United States

Phishing simulation for US
tax, M365 and callback lures.

In the US, employees face tax-agency refund and audit lures, parcel-delivery texts, Microsoft 365 password-expiry emails and callback invoices that push them to phone a fake support line.

Regulators & frameworks
HIPAA, PCI DSS v4.0.1, NYDFS Part 500, FTC Safeguards Rule, NIST SP 800-50 Rev. 1
Channels to rehearse
Email, voice calls, SMS, Microsoft Teams and Slack
Local lure patterns
Tax-agency notices, parcel delivery, M365 password expiry, callback invoices
KeenSec evidence
Simulation results, reporter logs, certificates, policy acknowledgements

Simulated US lures

Taxes, passwords and invoices:
the pretexts to rehearse.

Simulated examples of tax, password and invoice lures common in the US, including one with no link at all.

Regulators and frameworks

The US frameworks
your evidence supports.

FrameworkApplies toKeenSec evidence
HIPAACovered entities and business associates handling health informationSecurity awareness training records, simulation results, policy acknowledgements
PCI DSS v4.0.1Organisations that store, process or transmit cardholder dataRequirement 12.6: training on hire and every 12 months, including phishing and social engineering
NYDFS 23 NYCRR 500.14(a)(3)Financial services firms regulated by New York DFSAt least annual awareness training that includes social engineering, for all personnel
FTC Safeguards Rule, 16 CFR 314.4(e)Non-bank financial institutions under FTC jurisdictionSecurity awareness training updated for the risks you identify
NIST SP 800-50 Rev. 1 and SP 800-53 AT-2(1)Organisations building a learning programmeGuidance naming phishing, smishing and vishing simulations as practical exercises

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

Questions buyers ask

Frequently asked questions.

Which US frameworks does KeenSec help with?

KeenSec helps produce awareness evidence for HIPAA, PCI DSS v4.0.1 Requirement 12.6, NYDFS Part 500, the FTC Safeguards Rule, NIST SP 800-50 Rev. 1 and ISO/IEC 27001:2022. Your auditor decides compliance.

Can we simulate callback phishing?

Yes. KeenSec sends a link-free invoice email and connects the call to an IVR or agentic AI voice agent, then records who shared details and who reported.

Can we simulate Microsoft 365 password-expiry lures?

Yes. Credential-capture scenarios lead to a realistic sign-in page built for the test, and anyone who submits sees a just-in-time lesson straight away.

Let’s connect the dots

Rehearse the email and the call.
Prove it at audit.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo