Skip to main content

Phishing Simulation Templates: 17 Proven Examples by Category

, CEO
Phishing simulation templates by category

The phishing emails that fool people are rarely clever. They look like a package update, a gift card, a password reset, or a note from HR. Attackers reuse these patterns because they work, and that is exactly why they make the best phishing simulations.

Below are the templates that have performed best across years of Hook Security simulations, grouped by the psychology that makes them work. Use them to plan a year of practice for your team or your clients, and to show people what real attacks look like before a real one arrives.

The short version: the most-clicked phishing simulations fall into five groups: delivery notices, account and security alerts, gift cards and freebies, internal HR and payroll messages, and collaboration invites. Rotate through all five so people learn the pattern, not one email.

1. Delivery and shipping notices

Nobody wants to miss a package, and “what did I order?” is a powerful reason to click. These spike around the holidays and big shopping days.

  • UPS failed delivery attempt: a missed-delivery notice with a link to reschedule. Urgency plus confusion is a potent combination.
  • UPS estimated delivery: a friendly “your package is on the way” update. It works because it looks exactly like the real thing people get every week.
  • FedEx delivery exception: a warning that a package could not be delivered, with a tracking link to “manage your delivery.”
  • Amazon shipping confirmation: an order confirmation for something the person never bought, which makes them click to investigate.

What to teach: check tracking numbers by going to the carrier’s site directly, never through the email.

2. Account and security alerts

These turn good instincts against people. Someone who wants to stay safe clicks “this wasn’t me” to lock things down, and lands on a credential-harvesting page.

  • Google device sign-in: a new-device alert that can fool even careful people, because reacting fast feels like the secure thing to do.
  • Uber new device sign-in: the same pattern from a different brand. Uncertainty overrides judgment.
  • Apple support ticket: a case number and a familiar logo. Even people without an Apple ID click to find out who contacted Apple in their name.
  • Netflix password reset: shared passwords are common, so a surprise reset feels plausible and urgent.
  • Account scheduled for deletion: pure urgency. It needs no explanation.
  • Dropbox setup: a request to finish setting up the organization’s shared storage, using the company’s real name.

What to teach: when an alert asks you to act, open the app or type the site address yourself. Real security alerts can wait 30 seconds.

3. Gift cards, rewards, and freebies

“Too good to be true” still works, especially when the offer is small enough to be believable. Food brands have consistently been among the most-clicked simulations Hook has run.

  • Venmo gift card: an animated, well-designed email offering an employee gift card. It looks eerily real.
  • Starbucks eGift and rewards: a free drink or a reward to redeem. Starbucks simulations have drawn a lot of clicks. See how to run a Starbucks phishing simulation.
  • DoorDash promotion: free delivery or a discount on the next order.
  • Customer appreciation gift card: a thank-you reward from a brand the person may or may not use.
  • Papa John’s free pizza: a local-feeling offer that seems too small to be a scam.

What to teach: anything claiming to be free deserves a second, slower look, especially when it asks you to sign in.

4. Internal HR and payroll messages

Internal emails do not need a famous logo. They need to look like a quick note from someone inside the company, and simple usually works better than polished.

  • HR direct deposit update: a short, plain request to confirm payroll details. Written like a real internal email, it is one of the hardest to catch.

What to teach: confirm any request involving pay, banking details, or gift cards with a phone call or a separate message to the sender.

5. Collaboration and messaging invites

Group conversations create fear of missing out. A chat invite or shared document from a trusted platform feels routine.

  • Google Hangouts invite: a trusted brand plus the pull of a group conversation you are not in yet.

What to teach: hover before you click, and be wary of invites you were not expecting, even from familiar tools.

Two categories with their own guides

Social media and healthcare simulations have enough nuance to deserve their own write-ups:

How to use these templates well

  • Rotate categories. People who only ever see delivery emails learn to spot delivery emails. Mix all five groups across the year.
  • Match the season. Delivery notices in November and December, tax and payroll messages in the first quarter, gift cards around holidays.
  • Train at the moment of the click. A short, relevant video right after a click teaches far more than a long annual course.
  • Celebrate reports, not just clean records. The goal is a team that reports suspicious email fast, not one that never clicks.
  • Keep it kind. A simulation is practice. If people feel tricked and shamed, they stop reporting. That is the idea behind PsySec.

For a step-by-step setup, read how to run a phishing simulation. For real phishing emails with the red flags marked up, browse our phishing email examples.

Run these on Autopilot

Hook’s phishing simulator rotates realistic templates across all of these categories every month, pairs each click with a short training moment, and reports results automatically. MSPs can run it across every client from one place. See pricing or book a demo.

Frequently asked questions

What is a phishing simulation template?

A phishing simulation template is a safe, realistic copy of a phishing email that organizations send to their own employees for practice. When someone clicks, they see a short training moment instead of a real attack.

Which phishing templates get the most clicks?

In Hook Security simulations, delivery notices (UPS, FedEx, Amazon), account security alerts (Apple, Google, Uber), and food or gift card offers (Starbucks, DoorDash) have consistently been among the most clicked. Simple internal messages, like an HR direct deposit request, are also very effective.

How often should we run phishing simulations?

Monthly is the most common cadence. It keeps the habit fresh without overwhelming people, and it lets you rotate through categories across the year.

Is it ethical to send phishing simulations to employees?

Yes, when they are run as practice rather than punishment: tell people the program exists, make reporting easy, pair clicks with short training, and never shame individuals publicly.

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.