Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > running a callback phishing simulation a guide for cybersecurity professionals

How to Create a Callback Phishing Simulation Campaign: A Step-by-Step Guide A Guide

Callback phishing simulations are essential for training employees to recognize and respond to sophisticated phone-based phishing attacks. Here’s a guide on setting up and running these simulations to strengthen cybersecurity across your organization.

Ozan Ucar, Founder and CEO of Keepnet

How to Create a Callback Phishing Simulation Campaign: A Step-by-Step Guide 2025

Callback phishing, also known as telephone-oriented attack delivery (TOAD), is a method where attackers trick employees into calling a number provided in a phishing email. During the call, attackers use social engineering to persuade employees to share sensitive information or even grant unauthorized access. This tactic is particularly dangerous because the real-time interaction often seems more legitimate, catching employees off guard.

Running callback phishing simulations gives your team hands-on practice in spotting and stopping these sophisticated scams before they lead to security breaches.

This guide outlines the steps to set up an effective simulation, analyze the results, and apply the insights to build a more vigilant and security-aware workforce.

What Is Callback Phishing?

Callback phishing is a social engineering tactic where attackers send a phishing email designed to prompt the recipient to call a provided phone number. The email often carries a sense of urgency, presenting a fabricated issue such as a security alert or a service problem that needs immediate attention.

When employees respond, they encounter attackers posing as legitimate representatives, usually from a trusted vendor, service provider, or internal department. Using social engineering techniques, the attackers manipulate employees into revealing sensitive information, such as login credentials or financial details, or even granting remote system access.

Callback phishing is particularly dangerous because the real-time interaction creates a sense of legitimacy, making it challenging for employees to recognize the threat.

Read our blog to learn more about what is callback phishing and how to protect your organization against it.

Why Conduct Callback Phishing Simulations?

Organizations increasingly rely on cybersecurity awareness training to reduce the risks associated with phishing. Callback phishing simulations serve as an effective training tool by giving employees hands-on experience with realistic phishing scenarios. These simulations provide an opportunity for employees to learn how to spot the red flags in phone-based scams, strengthening their response skills and creating a more resilient front line against phishing attacks.

Running these simulations not only helps to mitigate human risk but also builds a security-aware culture where employees become an active part of threat detection and prevention.

Step-by-Step Guide to Running a Callback Phishing Simulation

Running a successful callback phishing simulation involves careful planning, clear objectives, and thorough analysis. A well-designed simulation will help your team practice identifying red flags, build confidence in responding to suspicious requests, and improve reporting habits.

Here’s a step-by-step guide to setting up, executing, and learning from a callback phishing simulation that strengthens your organization’s security awareness.

1. Define Your Callback Phishing Test Goals

Establishing clear objectives is the foundation of an effective simulation. Common goals include:

Raising awareness of callback phishing tactics: Ensure employees recognize suspicious emails that prompt callbacks.

Testing response protocols: Evaluate how quickly and effectively employees respond to potential phishing attempts.

Identifying vulnerable groups: Track which employees or departments are more susceptible to these types of attacks and may need further training.

Defining specific goals ensures the simulation aligns with your organization’s overall cybersecurity strategy and helps measure the success of the exercise.

2. Select or Customize a Phishing Scenario

Many platforms, like Keepnet’s Phishing Simulator, offer callback phishing templates that can be tailored for different scenarios. For instance, you might choose a scenario where an email claims to be from IT support asking the employee to call to resolve a security alert or from a vendor with an urgent issue.

Picture 1: Keepnet Callback Phishing Scenario

Customizing the simulation to reflect your company’s branding, language, and style increases realism and engagement, making it easier for employees to take the exercise seriously and learn from it. Authentic scenarios make the training experience more effective by helping employees practice in situations that feel relevant to their daily tasks.

Explore more customizable simulation templates with tools like Keepnet’s Phishing Simulator.

3. Configure Callback Simulation Parameters

With your template selected, it’s time to configure the parameters of your simulation:

Timing and frequency: Schedule the simulation at a time when employees are active in their inboxes, like mid-morning or early afternoon.

Picture 2: Keepnet Callback Phishing Simulation: Delivery Settings

Targeted groups: For added realism, consider focusing on departments more likely to receive external communications, such as finance or HR.

Picture 3: Keepnet Callback Phishing Simulator: Target Audience Settings

Data to capture: Determine which metrics are most useful, such as the number of employees who called the number provided, time taken to respond, and the rate of reporting.

Platforms like Keepnet enable you to set up these parameters and automatically capture data on employee behaviors, allowing you to track response times and effectiveness in real-time.

Learn about tracking and analyzing human risk insights with Keepnet’s Human Risk Management Platform here.

4. Launch the Callback Simulation Campaign

With all configurations set, you’re ready to launch the simulation. Here are a few steps to ensure a smooth rollout:

Notify relevant stakeholders: Inform IT and security personnel that a simulation is in progress to prevent confusion.

Keep it unannounced: Avoid notifying employees to keep the simulation realistic. Authentic responses provide more accurate insights into employee behaviors.

Picture 4: Keepnet Callback Phishing Simulator: Campaign Summary

As employees interact with the simulation, the platform will record who initiates the callback and who recognizes it as suspicious, allowing for a complete analysis of the results.

5. Analyze the Results

Once the simulation has run its course, review and analyze the results to assess your organization’s strengths and areas for improvement:

Callback initiation rate: Track the percentage of employees who dialed the number provided in the phishing email, showing who may need additional training.

Picture 5: This chart presents the average response times of users who clicked on phishing links and submitted data during phishing simulations.

Picture 6: This graphic displays the human risk score for users who are considered at the highest risk within your organization

Reporting rate: Measure how many employees recognized the email as suspicious and reported it appropriately.

Picture 7: This graphic shows the percentage of users who have repeatedly fallen for phishing simulations, defined here as having failed at least twice.

Picture 8: This chart highlights a specific group of users within your organization who are at higher risk due to their repeated failure to recognize phishing attempts.

Response time: Look at the time it took for employees to report the phishing attempt, which can highlight potential vulnerabilities.

Picture 9: The "Phishing Dwell Time Distribution" graph shows how long users engage with phishing simulation emails before responding, reporting, or falling victim.

By analyzing these metrics, you gain valuable insights into how effectively employees can recognize and respond to callback phishing attempts. Identifying patterns in responses across departments or job roles can help tailor future training efforts more effectively.

Picture 10: This graphic compares your company's phishing risk score with the average scores in your industry and across all industries.

For more insights into measuring and improving human risk, read our article on phishing risk score trends across industries.

6. Provide Tailored Follow-Up Training

The final and crucial step is to use the results to inform follow-up training. Based on the findings, develop training that addresses specific vulnerabilities highlighted during the simulation. For example:

  • Enhance social engineering awareness: Training can focus on helping employees recognize manipulation tactics used in callback phishing.
  • Reinforce reporting procedures: Remind employees of the steps to take when they encounter a suspicious email or phone call, ensuring they know how to report safely and efficiently.
  • Encourage regular practice: Ongoing simulations reinforce phishing awareness, helping employees respond more effectively to threats over time.

Follow-up training helps bridge knowledge gaps, ensuring that employees learn from the simulation and are better prepared to respond to real threats. Tools like Keepnet’s Security Awareness Training can provide the needed flexibility and customization to target these areas effectively.

Explore strategies for effective security awareness training here.

Test both directions: add an outbound help desk scenario

A callback simulation measures one specific behaviour: what an employee does with a number that arrives in a message. Google Threat Intelligence Group reported in August 2026 that the UNC6671 extortion cluster works in the opposite direction, calling employees while posing as internal IT and asking them to enrol a FIDO2 passkey or update MFA before a deadline.

Running both gives you a comparison worth having. The same population, two directions, one measurement: whether an identity change gets completed on a call. Keep the callback campaign as it is and add an outbound scenario with three properties. An internal IT voice rather than an outside brand, a security improvement rather than a problem, and a request to act while the call is still running.

What the comparison usually shows

Teams that run both often find the outbound results worse, because the employee never had to take a first step of their own. In a callback scenario the person chose to dial. In an outbound scenario the call simply arrives, and the only defence left is a verification habit. That gap is the number worth reporting to leadership, not the raw failure rate of either campaign on its own.

Source: Google Threat Intelligence Group, UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments, August 2026.

Best Practices for Callback Phishing Simulations

To maximize the effectiveness of your callback phishing simulations, consider these best practices:

  • Keep scenarios realistic and varied: Regularly changing phishing scenarios keeps employees alert and prevents them from becoming complacent.
  • Use data-driven improvements: Continuously assess and refine your simulations based on previous results to address any emerging vulnerabilities.
  • Communicate results: Sharing results (in an anonymized way) helps employees understand the importance of the training and reinforces a culture of cybersecurity.

By following these practices and consistently analyzing results, you can create a proactive, engaged security culture across your organization.

For more insights into phishing simulation strategies, read our deep dive into voice phishing trends.

Running Callback Phishing Simulations with Keepnet

Keepnet’s callback phishing simulator is an AI-powered platform that helps train employees to recognize and respond to phishing attacks. With 250+ customizable templates in over 30 languages, including the latest phishing tactics, Keepnet’s library reflects real-world, telephone-based threats for comprehensive training.

For added realism, simulations can use local phone numbers or select from 30+ preset options, making campaigns feel region-specific. Keepnet’s AI-powered text-to-speech and custom voice upload options further enhance the experience, delivering lifelike phishing scenarios.

With adjustable complexity levels to suit different skill sets and real-time analytics to track responses, Keepnet enables security teams to identify training needs, provide targeted follow-up, and build organizational resilience against phishing threats.

Schedule a demo to see how Keepnet’s callback phishing simulator can boost your team’s readiness and minimize human risk.

Editor's Note: This article was updated on March 12, 2026.

What Better Program Design Looks Like

Create a Callback Phishing Simulation Campaign: A Step-by-Step Guide A Guide works best when the content reflects how people actually make decisions. Strong programs do not try to teach everything at once. They focus on the few behaviors that create the most risk, then reinforce them with current examples, timely reminders, and clear reporting paths.

That is also what makes training easier to defend internally. When a program changes behavior, reduces repeat-risk patterns, or improves reporting quality, leaders can see how awareness supports real business outcomes instead of acting like a standalone compliance activity.

Keepnet teams usually see the biggest gains when training is tied to a reporting path and a follow-up workflow. For most organizations, the common mistake is treating create a callback phishing simulation campaign: a step-by-step guide a guide as content delivery instead of behavior design.

Program Checklist

  • Choose the user decisions that matter most instead of covering every possible topic.
  • Use short modules, current examples, and realistic follow-up after incidents or simulations.
  • Measure reporting, repeat risk, and remediation behavior, not only completions.
  • Give managers and team leads a role in reinforcing the habits you want to build.

SHARE ON

twitter
linkedin
facebook

Schedule your 30-minute private demo now.

You'll learn how to:
tickBuild personalized callback phishing templates with AI text-to-s
tickTest employee awareness quickly with real-world callback phishing scenarios to test readiness.
tickGenerate custom reports on employee behavior and benchmark your performance against industry standards.

Frequently Asked Questions

What is a callback phishing simulation?

arrow down

It is a controlled test that sends a message with no link and no attachment, usually a fake invoice or renewal notice, and measures who calls the number and what they disclose on the call.

Why run callback phishing simulations?

arrow down

Because email filters cannot see this attack, and neither can an email only programme. Phone centric simulations fail at roughly 40% higher rates than email based ones (Verizon, 2026 Data Breach Investigations Report, 2026, p. 50).

How do you run a callback phishing simulation?

arrow down

Define the goals, select or customise a scenario, configure the callback parameters, launch to the chosen group, analyse who called and what happened, then deliver tailored follow up training.

What should the scenario look like?

arrow down

A plausible charge or renewal the recipient could believe, a number inside the message, and a short window to act. Finance and administrative roles receive the real version of these messages most often.

What should you measure?

arrow down

How many called, how long they stayed on the call, what they disclosed, whether anything was installed, and whether they reported it afterwards. Reporting after a call still contains the incident.

What training follows a failed callback test?

arrow down

Something short and specific: verify through a number the organisation already holds rather than one supplied in the message, and report the call even if nothing was disclosed.

Should we simulate outbound calls as well as callback scenarios?

arrow down

Yes, and the comparison is the point. Callback simulations measure what an employee does with a number supplied in a message. Google Threat Intelligence Group reported in August 2026 that the UNC6671 cluster calls employees directly while posing as internal IT and requests a passkey enrolment or MFA update. Running both against the same population shows whether the failure comes from the message or from the absence of a verification habit.