# Arsen > Arsen is a cybersecurity awareness platform that trains employees against phishing, vishing, smishing, QR-code (quishing) and AI-driven social engineering using realistic, AI-powered attack simulations, adaptive training, and human cyber-risk scoring. Arsen publishes original analyses of real-world social-engineering attacks, a cybersecurity glossary, and practical guides for CISOs and security teams. Content is available in English (/en/) and French (root paths). ## Platform - [Phishing Simulation](https://arsen.co/en/platform/phishing-simulation): Run realistic, AI-generated phishing campaigns to measure and reduce employee click rates. - [Cybersecurity Awareness Training](https://arsen.co/en/platform/cybersecurity-awareness-training): Adaptive, role-based security awareness training triggered by simulation results. - [Vishing Simulation](https://arsen.co/en/platform/vishing-simulation): Simulate AI voice-phishing (vishing) calls to test and train employees. - [Smishing Simulation](https://arsen.co/en/platform/smishing-simulation): Simulate SMS phishing (smishing) attacks across your workforce. - [Threat Monitoring](https://arsen.co/en/platform/threat-monitoring): Monitor brand impersonation, look-alike domains, and external social-engineering threats. - [Human Cyber Risk Scoring](https://arsen.co/en/human-risk-scoring): Quantify human cyber risk per employee, team, and department. ## Solutions - [Spear Phishing](https://arsen.co/en/solutions/spear-phishing): Defend against targeted spear-phishing of high-value individuals. - [Business Email Compromise (BEC)](https://arsen.co/en/solutions/business-email-compromise): Reduce exposure to CEO fraud and business email compromise. - [Vishing & Smishing](https://arsen.co/en/solutions/vishing-smishing): Train teams against voice and SMS phishing attacks. - [Deepfake](https://arsen.co/en/solutions/deepfake): Prepare employees for deepfake voice and video impersonation fraud. - [QR-Code Attacks (Quishing)](https://arsen.co/en/solutions/qr-code-attacks): Simulate and defend against malicious QR-code phishing. - [Executive Protection](https://arsen.co/en/solutions/executive-protection): Protect executives and finance teams from targeted social engineering. - [Threat Prevention](https://arsen.co/en/solutions/threat-prevention): Prevent credential theft, MFA bypass, and account takeover. - [Cybersecurity Culture Change](https://arsen.co/en/solutions/cybersecurity-culture-change): Build a lasting security culture through behavior change. - [Compliance](https://arsen.co/en/solutions/compliance): Support GDPR, DORA, NIS2 and audit requirements with training evidence. - [Phishing API Integration](https://arsen.co/en/solutions/phishing-api-integration): Integrate phishing simulations and results into your own stack via API. ## Industries - [Financial Services](https://arsen.co/en/industries/financial-services): Social-engineering defense for banks, fintech, and financial services. - [Crypto](https://arsen.co/en/industries/crypto): AI-augmented awareness training for crypto and blockchain companies. - [Call Centers](https://arsen.co/en/industries/call-centers): Vishing training for call-center and BPO teams. - [Insurance](https://arsen.co/en/industries/insurance): Human-risk training for insurers. - [Retail](https://arsen.co/en/industries/retail): Phishing and social-engineering defense for retail. ## Free Tools - [Phishing Resilience Evaluation](https://arsen.co/en/resources/phishing-resilience-evaluation): Free assessment of your organization's phishing resilience. - [SPF / DKIM / DMARC Checker](https://arsen.co/en/resources/check-spf-dkim-dmarc): Free tool to check your email authentication records. - [Password Strength Checker](https://arsen.co/en/resources/password-strength-checker): Test how strong a password is. - [QR-Code Phishing Checker](https://arsen.co/en/resources/qr-code-phishing): Analyze a QR code for phishing risk. - [Phishing Policy Generator](https://arsen.co/en/resources/phishing-policy-generator): Generate a phishing policy for your organization. - [AI Voice Phishing Playground](https://arsen.co/en/resources/ai-voice-phishing-playground): See how AI voice-phishing (vishing) calls are built. ## Company - [About Arsen](https://arsen.co/en/about): Company mission and team. - [Pricing](https://arsen.co/en/pricing): Plans and pricing for Arsen. - [Customer Stories](https://arsen.co/en/customers): How organizations use Arsen. - [Customer Reviews](https://arsen.co/en/customer-reviews): Verified customer reviews. - [Phishing Test](https://arsen.co/en/phishing-test): Test your organization against a phishing simulation. ## Glossary & Definitions - [Cybersecurity & Social Engineering Glossary](https://arsen.co/en/glossary): Definitions of phishing, vishing, smishing, social engineering, and related terms. - [Active Directory: Managing User Access](https://arsen.co/en/resources/active-directory): Active Directory (AD) is a critical tool in cybersecurity for managing and securing user access within an organization's network. It... - [Approval Phishing](https://arsen.co/en/resources/approval-phishing): Approval phishing tricks crypto users into granting wallet access, letting attackers drain funds. Here's how it works and how to stop it. - [BEC (Business Email Compromise): Prevention Strategies](https://arsen.co/en/resources/business-email-compromise): When it comes to cyber attacks delivered by email, Business Email Compromise or BEC is a very present threat, costing billions of... - [Catfishing: How to Spot One, Prevent and Protect](https://arsen.co/en/resources/catfishing): Catfishing is a big problem. Because it relies on interesting (and dangerous) social engineering techniques, we’ll deep dive into it in... - [Compromised Account Recovery](https://arsen.co/en/resources/compromised-account-recovery): A compromised account can pose significant risks to your digital identity, privacy, and security. Whether it's a personal email, social... - [Computer Virus: Detection and Removal Techniques](https://arsen.co/en/resources/computer-virus): A computer virus is a type of malicious software (malware) that can infect computers, replicate itself, and spread to other systems.... - [CryptoLocker Ransomware: Prevention and Response](https://arsen.co/en/resources/cryptolocker): In this guide, we’ll explore how CryptoLocker works, how to prevent an infection, and effective response strategies in case you fall... - [Cyber Crime: Trends and Prevention Strategies](https://arsen.co/en/resources/cyber-crime): Cybercrime refers to illegal activities carried out using computers or the internet. From data breaches to identity theft,... - [Cyber Hygiene: Essential Practices for Security](https://arsen.co/en/resources/cyber-hygiene): In today’s digital age, cyber hygiene is more critical than ever. With the rise of cyber threats, ensuring that employees follow best... - [Cybersecurity Awareness Training and Compliance: A Framework-by-Framework Guide](https://arsen.co/en/resources/awareness-compliance): This guide provides a framework by framework breakdown of how CSAT supports compliance, reduces risk, and prepares your organization for... - [DLP (Data Loss Prevention): Strategies and Tools](https://arsen.co/en/resources/dlp): In today's digital world, securing sensitive information has never been more critical. Data Loss Prevention (DLP) is a cybersecurity... - [DNS (Domain Name System): What is it and How it Works?](https://arsen.co/en/resources/dns): The Domain Name System (DNS) is a foundational component of the internet that makes navigating websites, sending emails, and other... - [DNS Spoofing: Detection and Prevention](https://arsen.co/en/resources/dns-spoofing): DNS spoofing is a critical cybersecurity threat that can undermine the integrity of internet communications. By understanding what DNS... - [Data Exfiltration: Prevention, Tips & Techniques](https://arsen.co/en/resources/data-exfiltration): Data exfiltration refers to the unauthorized transfer of data from a computer, network, or server to an external destination. This is... - [Data Leaks: Impact and Countermeasures](https://arsen.co/en/resources/data-leak): A data leak refers to the unauthorized transmission or exposure of sensitive information from an organization to an external or... - [Doxing: What It Is and How to Prevent It?](https://arsen.co/en/resources/doxing): Doxing, a term derived from "dropping docs," refers to the malicious act of revealing someone's private information without their... - [E-discovery: Streamlining Legal Investigations](https://arsen.co/en/resources/e-discovery): In this guide, we’ll explore how e discovery plays a vital role in streamlining legal investigations, the challenges it addresses, and... - [Electronic Communication: How to Secure your Privacy?](https://arsen.co/en/resources/electronic-communication): In today's digital age, electronic communication is an essential part of our daily lives, whether it's through emails, instant... - [Email Archiving Solutions for Businesses](https://arsen.co/en/resources/email-archiving): Email is a critical communication tool for businesses, but it also presents unique challenges in terms of security, compliance, and data... - [Email Filtering: Advanced Solutions for 2024](https://arsen.co/en/resources/email-filtering): Email is one of the primary means of communication. It’s an old, yet prevalent technology. As it can be used as a vector for malicious... - [Email Gateway: Secure Your Communications](https://arsen.co/en/resources/email-gateway): Emails are ubiquitous. In an organization context, this can bring challenges, from establishing the correct distribution and... - [Email Scams: Detection and Prevention Tips](https://arsen.co/en/resources/email-scams): Email scams are one of the most common cybersecurity threats today. Scammers use deceptive emails to trick recipients into sharing... - [Email Security: Protect Against Cyber Threats](https://arsen.co/en/resources/email-security): Email security is crucial in safeguarding your personal and business communications from cyber threats like phishing, malware, and data... - [Email Spoofing — Definition, Examples & How to Prevent It](https://arsen.co/en/resources/spoofing): Email spoofing is a deceptive practice where cybercriminals forge the sender's address in an email to make it appear as if it’s from a... - [Encryption Techniques: Protecting Your Data](https://arsen.co/en/resources/encryption): This guide will dive into the various encryption techniques used in cybersecurity, how they work, and why they are critical in... - [Graymail: Handling Unwanted but Legitimate Emails](https://arsen.co/en/resources/graymail): Although graymail is not malicious, it can clutter your inbox and make it difficult to find important messages. In today’s cybersecurity... - [Hacking: Understanding Risks and Protections](https://arsen.co/en/resources/hacking): This guide provides an overview of the most common hacking methods and best practices to help you stay safe online. - [Honeypot Techniques: Trapping Cyber Attackers](https://arsen.co/en/resources/honeypot): In this guide, we’ll dive deep into the concept of honeypots, their various types, how they work, and how they can strengthen your... - [ITDR (Identity Threat Detection and Response): Prevention & Protection](https://arsen.co/en/resources/identity-threat-detection-and-response-itdr): In this guide, we’ll dive deep into ITDR, its importance, and how to implement it to safeguard user identities, prevent breaches, and... - [Insider Threat: Detection and Prevention Strategies](https://arsen.co/en/resources/insider-threat): This guide will help you understand how to detect and prevent insider threats using effective strategies, policies, and tools. - [Malware: Comprehensive Protection Strategies for you and your Business](https://arsen.co/en/resources/malware): Understanding malware is crucial for both individuals and businesses. Cybersecurity threats are constantly evolving, making it important... - [Mobile Security: Defending Against Mobile Threats](https://arsen.co/en/resources/mobile-security): In today’s connected world, mobile security is more important than ever. Our smartphones and tablets are essential tools in our daily... - [OSI Model (Open Systems Interconnection): Understanding Network Layers](https://arsen.co/en/resources/osi-model): In this guide, we'll explore the OSI model, its seven layers, and how it plays a crucial role in cybersecurity. - [Pharming: Recognizing and Preventing Attacks](https://arsen.co/en/resources/pharming): In this guide, we’ll break down what pharming is, how it works, and—most importantly—how you can protect yourself and your organization... - [Phishing: Ultimate Guide 2024 | How to Recognize and Prevent Attacks](https://arsen.co/en/resources/phishing): Phishing is a vast subject, we’ve seen all sorts of information about it, from facts to fiction. We’ve published this page to deep dive... - [Pretexting: The Art of Deceptive Persuasion](https://arsen.co/en/resources/pretexting): Pretexting is a sophisticated form of social engineering where attackers create false scenarios to manipulate individuals into revealing... - [Preventing Intellectual Property Theft](https://arsen.co/en/resources/intellectual-property-theft): Intellectual property theft is a growing concern for organizations across industries. As businesses increasingly rely on digital... - [Privilege Escalation: Definition, Types & Prevention Methods](https://arsen.co/en/resources/privilege-escalation): In cybersecurity, privilege escalation is a type of attack where a malicious actor exploits system flaws or misconfigurations to gain... - [Privileged Identity Management (PIM): Securing Access](https://arsen.co/en/resources/privileged-identity-management): In today’s cybersecurity landscape, Privileged Identity Management (PIM) plays a crucial role in safeguarding critical systems and... - [Protecting PII (Personal Identifiable Information): Best Practices 2024](https://arsen.co/en/resources/personal-identifiable-information): This guide explores essential best practices for protecting Personal Identifiable Information from cyber threats and ensuring compliance... - [Ransomware Explained — Protection, Response & Future Outlook](https://arsen.co/en/resources/ransomware): In today's digital age, where information and data are paramount, the threat of ransomware cannot be underestimated. Cyberattacks are... - [SPF (Sender Policy Framework) Records: Securing Your Email](https://arsen.co/en/resources/spf): SPF (Sender Policy Framework) is a vital email authentication protocol that helps protect your domain from email spoofing and phishing... - [Sandbox Environments: Enhancing Software Security](https://arsen.co/en/resources/sandbox): In today's cybersecurity landscape, sandbox environments play a crucial role in safeguarding systems from potential threats. Whether... - [Security Awareness Training: Empowering Employees](https://arsen.co/en/resources/security-awareness-training): The human factor is often exploited in cyber attacks. This is why understanding and building a comprehensive security awareness training... - [Smishing (SMS Phishing) Protection: Secure Your SMS](https://arsen.co/en/resources/smishing): You’ve probably heard about it, you’ve probably received some of it. Smishing is basically phishing via SMS and is a very popular vector... - [Social Media Threats: How to Protect Your Online Presence?](https://arsen.co/en/resources/social-media-threats): In this guide, we will explore the most common social media threats and provide actionable tips on how to protect your online presence. - [Spam: Identifying and Blocking Unwanted Emails](https://arsen.co/en/resources/spam): Spam refers to unsolicited and often irrelevant emails sent in bulk to a large number of recipients. These messages can flood your inbox... - [Spear Phishing: Targeted Attack Prevention](https://arsen.co/en/resources/spear-phishing): Let’s talk about spear phishing. We’ve all heard, seen and probably received phishing emails. Although still an active threat, phishing... - [Spyware: Identifying and Removing Hidden Threats](https://arsen.co/en/resources/spyware): Learn how to identify and remove spyware, a hidden threat that can compromise your privacy and security. - [Telemetry: Harnessing Data for Security Insights](https://arsen.co/en/resources/telemetry): In the evolving world of cybersecurity, telemetry plays a critical role in ensuring robust protection against emerging threats. By... - [Trojan Horse: Unmasking Hidden Malware Threats](https://arsen.co/en/resources/trojan-horse): Trojan horse malware has become a persistent threat in the world of cybersecurity. Hidden within seemingly legitimate software, these... - [VPN Use: Enhancing Privacy and Security Online](https://arsen.co/en/resources/vpn): In this guide, we’ll explore what a VPN is, how it works, and why it’s essential for cybersecurity and privacy. - [Vishing Defense: Protect Your Information](https://arsen.co/en/resources/vishing): Vishing is a potent threat. It's basically phishing over voice. It always has been but it's becoming more accessible and prevalent given... - [What Is Cross-Site Scripting (XSS)? Examples & Defense Tips](https://arsen.co/en/resources/cross-site-scripting-xss): Cross Site Scripting (XSS) is one of the most common security vulnerabilities found in web applications. It allows attackers to inject... - [What Is DMARC? Definition, Setup Guide & Best Practices](https://arsen.co/en/resources/dmarc): DMARC (Domain based Message Authentication, Reporting & Conformance) is an essential email authentication protocol that helps prevent... - [What Is Data Classification? Definition & How to Implement It](https://arsen.co/en/resources/data-classification): In this guide, we’ll break down the best practices for establishing robust data classification policies to secure company information. - [What Is Social Engineering? Definition, Examples & Defense](https://arsen.co/en/resources/social-engineering): In the context of cybersecurity, social engineering is a critical area of concern. Despite the growing threat, many people remain... - [What are Compromised Accounts?](https://arsen.co/en/resources/compromise-accounts): Compromised Accounts occur when fraudsters take over existing accounts (email, social media, cloud, or corporate) to exploit previously... - [What is Access Acquisition?](https://arsen.co/en/resources/access-acquisition): Access Acquisition is a resource development technique in the MITRE F3 Framework. Fraud actors purchase or otherwise obtain existing... - [What is Account Takeover?](https://arsen.co/en/resources/account-takeover): Account Takeover (ATO) is a technique covering unauthorized access to bank and payment accounts. Fraud actors use stolen credentials,... - [What is Adversary-in-the-Middle?](https://arsen.co/en/resources/adversary-in-the-middle): Adversary in the Middle (AiTM) is a technique for bypassing verification in login chains. Fraudsters insert themselves between two... - [What is Browser Session Hijacking?](https://arsen.co/en/resources/browser-session-hijacking): Browser Session Hijacking is a penetration technique in which fraudsters inject code into a browser, inheriting active sessions, SSL... - [What is Brute Force?](https://arsen.co/en/resources/brute-force): Brute Force is an Initial Access Technique. To gain unauthorized access to accounts and systems, fraudsters systematically guess or test... - [What is DKIM (DomainKeys Identified Mail)? Guide, Definition, Usecase](https://arsen.co/en/resources/dkim): DKIM (DomainKeys Identified Mail) is an essential email security standard that helps verify the authenticity of an email's sender and... - [What is Impersonation?](https://arsen.co/en/resources/impersonation): Impersonation is a technique covering two sub techniques: Account Holder Impersonation and Official Impersonation. Fraud actors assume... - [What is Multi-Factor Authentication Takeover?](https://arsen.co/en/resources/mfa-takeover): MFA Takeover includes MFA Request Generation (fatigue attacks) and MFA Interception. Both methods enable fraudsters to bypass multi... - [What is Phishing for Information?](https://arsen.co/en/resources/phishing-for-information): Phishing for information is a reconnaissance technique in the MITRE F3 framework. Fraud actors use multi channel social engineering... - [What is Phone Number Spoofing?](https://arsen.co/en/resources/phone-number-spoofing): Phone Number Spoofing is a defense evasion technique. Fraud actors manipulate caller ID so outgoing calls appear to originate from a... - [What is Supply Chain Compromise?](https://arsen.co/en/resources/supply-chain-compromise): Supply Chain Compromise is an initial access technique where fraud actors manipulate products, software, or distribution mechanisms... - [What is Typosquatting?](https://arsen.co/en/resources/typosquatting): Typosquatting (also called URL hijacking) exploits typing mistakes to redirect users to fraudulent domains that mimic legitimate brands.... - [What is Web Session Cookie Stealing?](https://arsen.co/en/resources/steal-web-session-cookie): Web session cookie theft is an intrusion technique. Fraudsters use active browser sessions to bypass authentication and MFA without... - [What is a ClickFix attack?](https://arsen.co/en/resources/clickfix-attack-vector): ClickFix is a type of social engineering attack that makes people run malware on their own without the attacker needing to use an... ## Blog (latest) - [Why You Should Train Your Financial Team Against Vishing](https://arsen.co/en/blog/financial-services-deepfake-vishing-case-study): Your finance team is the priority for vishing training, for two reasons: finance is where AI enabled fraud converts into cash, and... - [AI Voice Phishing Is Targeting IT Help Desks: How to Defend Yours](https://arsen.co/en/blog/ai-vishing-help-desk-attacks): AI voice phishing turned the IT help desk into a primary breach entry point. Attackers impersonate employees on the phone and pressure... - [Crypto Token Compromise: Why Humans Are the Prime Entry Point](https://arsen.co/en/blog/humanity-crypto-token-compromise-social-engineering-phishing-analysis): A recent token compromise shows the real attack surface of a Web3 and crypto business is its people. Here's the social engineering... - [Cybersecurity Awareness Training for MiCA Compliance: Managing Human Risk for Crypto Services](https://arsen.co/en/blog/mica-compliance-security-awareness-training): MiCA institutes uniform EU market rules for crypto assets and requires CASPs to run cybersecurity measures aligned with DORA, prove... - [Why Crypto Firms are More Targeted by Phishing Scams than Others](https://arsen.co/en/blog/why-crypto-firms-are-primary-social-engineering-targets): Crypto firms combine irreversible assets, globally distributed teams, complex contractor networks, and immature human risk programs;... - [The 2026 Crypto CISO Checklist: How to Protect Crypto & Blockchain Companies Against Social Engineering and Data Breaches](https://arsen.co/en/blog/crypto-blockchain-ciso-social-engineering-checklist-2026): Social engineering, not smart contract exploits, is now the primary attack vector against crypto firms. Arsen offers a comprehensive... - [Social Engineering Threats Targeting Crypto Teams: 7 Attack Tactics to Know](https://arsen.co/en/blog/social-engineering-threats-targeting-crypto-blockchain-teams): Most crypto security incidents start with human manipulation. These are the 7 social engineering techniques most actively used against... - [Microsoft 365 and Azure Social Engineering Threats You Need to Know About](https://arsen.co/en/blog/microsoft-365-azure-attacks-social-engineering): The FBI and Microsoft both flagged active attacks against M365 and Azure in May 2026. Both bypass MFA. Neither uses malware. Both start... - [We're Building the Future of Human Risk Management, and We're Hiring](https://arsen.co/en/blog/cybersecurity-product-mission-statement): Most breaches start with a human mistake. Arsen is building the tools to fix that and hiring the team to accelerate. Here's our product... - [From Reactive to Resilient: A Practical Guide to Cyber Security Awareness That Actually Works](https://arsen.co/en/blog/cyber-resilience-security-posture): Recent CISO surveys point to a more complex threat landscape: AI is accelerating attacks and amplifying risk, even as it offers powerful... - [MITRE Fight Fraud Framework (F3): What It Is and Why It Matters](https://arsen.co/en/blog/mitre-fight-fraud-framework-f3): The MITRE Fight Fraud Framework (F3) is a structured, analyst built knowledge base of tactics, techniques, and sub techniques used by... - [Why Vishing Has Become the Main Cyber Threat, And What to Do About It](https://arsen.co/en/blog/vishing-main-threat-vector-2026): Vishing has overtaken email phishing as the go to attack vector for threat actors in 2025. Google and Mandiant's M Trends 2026 report... - [Introducing the New Arsen Cyber Awareness Training Platform](https://arsen.co/en/blog/arsen-new-cyber-awareness-training-platform): For the past few weeks, we’ve been gradually deploying a redesigned security awareness training module, progressively available to all... - [Why Basic Phishing Training Won't Stop AI Social Engineering](https://arsen.co/en/blog/ai-social-engineering-awareness-training-finance): Annual phishing training built around spotting typos and suspicious sender addresses doesn't address AI enabled social engineering. In... - [AI Vishing: Why Finance Teams Are the New Front Line](https://arsen.co/en/blog/ai-vishing-attacks-finance-defense): AI voice cloning has collapsed the cost of vishing from hundreds of dollars per targeted call to effectively zero at scale. Finance,... - [Deepfake Fraud in Financial Services: What CISOs Need to Do Now](https://arsen.co/en/blog/deepfake-fraud-financial-services-ciso-guide): Deepfake fraud is now an active loss event for financial institutions. Over $200 million in financial losses were attributed to deepfake... - [VENOM: Inside a C-Suite Credential Theft Campaign That Neutralizes MFA](https://arsen.co/en/blog/c-suite-credential-theft-campaign-that-neutralizes-mfa): Abnormal Intelligence documented VENOM, a previously unknown PhaaS platform behind a five month campaign targeting C suite executives... - [From a CEO Impersonation, a Slack Lure to a Full-On Compromise: The Axios & UNC1069 Case](https://arsen.co/en/blog/ceo-impersonation-slack-lure-social-engineering-attack-analysis): The recent Axios npm supply chain attack, attributed to UNC1069 (suspected North Korean actors), was not a technical exploit. It was a... - [Google Safe Browsing: How to Recover from a Domain Flagging](https://arsen.co/en/blog/how-to-recover-flagged-phishing-simulation-domains): Phishing simulation domains can get flagged by Google Safe Browsing even when used for legitimate security testing. Here's how to... - [Google Safe Browsing: How to Stay Invisible to Google's Bots](https://arsen.co/en/blog/how-to-stay-invisible-to-google-bots): Google Safe Browsing protects billions of devices — but it can disrupt authorized phishing simulations. Discover multi layered anti... - [Google Safe Browsing: How Does It Work?](https://arsen.co/en/blog/google-safe-browsing-how-does-it-work): Google Safe Browsing protects billions of users from malicious websites and phishing threats. But for organizations running internal... - [How to Defend Against Advanced Smishing Attacks (and Why Basic Training Isn't Enough Anymore)](https://arsen.co/en/blog/smishing-attacks-how-to-defend): Smishing has moved well beyond a fraudulent text. From MitM OTP hijacking to cross channel escalation, here's how sophisticated SMS... - [ClickFix Attacks: How Hackers Make Your Employees Run Malware Themselves](https://arsen.co/en/blog/clickfix-attacks-targeting-microsoft-cloudflare-and-crypto): ClickFix is one of the fastest growing social engineering attack techniques. It needs no exploit, no malicious attachment, just a fake... - [AI-Enhanced Vishing in Financial Services: How Voice Cloning Is Outpacing Your Defenses](https://arsen.co/en/blog/ai-voice-cloning-vishing-attacks-financial-services): AI voice cloning has turned vishing into a scalable, high precision weapon against financial institutions. A Canadian insurer lost $12M... - [Supply Chain Attacks in Financial Services: Why Your Vendors Are Becoming Your Biggest Vulnerability](https://arsen.co/en/blog/supply-chain-attacks-third-party-risk-financial-services): Your perimeter controls mean nothing if an attacker compromises a trusted vendor first. The SitusAMC breach in November 2025 exposed... - [Deepfake Video Impersonation: The Threat Financial Institutions Can No Longer Ignore](https://arsen.co/en/blog/deepfake-video-impersonation-financial-services): Deepfake video impersonation has crossed from theoretical risk to documented loss. The 2024 Arup attack cost $25 million after a finance... - [New: simulate ClickFix attacks on your workforce to identify who needs training before it's too late.](https://arsen.co/en/blog/clickfix-attack-simulation-employee-security-training): ClickFix attacks trick employees into running malware themselves, without any exploit needed. Learn how this fast growing threat works,... - [ The Financial Services CISOs White Paper: Navigating Cyber & AI Regulations in 2026](https://arsen.co/en/blog/ai-regulatory-risks-financial-services-ciso-2026): AI regulation is accelerating fast. From DORA to the EU AI Act, financial services CISOs face a tightening compliance landscape in 2026.... - [AI-Powered Social Engineering in Financial Services: What Every CISO Needs to Know in 2026](https://arsen.co/en/blog/ai-social-engineering-threats-a-2026-ciso-guide-for-finance): AI powered social engineering is reshaping the threat landscape for banks, insurers, and fintechs. This guide gives financial services... - [Microsoft Entra Users: Be Careful, You Might Be the Target of a New Vishing Campaign](https://arsen.co/en/blog/vishing-microsoft-entra-device-hacking): ShinyHunters are exploiting a legitimate Microsoft OAuth feature to compromise Entra accounts. No fake login page, no stolen password.... - [Figure Data Breach: Social Engineering Actors Are Preying on Fintechs, but It’s Not a Fatality](https://arsen.co/en/blog/fintech-social-engineering-attacks-how-to-fight-back): Blockchain lending firm Figure confirmed a significant data breach resulting from a social engineering attack on an employee, leading to... - [The Era of "Dark LLMs": How AI is Supercharging Social Engineering](https://arsen.co/en/blog/dark-llm-social-engineering): The AI revolution of the 2020s has positioned Large Language Models (LLMs) as the new foundation for digital transformation. With... - [How Sophisticated Vishing Attacks are Currently Bypassing SSO for Wide-Scale SaaS Data Theft](https://arsen.co/en/blog/vishing-bypassing-sso-saas-data-theft): The ShinyHunters group is currently orchestrating vishing attacks and exploiting SSO to bypass multi factor authentication. These... - [The New Vishing Playbook: Attackers Can now Control the Flow in Real-Time and Break SSO](https://arsen.co/en/blog/the-new-vishing-kits-let-attackers-control-the-flow-in-real-time-and-break-sso): Identity attacks are evolving into hybrid vishing operations. New phishing kits allow attackers to manipulate a victim’s browser in real... - [New in Arsen: Turn a Simple Prompt into a Comprehensive Defense Strategy](https://arsen.co/en/blog/arsen-product-update-ai-assisted-cybersecurity-awareness-training-building): Our latest release note: Building effective cybersecurity training takes time. Arsen’s new AI assisted builder combines hyper realistic... - [How Quishing Can Be Weaponized to Target Top Organizations: The North Korea’s Kimsuky Case](https://arsen.co/en/blog/how-quishing-can-be-weaponized-to-target-top-organizations): The FBI warns that North Korean group Kimsuky is using quishing to target organizations. Discover how bad actors exploit QR codes to... - [The InboxPrime Case: AI-Based Phishing Kits, Or The New Frontier of Credential Theft](https://arsen.co/en/blog/ai-based-phishing-kits-or-the-new-frontier-of-credential-theft): AI and LLMs are creating a paradigm shift in cyberattacks. Attackers now use AI powered kits to automate the entire attack lifecycle... - [The BlackForce MitM Phishing Kit & MFA Hijacking: When Your Credentials Are No Longer Enough](https://arsen.co/en/blog/the-blackforce-mitm-phishing-kit-and-mfa-hijacking): Phishing has evolved. Zscaler ThreatLabz recently revealed BlackForce, a toolkit hijacking active sessions and bypassing MFA, using the... - [Vishing Training Platforms for Call Center Teams](https://arsen.co/en/blog/vishing-training-platforms-for-call-center-teams): Call centers are prime targets for voice phishing due to high pressure environments and shared access. Discover why specialized vishing... - [Vishing Training for Financial Services Teams](https://arsen.co/en/blog/vishing-training-for-financial-services-teams): Protect your financial institution from voice phishing. Learn why vishing targets banking and fintech teams, the limitations of... ## Full content - [llms-full.txt](https://arsen.co/llms-full.txt): Full text of Arsen's evergreen resource guides and definitions. - [Sitemap](https://arsen.co/sitemap.xml)