
Allows you to test employees' resilience against fraudulent SMS messages, replicating real smishing attacks.
Helps identify which employees are most vulnerable to this type of threat.
Allows you to segment the audience with precision: all employees with a valid phone number, or a custom selection by employee, department, or team.
Offers ready-to-use message templates, or the option to write your own message with dynamic variables such as the recipient's name.
Allows you to assign automatic training to those who fall for the simulation, closing the awareness cycle. (Coming soon)
Navigation: Awareness → Simulations → New simulation → Smishing
From the side menu, go to Awareness → Simulations and click + New launch.
On the type selection screen, choose Smishing.
Enter the simulation name (it will be used to identify it in reports).
If you want to do an internal test send before the real one, enable the Test toggle in the upper right corner. Simulations in Test mode are not counted in analytics or in the Human Risk Score.
Click Continue.
Select the simulation language from the dropdown: Spanish, English, or Portuguese.
In the Audience section, choose one of the available options:
Suggested audience (coming soon): employees the platform identifies as at risk and who have a valid phone number.
All employees: includes all employees with a valid phone number. The Selected users counter updates automatically.
Custom audience: opens an advanced selection modal.
If you choose Custom audience, a modal opens with three tabs: Employees, Departments, and Teams. You can combine selections from all three tabs; the platform unifies them into a single audience.
Use the search bar to filter by name.
Enable the Valid phone number toggle to see only employees with a phone number on file.
The right panel shows the summary: Total users, Reachable users, and Excluded.
When finished, click Apply.
The Selected users field in the Audience section updates with the confirmed total.
In Simulation type, choose between:
Click only: the employee receives an SMS with a link and it is recorded whether they click it.
Credential harvesting: the employee is redirected to a fake login page where they can enter their data.
In Simulation results, choose the Recommendation page that the user will see when they fall for the simulation. It is selected from a dropdown with multiple options.
Enable the Preview toggle to preview the selected page before confirming.
In Training assignment (coming soon), enable the toggle if you want a course to be automatically assigned to those who fall for the simulation.
Click Next.
In the Message section, choose one of the two options:
Choose Smishing template: select a pre-designed template from the dropdown.
Write your own SMS: draft the message from scratch in the free text field.
The Preview panel on the right shows in real time how the SMS will look on the recipient's phone, including dynamic variables such as {{FirstName}}.
Coming soon: the message will be able to include the "High deliverability" indicator, which confirms that it has a high probability of arriving without being filtered.
Click Next.
Choose when the simulation will be sent:
Time period: the platform distributes the send over a time range.
Specific date: it is scheduled for a specific day and time.
Send now: it is sent immediately upon confirmation.
Click Preview & Send to review the final configuration before launching.
The Preview & Send confirmation modal shows a summary with: simulation name, number of reachable users, delivery mode, and a preview of the message with the assigned recommendation page.
Click Send to launch the simulation.
What's the difference between "Suggested audience" and "All employees"?
The suggested audience (coming soon) will prioritize employees the platform identifies as at risk and who have a valid phone number. "All employees" includes any employee with a phone number on file, regardless of their history
Can I combine employees, departments, and teams in the same campaign?
Yes. In the custom audience selection modal you can select items from all three tabs; the platform unifies them into a single audience.
What happens if an employee doesn't have a phone number on file?
They will not be reachable for the simulation. The Valid phone number toggle in the audience modal lets you filter and see only those with a valid number. The summary shows the Reachable users so you know exactly how many the SMS will reach.
Can I personalize the message with the recipient's name?
Yes. Templates and the free text field support the {{FirstName}} variable, which the platform automatically replaces with each employee's name at the time of sending.
What is "Test" mode?
It allows you to send the simulation as an internal test before launching it to the real audience. Simulations in Test mode are not counted in analytics or in the Human Risk Score. It is enabled with the Test toggle in the Basics step.
Have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap