Night Shift at Veltrix
A late shift in a logistics office. A vendor asks to change their bank details, a push keeps buzzing, and a caller says he is the CEO. Handle a full evening of pressure.
Interactive 3D exercises across phishing, ransomware, GDPR and the EU AI Act, LLM and agent security, and the bugs your developers actually ship. Pick a threat and play it. Free, no sign-up.
24 exercises · Phishing, ransomware, social engineering, and the everyday judgement calls that keep an attacker out.
A late shift in a logistics office. A vendor asks to change their bank details, a push keeps buzzing, and a caller says he is the CEO. Handle a full evening of pressure.
A display name says one thing, the real address another. Learn where to look before you trust a message, and how a lookalike domain is built.
A supplier emails new payment details before an invoice run. Verify the request through a channel the sender does not control before a payment leaves.
A short, urgent message from a manager asks you to buy gift cards quietly. Spot the business email compromise pattern and shut it down.
A friendly phone call warns you an email is coming, so you trust it when it lands. See how a two-step lure lowers your guard, and where it slips.
Your public posts are the attacker’s script. Watch a message built from details only a colleague should know, and learn what gives it away.
A receipt for something you never bought, and a number to call to cancel. The link is the phone number. Practise not dialling it.
A poster or an email asks you to scan a code, and the code skips every email filter you have. Learn to treat a QR code like any other link.
Someone from support needs a code to fix your account. Codes are never read aloud. Practise hanging up, calling back on a known number, and reporting.
A text says a delivery is stuck and a small fee will release it. SMS has no spam filter in front of it. Learn to read the link, not the panic.
A new number messages you as the CEO, urgent and off the usual channel. Practise moving it back to a channel you both trust before you act.
A finance approval comes from a face and a voice you know, live on a call. Learn the tells and the call-back rule that beats a convincing fake.
A shared drive is encrypting file by file. Know the early signs, disconnect the right way, and raise it before it spreads across the team.
A routine-looking invoice arrives with a document that wants you to enable content. See what one click sets off, and how to handle it safely.
A full-screen warning says your machine is infected and to call the number now. The warning is the attack. Practise closing it and reporting.
Approvals keep arriving on your phone at 11pm. Understand push fatigue, why you never approve one you did not start, and how to report it.
An attacker does not need your password if they can reset it. Lock down recovery email, phone and questions before someone else uses them.
A breach at one site becomes a break-in at yours when a password is reused. See credential stuffing work, then set up a manager and passkeys.
A branded memory stick is left by the door. Decide what to do with a device of unknown origin, and why curiosity is the whole attack.
A courier with full hands asks you to hold the door. Practise the polite, firm habit that keeps a stranger out of the building.
You step away for two minutes and leave the screen open. See how much an insider or a visitor can do in that window, and build the lock habit.
Open wifi, a shoulder near your screen, and a login page that looks a little off. Handle sensitive work outside the office safely.
The padlock means the connection is private, not that the site is honest. Learn what the address bar really tells you before you type a password.
The fastest control you have is a report. Practise the one action that turns a near miss into an early warning for the whole team.
9 exercises · GDPR, data handling, retention, and the EU AI Act, taught through the decisions people make with real data.
A customer asks for everything you hold on them. Learn what counts, the clock you are on, and how to answer without leaking someone else’s data.
An erasure request lands. Work out what can be deleted, what must be kept, and why a backup is not an exception you can ignore.
A colleague needs a report, so a full customer export is on its way. Practise minimising data, masking fields, and sharing the least that does the job.
A laptop with personal data is gone. Understand what makes it notifiable, who to tell, and how the first hour shapes the next 72.
Marketing wants to email a list. Consent or legitimate interest? Walk the decision that decides whether you can send it at all.
A new SaaS tool will hold customer records. Check the processor, the contract, and where the data actually lives before you sign up.
Data is about to leave the region. Know when that is fine, when it needs safeguards, and how to spot a transfer hiding inside a support ticket.
A bot joins the call to transcribe. Under the EU AI Act and privacy law, who consents, what is recorded, and where does the transcript go?
Old records pile up because deleting feels risky. Learn why keeping everything is the risk, and how a retention schedule protects people.
8 exercises · Prompt injection, data leakage, shadow AI, and giving an assistant only the reach it should have.
Your AI assistant summarises an inbox, and one message contains instructions aimed at it, not you. See indirect prompt injection do its work.
A deadline is close, so source code and a customer list go into a public assistant. Understand where that data goes and why it may not come back.
A free extension promises to write your replies and reads every page you open. Weigh the offer against what it quietly takes.
An AI agent can read mail, send mail, and move files. Decide the reach it actually needs before a clever prompt uses the rest.
An assistant gives a policy citation that does not exist. Build the habit of checking before you act on generated text.
A model learns from user uploads, and someone feeds it exactly what they want it to repeat. See a poisoning attempt take shape.
A finance approval comes from a face and voice you know, on a call. Learn the tells and the call-back rule that beats a convincing fake.
An API key goes into a prompt to "help the model help you". Understand why the prompt is not a safe place for a secret.
5 exercises · Playable case studies drawn from documented breaches, with the names changed and the lessons kept.
Modelled on a 2023 casino-sector breach: a caller talks a service desk into a password reset. See how one polite call became a full intrusion.
Based on the wave of malicious document attachments: a routine-looking invoice arrives with a payload one click away. Handle it the safe way.
Modelled on repeated cloud exposures: a storage bucket set to public spills customer records. Trace how it happened and how it is found.
A composite of business email compromise cases: an employee’s salary is redirected by a single convincing email to HR. Catch it in time.
Drawn from supply-chain intrusions: access came through a trusted supplier, not the front door. See why vendor access is your attack surface.
Application security split by attack surface. Break a real bug, then write the fix. Free, hands-on, no sign-up.
SQL injection in the login · Stored cross-site scripting · Server-side request forgery
The id you can change · Mass assignment · No rate limit, no mercy
The key in the commit history · The friendly pull request · Branch protection that means it
The public bucket · The role that can do anything · The admin console on the internet
Tell us a little about your team and we will set up a walkthrough and a pilot. No data leaves this page until you press send: it opens your own email to us.
Prefer email? Write to labs@hamcodes.com.