United States
Phishing simulation for US
tax, M365 and callback lures.
In the US, employees face tax-agency refund and audit lures, parcel-delivery texts, Microsoft 365 password-expiry emails and callback invoices that push them to phone a fake support line.
- Regulators & frameworks
- HIPAA, PCI DSS v4.0.1, NYDFS Part 500, FTC Safeguards Rule, NIST SP 800-50 Rev. 1
- Channels to rehearse
- Email, voice calls, SMS, Microsoft Teams and Slack
- Local lure patterns
- Tax-agency notices, parcel delivery, M365 password expiry, callback invoices
- KeenSec evidence
- Simulation results, reporter logs, certificates, policy acknowledgements
Simulated US lures
Taxes, passwords and invoices:
the pretexts to rehearse.
Simulated examples of tax, password and invoice lures common in the US, including one with no link at all.
IT Service Desk · it-support@m365-account.example
Your Microsoft 365 password expires today
Keep your current password by confirming your sign-in below. Accounts not confirmed will be locked at 5 pm.
Keep my password- Look-alike domain
- Lockout deadline
Billing desk · invoices@renewals.example
Invoice #88213: annual plan renewed
Your card has been charged for an annual subscription. If you did not authorise this, call our billing team to cancel.
- No link, just a phone number
- Charge you don’t recognise
Regulators and frameworks
The US frameworks
your evidence supports.
| Framework | Applies to | KeenSec evidence |
|---|---|---|
| HIPAA | Covered entities and business associates handling health information | Security awareness training records, simulation results, policy acknowledgements |
| PCI DSS v4.0.1 | Organisations that store, process or transmit cardholder data | Requirement 12.6: training on hire and every 12 months, including phishing and social engineering |
| NYDFS 23 NYCRR 500.14(a)(3) | Financial services firms regulated by New York DFS | At least annual awareness training that includes social engineering, for all personnel |
| FTC Safeguards Rule, 16 CFR 314.4(e) | Non-bank financial institutions under FTC jurisdiction | Security awareness training updated for the risks you identify |
| NIST SP 800-50 Rev. 1 and SP 800-53 AT-2(1) | Organisations building a learning programme | Guidance naming phishing, smishing and vishing simulations as practical exercises |
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
Questions buyers ask
Frequently asked questions.
Which US frameworks does KeenSec help with?
KeenSec helps produce awareness evidence for HIPAA, PCI DSS v4.0.1 Requirement 12.6, NYDFS Part 500, the FTC Safeguards Rule, NIST SP 800-50 Rev. 1 and ISO/IEC 27001:2022. Your auditor decides compliance.
Can we simulate callback phishing?
Yes. KeenSec sends a link-free invoice email and connects the call to an IVR or agentic AI voice agent, then records who shared details and who reported.
Can we simulate Microsoft 365 password-expiry lures?
Yes. Credential-capture scenarios lead to a realistic sign-in page built for the test, and anyone who submits sees a just-in-time lesson straight away.
Let’s connect the dots
Rehearse the email and the call.
Prove it at audit.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo