SECURE_NODE // ATHENS_GR
← BACK TO RESEARCH Operation · Social Engineering

Authorized Phishing Campaign

01 JUN 2026| ≈ 3 MIN READ| PhishingRedTeamOSINT
SANITIZED ▸ This describes authorized, scoped security testing only. Phishing without explicit written authorization is illegal. No real targets, captured credentials, or client data appear here.

The technical exploits get the attention, but in many engagements the fastest path in is a convincing email. A good authorized phishing campaign is less about a clever payload and more about discipline and realism — building a pretext that matches a real workflow, measuring outcomes that actually inform a security programme, and reporting results in a way that improves posture rather than embarrassing staff.

ENGAGEMENT
Red Team
authorized · scoped
PRIMARY VECTOR
Email
pretext-driven
MEASURE
Report rate
not just clicks

Scoping comes first

Before anything is sent, the rules are agreed in writing: which addresses are in scope, what the payloads may do, how captured data is handled, and a kill-switch contact. Skipping this is not "moving fast" — it is operating without authorization. Every subsequent step depends on this document existing and being signed before Day 0.

Reconnaissance shapes the pretext

Open-source intelligence guides the lure. Public org charts, conference talks, job postings, and internal naming conventions visible in email signatures or job ads tell you who talks to whom and what routine traffic looks like. The goal is a message indistinguishable from expected internal communication — not generic "reset your password" language, but a pretext anchored in a real, recognizable workflow.

The campaign in numbers

Once the pretext is built and the landing page mirrors the expected experience, the campaign runs with staggered delivery and real-time monitoring for security control responses. These are the key metrics from a representative engagement — all lab values:

# authorized phishing campaign — scope and results (lab values)
targets:         30   (all confirmed in-scope, written authorization obtained)
vector:          email / credential harvest landing page
pretext:         IT helpdesk password expiry notification

# results after 7-day window:
click-through:   23%   (7 of 30 targets opened and clicked)
submission:       3%   (1 credential pair captured and immediately voided)
time-to-report:   4h   (first security team notification after send)
report rate:     17%   (5 targets reported the email within 24 hours)

The report rate is the metric that matters most. A 17% report rate means almost one in five recipients recognized the suspicious email and escalated it — that is the security culture working as intended. A 23% click rate is a training opportunity. A 17% report rate is a signal worth reinforcing.

The campaign timeline

DAY 0 — AUTHORIZATION

Scope signed off in writing. In-scope addresses, allowed payload behaviour, data-handling rules and a kill-switch contact agreed before anything is sent.

DAY 1–3 — RECON

OSINT on the target org. Public org charts, job postings and naming conventions mapped to identify a believable internal-traffic pattern.

DAY 4 — BUILD

Lure and landing built. Pretext matched to a real internal workflow; sender details and landing experience tuned to survive a quick glance.

DAY 5 — LAUNCH

Controlled send. Staggered delivery to in-scope targets, monitoring for technical-control responses in real time.

DAY 5–7 — MEASURE

Metrics collected. Click-through, submission rate, and — critically — time-to-report tracked per cohort.

DAY 8 — REPORT

Findings delivered. What worked, what the controls caught, and concrete awareness recommendations — framed constructively, not as a "gotcha."

Building resilience

  • Establish a clear, tested reporting path. If employees do not know how or where to report a suspicious email, even a security-aware workforce cannot protect the organization. The reporting mechanism must be practiced before the campaign, not discovered during it.
  • Measure report rate alongside click rate. Click rate identifies who was caught. Report rate identifies whether the security culture is functioning. A high report rate is a success condition — recognize and reinforce it explicitly in the debrief.
  • Debrief using the real campaign materials. Generic phishing awareness training has low retention. A debrief using the actual pretext and lure from the campaign resonates — employees remember what they were nearly tricked by, not a hypothetical example.
  • Run campaigns regularly with rotating pretexts. Phishing resilience decays between exercises. Quarterly campaigns with different pretexts and randomized cohorts produce measurable improvement over time and catch cultural drift before a real attacker does.

The takeaway

People are part of the attack surface. Testing them honestly, with consent and care, tells an organization more about its real resilience than another scanner report ever will.