TLDR: On the first Monday of Cybersecurity Awareness Month, Symbol’s own phishing simulation reached me as a fake Google password reset in Spanish from googkle.com. I reported it about a minute after it arrived. The typo in the email was the funniest signal and the least durable one, because AI-written phishing no longer misspells anything. The habits worth measuring this October are the ones that survive a perfect email: checking the request against your own intent, a one-action report path on every mail platform, fast closure for the reporter, and report speed as a metric next to click rate.
Monday, October 5, 10:22 AM in Bogotá. A Google security email lands in my inbox. The header reads “Código de Verificación de Google.” The body opens with my first name and a familiar kind of urgency:
“Hola Antonio, recibimos una petición para restablecer to contraseña de Google.”
To contraseña. Google’s verification team, apparently, switches to English for exactly one word and then switches back. The subject line had its own trouble: “Renueva to Contraseña de Google,” with the ñ mangled into two characters that have never appeared in any language on purpose.
The sender was [email protected]. The link promised to reset my password. The footer gave Google’s Mountain View address, which is the most reassuring part of any phishing email and the easiest part to copy.
It was a simulation. Symbol sent it. I co-founded Symbol and I run its engineering, so the system that tests our customers’ employees had just tested the person who signs off on that system. I forwarded the message to our report address at 10:23. Sixteen seconds after the forward, a reply arrived: “You’ve successfully identified a Phishing Email!”
I would love to credit years of security instinct for that minute. Some of the credit belongs to whoever taught me that tu has a u.
I Was in the Population, Which Is the Point
The first thing worth saying is boring and important: I was on the list.
Many programs quietly exempt leadership. Executives are busy, the reasoning goes, and a failed simulation in the C-suite is awkward to report upward. That exemption has the threat model backwards. Leadership inboxes are where approval, payment, and access requests land. They are the inboxes attackers research first. Vendors now sell executive-impersonation drills built on cloned voices and fake video calls because that is where real fraud goes.[1]
There is a credibility cost, too. An MSSP that asks a client’s finance team to sit through simulations while its own leaders are excluded is running a program it does not believe in. I would rather be the founder who got a fake Google reset at 10:22 on a Monday than the founder who never had to.
Being in the population also changed how I read the email. I was not reviewing a template in an admin console, where every phishing email looks obvious because you already know it is one. I was in the middle of a workday, switching between tabs, with a message that wanted one click. That is the only context where a simulation measures anything.
What I Actually Caught
When I slow the minute down, four things happened, in roughly this order.
I had not asked for a reset. This was the first signal and the strongest one. A password reset email is a reply to something. If you did not start the conversation, a reply is suspicious no matter how good it looks. This signal does not depend on the attacker’s spelling, design, or language skills. It depends on me knowing what I did this morning.
The domain was wrong. googkle.com is close enough to read past and wrong enough to catch if you look. Lookalike domains are older than most of the people who fall for them, and they still work, because people read the display name and skip the address.
The language was normal. Spanish in my inbox is ordinary for me. That is worth saying because “unexpected language” is a common training tip, and for a large part of the workforce MSSPs protect, it is useless. A simulation that arrives in the language people actually read is a better test than one that arrives in a language they would never trust.
The typo. “Restablecer to contraseña” made me smile, and then it made me certain. A few lines later, the same email gets it right: “restablecer tu contraseña.” Even the template could not decide.
That fourth signal is the one everyone will remember from this story, including me. It is also the one I trust least.
The Typo Is a Retiring Signal
For years, awareness training taught people to look for bad grammar. It was decent advice when phishing was written fast by people working in a second or third language. It is weak advice now.
Language models write clean Spanish, clean English, and clean Portuguese on the first try. They match brand tone. They do not mix to and tu. When Sublime Security launched tailored simulations on October 6, its CEO said it plainly: AI has given attackers the ability to launch convincing, highly targeted phishing campaigns at a speed and scale that generic, once-a-quarter training cannot keep up with.[2]
If the only thing my minute proved was that I can spot a typo, it proved almost nothing about next month’s real attack. The attack that gets me will be perfect. It will arrive in the right language, from a domain that passes a glance, about something I half-expect.
What will still work against a perfect email is the first signal. Did I start this? Is this a reply to something I did? If the answer is no, I do not need to evaluate the design, the grammar, or the footer. I need to report it and go to the real service directly if I am worried.
So the honest lesson from my simulation is uncomfortable for anyone who writes templates, including us. The typo made the test easier. It did not make the test useless, because it still exercised the habit that matters. But a program that only ever sends typo-grade simulations is training people for an attacker who retired years ago.
The Minute That Matters
Here is the part of the story I care about most, and it has nothing to do with spelling.
The email arrived at 10:22. My report left at 10:23. The confirmation came back sixteen seconds later.
In a real attack, that minute is the asset. Phishing campaigns rarely target one person. They hit a department, a tenant, or a whole client list in the same window. The first person who reports gives the security team a message ID, a sender, and a URL while the campaign is still landing in other inboxes. One early report can be worth more than a hundred people who silently ignore the email.
Silent ignoring is the hidden failure mode in most programs. A person who deletes a phishing email protected one inbox. A person who reports it protected everyone else who got it. Click rate cannot tell those two people apart. Both of them “did not click.” Only one of them helped.
That is why I want report rate and time to report on the same dashboard as click rate. TechTarget’s Awareness Month guidance makes the same point from the CISO side: track simulated click-through rates and internal incident reporting rates through the year, and adjust training from there.[3] Click rate measures how often the defense failed. Report speed measures whether the defense is working.
The report path has to be one action
I use Gmail. There is no Outlook add-in button in my world. My report path is forwarding the message to a dedicated address, and that path took one action because I knew the address.
Every MSSP should test this for every client, not only the Microsoft 365 tenants. If the report path for Google Workspace users is “open a ticket and paste the headers,” most people will choose deletion. Deletion is one action. The report has to be one action too.
Closure is part of the habit
The sixteen-second reply mattered more than it sounds. Reporting into a void feels like shouting into a well. People stop doing it. A fast, specific acknowledgment, even an automated one, tells the reporter that the action landed somewhere and that it counted. In a simulation, it closes the loop. For a real phish, the equivalent is a short “thanks, we pulled it from every inbox that got it” note from the security team, which is the best awareness training money cannot buy.
Awareness Month Is a Starting Line
October is Cybersecurity Awareness Month, and this year the market moved hard in the same direction within one week.
- Sublime Security made its tailored simulations generally available on October 6. It uses attacks detected in each customer’s mail flow to prioritize simulations and can turn a detected malicious email into a test in minutes.[2]
- Hoxhunt expanded its adaptive training on September 29 to cover Microsoft Teams, SMS, callback phishing, vishing, and deepfake video, including executive impersonation.[1]
- Paubox entered the category on October 2 with phishing simulation inside its email suite, pitched as “easier to use and more affordable than KnowBe4,” with no new login or employee roster to manage.[4]
Read together, those launches say three things. Simulations are moving toward the attacks people actually receive. They are leaving email for the other channels attackers already use. And buyers are tired of running a separate roster and console just to train the same people.
TechTarget’s coverage of the month carries the line I would put on every MSSP’s October planning doc: “One October of training buys you about 90 days of better behavior. A year-round rhythm buys you a different company."[3] Awareness Month is useful as a reason to restart the rhythm. It is a poor substitute for the rhythm.
What I Would Ask an MSSP to Check This Month
If you run awareness across many clients, my Monday suggests a short audit you can finish before Halloween:
| Check | Weak answer | Strong answer |
|---|---|---|
| Is leadership in the simulation population? | “We exempt executives” | Every role is in, and executive scenarios exist |
| Does every mail platform have a report path? | Outlook button only | Outlook button plus a forward address for Gmail and others |
| Does the reporter get closure? | Silence | A fast, specific acknowledgment |
| What do you measure? | Click rate | Click rate, report rate, and time to report |
| What signals does training teach? | Typos and bad logos | Intent, domains, and out-of-band verification |
| Do templates match the workforce? | English only | The languages each client’s people actually read |
| Are simulated reports separated from real ones? | Analysts triage your own tests | Simulations are tagged automatically |
None of those checks require a new tool. Most of them require looking at the program from the inbox side instead of the console side, which is exactly where I was standing on Monday.
Where Symbol Fits
Symbol exists to help admins run security awareness across many tenants without staffing a person for every client. The Monday simulation touched three parts of that job.
The template came from our phishing simulation library, which includes localized and AI-generated scenarios. The report went through Report a Phish, which gives Outlook users a button and gives everyone else, including Gmail users like me, a dedicated forward address. Reports are tagged automatically when they are simulations, so analysts are not triaging their own tests, and real reports are categorized and visible across every client from one dashboard. The congratulations note I got sixteen seconds later is the closure step for the reporter.
The template can get a proofread. The habit is the part worth keeping: notice that you did not ask for this, report it in one action, and let the people who protect the rest of the tenant know within a minute.
If you are planning your October campaigns now, put yourself on the list. The worst outcome is not that you fall for it. The worst outcome is that you never find out whether you would have.
References
- Hoxhunt, “Hoxhunt Expands Adaptive Phishing Training Beyond Email With AI Voice, Deepfake and Multichannel Simulations,” PR Newswire, September 29, 2026. https://www.prnewswire.com/news-releases/hoxhunt-expands-adaptive-phishing-training-beyond-email-with-ai-voice-deepfake-and-multichannel-simulations-302892857.html
- Sublime Security, “Sublime Security Launches Tailored Phishing Simulations and Training,” PR Newswire, October 6, 2026. https://www.prnewswire.com/news-releases/sublime-security-launches-tailored-phishing-simulations-and-training-302899306.html
- TechTarget, “Use Cybersecurity Awareness Month as a springboard, not a fire drill,” 2026. https://www.techtarget.com/cybersecurity/news/366651182/Use-Cybersecurity-Awareness-Month-as-a-springboard-not-a-fire-drill
- Paubox, “Paubox Launches Security Awareness Training Product as Healthcare IT Names Employee Negligence a Top Risk,” Business Wire, October 2, 2026. https://www.financialcontent.com/article/bizwire-2026-10-2-paubox-launches-security-awareness-training-product-as-healthcare-it-names-employee-negligence-a-top-risk
