Press ReleaseCloud SecurityCyber Crime & ForensicCyber SafetyThreat Detection & Defense

KnowBe4 Expands Gamified Training Library With Launch of ‘Spot the Vish’ Game

Real-time voice phishing simulation aims to help organisations combat social engineering attacks

KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the official launch of its 35th interactive game, Spot the Vish. This latest addition to the KnowBe4 game library is designed to train the digital workforce to recognise, resist, and report voice phishing (vishing) attacks in real time.

Vishing attacks have grown increasingly sophisticated, often involving bad actors posing as IT support or C-level executives to create artificial crises and manipulate employees into handing over sensitive credentials. Phone-based vishing attacks increased 449% according to the KnowBe4 2025 Phishing Threat Trends Report Volume Six. Spot the Vish addresses this growing threat by putting users into realistic audio scenarios where they must make split-second decisions to protect their organisation.

“An urgent call from what seems to be IT or a high-ranking executive with a high-pressure request for a password or large wire transfer can happen to any employee at any time,” said Isida Drake, SVP of Security & Compliance eLearning, KnowBe4. “We have gamified the critical threat vector of vishing into an interactive simulation where employees learn in an engaging and memorable way. By participating in the new Spot the Vish game, employees develop the muscle memory needed to help protect their organisations by stopping vishing attacks.”

Spot the Vish transforms passive training into an active problem-solving experience through several engaging mechanics like the scam-o-meter, which allows players to watch the threat level rise in real time as red flags pop up throughout the conversation. Users must choose whether to shut down the scam, safely verify the caller’s identity through official channels, or risk falling for the trick. Employees can earn top points, dodge penalties, and rack up performance badges, fostering healthy competition and high knowledge retention.

Spot the Vish joins a robust lineup of high-impact, fan-favourite titles, including: Danger Zone, the Spot the Phish series, Share If You Dare and The Inside Man. The KnowBe4 game library delivers gamified learning experiences designed to maximise user engagement and customers find the variety of materials useful and applicable to a global audience given the offerings in multiple languages, including a customer on G2: “KnowBe4 provides ongoing, customisable phishing simulations that mimic real attacks. It also helps employees recognise and respond to phishing in a safe environment. KnowBe4 provides a wide variety of training materials (videos, games, quizzes, posters) in multiple languages. Providing material in multiple languages is one of the very good features for global organisations.”

Spot the Vish is now available to KnowBe4 customers through the updated, AI-enabled ModStore. To learn more about how KnowBe4 secures the digital workforce through gamified training, visit www.knowbe4.com.

———————— HERE IS THE OTHER ————————–

CrowdStrike 2026 Technology Threat Landscape Report: China Steals AI Capabilities It Can’t Build

Technology is the world’s most targeted industry as adversaries exploit the AI being built and the tools used to build it

CrowdStrike has released the CrowdStrike 2026 Technology Threat Landscape Report, revealing that China-nexus adversaries are escalating espionage against technology organizations to steal the AI capabilities and intellectual property they cannot build fast enough on their own. With the world’s most valuable AI assets concentrated inside technology firms, the sector is now the most targeted industry in the world, and China-nexus adversaries drove more than 58% of state-sponsored targeted intrusions against it.

At the same time, DPRK-nexus adversaries are accelerating fraudulent IT worker schemes to funnel revenue to the regime, while eCrime actors are weaponising AI and turning the developer ecosystems behind it into attack vectors. The report makes it clear: the same innovation that makes technology valuable makes it the adversary’s primary target.

Technology Threat Landscape Report Highlights:
Based on frontline intelligence from CrowdStrike’s Counter Adversary Operations tracking more than 280 named adversaries, the report reveals:
China-Nexus Adversaries Steal Technology to Fuel Beijing’s AI Ambitions: China-nexus adversaries – including MURKY PANDA, MUSTANG PANDA, OVERCAST PANDA, SUNRISE PANDA, and WARP PANDA—targeted technology more than any other industry. MURKY PANDA’s password-spraying campaign alone impacted more than 340 U.S.-based entities.
DPRK Embeds Operatives Inside Tech Using AI: FAMOUS CHOLLIMA used AI-enhanced personas and U.S. front companies to secure remote IT roles inside technology firms, accounting for 47% of all state-sponsored interactive intrusions against the sector and channeling illicit revenue directly to the regime’s weapons programs.
Cybercriminals Accelerate Access for Extortion: Financially motivated attacks accounted for 65% of all interactive operations against the sector. Initial access brokers advertised access to 277 technology organizations, a nearly 30% increase, while big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.
eCrime Groups Weaponize AI to Scale Attacks: Adversaries used AI-generated scripts to dump credentials and erase forensic evidence at machine speed, collapsing the time defenders have to respond. Across the broader eCrime landscape, actors exploited surging AI adoption—distributing Skrawl, a novel macOS information stealer, through fake OpenClaw extensions and counterfeit download sites impersonating legitimate AI tools.Adversaries Infiltrate Developer Supply Chains: STARDUST CHOLLIMA compromised the Axios NPM package – downloaded 100 million times per week—likely exposing millions of downstream users, poisoning open-source supply chains. Separately, prior to CrowdStrike’s disruption of the Glassworm botnet, malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects, targeting software development ecosystems.

“Technology organisations are building the most valuable and most targeted assets in the world. Every AI breakthrough creates a competitive advantage and new attack surface at the same time,” said Adam Meyers, head of counter adversary operations at CrowdStrike. “China runs cyberespionage as industrial policy to try to close the AI innovation gap, demonstrating that AI capabilities are the prize adversaries are after. Whether you’re building AI or adopting it, security has to be built in from the start.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *