It combines simulation, real threat intelligence, and SOC integration.

Cofense distinguishes itself through integration into SOC workflow. When a user reports a suspicious email it flows into a single chain — PhishER-class auto-triage, human SOC analyst review, automatic quarantine. That is why it is popular at organisations with 10,000-plus employees.


5. Proofpoint Security Awareness Training (Formerly Wombat)

Proofpoint (proofpoint.com) was founded in 2002 by Eric Hahn and started life as an email security gateway. In 2018 Proofpoint acquired Wombat Security Technologies, the Carnegie Mellon spin-out behind the "ThreatSim" simulation product.

Proofpoint Security Awareness Training is strong because of how it ties back into the email security backbone. TAP (Targeted Attack Protection) data on real threats flows into simulation content immediately. You can turn the actual campaigns that hit your company this week into the training simulations next week.

Pricing is not publicly disclosed, but market quotes typically land at 25 to 50 USD per user per year. The bundle becomes more attractive when email gateway and awareness training are purchased together.


6. Infosec IQ — Under Cengage

Infosec IQ (infosecinstitute.com) was founded as Infosec Institute by Jack Koziol in 2004. In 2022 Cengage Group (the education publisher) acquired the company for approximately 240 million USD, splitting the brand into Infosec Skills and Infosec IQ.

Highlights.

Infosec IQ has historically been strong with US federal and state government contracts. Explicit mapping to NIST 800-50 ("Building an Information Technology Security Awareness and Training Program") makes adoption easier inside FedRAMP and CMMC programmes.


7. Mimecast Awareness Training (Formerly Ataata)

Mimecast (mimecast.com) was founded in 2003 in the UK by Peter Bauer and Neil Murray, starting as an email security gateway. In 2019 the company acquired the Boston-based security awareness startup Ataata, folding it in as Mimecast Awareness Training.

Highlights.

The original Ataata voice survives. Their slapstick "Tom & Jerry" style security videos are polarising but tend to drive higher employee engagement, which the data backs up.


8. Sophos Phish Threat — One Package With EDR

Sophos (sophos.com) was founded in 1985 in Oxford, England by Jan Hruska and Peter Lammer. It evolved from antivirus into EDR and then MDR (Managed Detection and Response).

Sophos Phish Threat is a simulation module integrated into the Sophos Central console.

Pricing sits at 5 to 12 USD per user per year, less than half of KnowBe4. The trade-off is a thinner content library and lighter analytics. It is a strong choice for mid-market organisations that already run Sophos EDR.


9. NINJIO — One-Man-Theatre Storytelling

NINJIO (ninjio.com) was founded in 2015 in California by Zack Schuler. While most of the industry produced "educational videos," NINJIO went for "Netflix-class mini-series."

NINJIO is the security training markets premium content brand. Pricing is higher than the alternatives but differentiates on quality. By 2022 it had landed ESPN, Pfizer, and Dollar Tree as large customers.

Interactive simulation, however, is thinner. The product centres on video, which is why it often appears bundled with KnowBe4 or Hoxhunt.


10. CybSafe, Living Security, and Elevate — Human Risk Management

CybSafe (cybsafe.com) was founded in 2015 in London by Oz Alashe (a former British Army officer). It takes a clear stance: turn security awareness into security behaviour.

Living Security (livingsecurity.com) was founded in 2017 in Texas. Its platform Unify is a human risk management (HRM) hub.

Elevate Security (elevatesecurity.com) was founded in 2017 by Robert Fly, formerly head of security at Salesforce. Mimecast acquired Elevate in 2024.

The HRM category is new — it crystallised across 2023 and 2024. Gartner formally recognised it in the 2024 Magic Quadrant for the first time.


11. AwareGO, MetaCompliance, Phriendly Phishing, Curricula

Smaller but meaningful players.

Each differentiates on geography, industry, or content tone. Large multinationals lean on KnowBe4 and Proofpoint; mid-market tends to land at Sophos or Mimecast; specific industries or regions pick NINJIO, MetaCompliance, or Phriendly Phishing.


12. GoPhish — The Open-Source Phishing Simulation Standard

GoPhish (getgophish.com) is an open-source phishing simulation framework created in 2015 by Jordan Wright. Written in Go, MIT licensed.

GoPhishs value lies in red team engagements and self-driven training inside small organisations. A company below 100 employees, for which a KnowBe4 licence in the hundreds of thousands of dollars is prohibitive, can build a respectable programme on GoPhish plus self-authored content.

# Simplified GoPhish install
wget https://github.com/gophish/gophish/releases/download/v0.12.1/gophish-v0.12.1-linux-64bit.zip
unzip gophish-v0.12.1-linux-64bit.zip
cd gophish
./gophish
# Then open https://localhost:3333/

Other open-source tools.

Evilginx2 and Modlishka must only be used in authorised penetration testing or security research. They can capture real user credentials and bring serious legal exposure if misused.


13. NIST Phish Scale — An Objective Difficulty Measure

In 2020 the US NIST (National Institute of Standards and Technology) published the NIST Phish Scale, a framework for measuring the objective difficulty of a phishing email.

The NIST Phish Scale makes click-rate comparisons meaningful. If KnowBe4 reports a 5 percent click rate but the email tested as Least Difficult, that is a poor result. If the same 5 percent came from a Most Difficult email, the result is excellent.

Across 2024 and 2025 many companies adopted the NIST Phish Scale into their KPIs. Beyond raw click rate, they measure a difficulty-adjusted click rate.


14. Real Incidents — MGM, Caesars, Twilio, Lapsus

Practical cases make the case for training better than theory.

Common ground: humans were the first entry point, MFA was bypassed, and help-desk and IT staff were prime targets. In response, 2026 awareness programmes increasingly run separate training tracks for IT and SOC operators and help-desk staff in addition to general employees.


15. Deepfake Voice and Video Simulation

After Arup the market for vishing plus deepfake video simulation moved quickly.

Simulation ethics — Simulations that ask employees to wire money based on a fake CEO video call sit in an ethical grey zone. Some companies ban that type of simulation outright (employee trust, psychological impact). Others run them only with prior consent and a clear debrief plan.

Most security consultancies confine vishing and deepfake simulations to high-risk executives and finance functions.


16. MFA Fatigue and Push Notification Bombing

MFA fatigue (push notification fatigue) spiked from 2022 onward.

The official guidance in NIST SP 800-63 Revision 4 across 2024 and 2025: gradually replace push plus password with FIDO2 or passkey. South Korea KISA points in the same direction.

In awareness terms, employees need the message reinforced repeatedly: "If you did not initiate this login, never approve it." KnowBe4 and Hoxhunt both added MFA-fatigue simulation modules in 2023 and 2024.


17. Email Security Companions — Abnormal, IRONSCALES, Material, Tessian

The email security stack often ships alongside phishing simulation.

These products are API-based complements to existing gateways such as Microsoft Defender for Office 365 or Proofpoint TAP. They re-inspect mail inside the mailbox after the gateway has passed it.


18. Phishing-Resistant Authentication — Passkey, FIDO2, WebAuthn

Training has limits. Technical controls have to ride alongside.

Major adoption moments across 2024 and 2025: Microsoft Authenticator passkeys, Apple passkeys, 1Password passkeys, Bitwarden passkeys. In Korea, KakaoTalk and Naver have begun partial passkey support.

The new awareness message is not "strengthen your password" but "stop using passwords." SMS and push-based MFA is being phased out in favour of FIDO2 and passkeys.

That said, the adoption curve has friction. Device-loss recovery, guest accounts, and legacy systems all need answers. The path forward is incremental migration, not a single cut-over.


19. Compliance — NIS2, PCI DSS 4.0, ISO 27001:2022

The compliance landscape shifted significantly across 2024 and 2026.

These regulations do not just demand "do training." They expect you to measure training and improve it. That makes the simulation, report, and continuous improvement loop intrinsically compliance-friendly.


20. Korean Security Awareness Training

Korean market players and institutions.

[Sample Korean Exercise Calendar]
  KISA Cyber Crisis Response Exercise   — July to August each year, voluntary for general firms
  FSI Exercise                           — Twice per year, mandatory for financial firms
  Ministry of Defense Cyber Safety       — Military and defense industry
  Public agency internal exercises       — One to two per year per agency

Market characteristics: heavily compliance-driven. A large share of training in Korea exists as documentation for ISMS-P certification, Financial Supervisory Service inspection, or Personal Information Protection Commission audits. Large enterprises adopt foreign tools such as KnowBe4 or Proofpoint, while mid-market companies often rely on home-grown systems delivered by domestic SI firms.


21. Japanese Security Awareness Training

The Japanese market resembles Korea but with distinct flavours.

Japan in particular uses the term 標的型攻撃メール訓練. The framing is APT (advanced persistent threat) preparedness — there is a strong sense that the Japanese government, defence-related companies, and critical infrastructure are routinely targeted by Chinese and North Korean APT groups.

On the regulatory side, the 改正個人情報保護法 revised in April 2022 and the NISC (Cabinet Cyber Security Center) guidelines explicitly address awareness training.


22. What Comes Next — Behaviour Change Meets AI

Three trajectories define the future of security awareness training in 2026.

Academic research is also active.

The fundamental limit — you cannot train humans to 100 percent. The answer is the combination of awareness training and technical controls (phishing-resistant MFA, mailbox quarantine, EDR). The goal is not to turn the weakest link into the strongest link, but to build systems that survive human error without catastrophic loss.


Epilogue — From Mitnick to GenAI, 30 Years of Lessons

In his 2002 book "The Art of Deception," Kevin Mitnick wrote:

"The weakest link in security is the human being. And the strongest line of defence is also the human being."

Thirty years on, in 2026, the thesis holds. The change is in the attackers toolkit. GPT-4 writes English-native BEC mail at 0.001 USD per piece, and ElevenLabs clones a CEO voice in three minutes. Arups 25-million-dollar incident was the inflection point.

The defenders answer is clear.

And the most important piece — a no-blame culture. Shaming employees who clicked depresses reporting rates. That is exactly why Hoxhunt insists on its "no gotcha" framing and why NINJIO leans into cartoon-style characters.

Another Mitnick line worth keeping.

"However advanced technology becomes, a single phone call or email is still the fastest path."

It is still true in 2026. The only difference is that the phone call and the email are now generated by AI.


References

Comments

No comments yet.

Sign in to leave a comment