Skip to content

Campaign type

You can choose the type of campaign you want to use.

Sophos Phish Threat includes templates for common attack types. These templates include emails, landing pages, and training modules. You can customize these templates before sending your campaign out. See Customize.

You can choose from the following campaign types:

  • Phishing: This simulates a phishing attack against your users. It encourages your users to click a link in an email.
  • Credential Harvesting: This simulates an attack designed to obtain login IDs and passwords. It encourages your users to enter credentials into a fake website. No passwords are collected.
  • Attachment: This simulates an attack designed to deploy malicious attachments on your system. It encourages your users to open an attachment in an email.
  • Training: This allows you to send anti-phishing training to your users without a simulated attack.

When you create a Phishing campaign, users don't receive a separate training enrollment email. Instead, they're enrolled through a link in the phishing email. Clicking the link triggers enrollment in the training. If users miss the phishing link, they can revisit the original phishing email or use the reminder email to access and complete the training.

In an Attachment campaign, users only receive a separate training enrollment email after opening the attachment. This email contains a link to the training. Users are caught only if they open the attachment, not if they preview it.

You can also select the language used for the campaign.