AI made phishing impossible to spot. heed trains your team to catch it anyway.

Three-minute lessons on AI threats, plus phishing tests built from your team's own Slack and tools. Real practice, no shaming, no annual video.

See how it works
beta opens summer 2026
heed.sh / learn / deepfakes / practice-02
Practice · 02 / 04

A Loom from your CEO appears in #leadership. The request: wire approval before EOD. What's your first move?

Two minutes of public conference audio plus a recent headshot is enough to produce a believable deepfake. The lips sync. The voice cadence is right.

1 Reply in-thread to confirm, channel context makes it safe
2 Verify through a second channel before money moves: call, in-person, or signed memo
3 Check the Loom URL for signs of spoofing
4 Forward to your manager and wait for guidance
⌘K commands14 select · submitmodule 2 / 4 · streak 12d

Every lesson and phish rolls up into a per-person risk score and one-click SOC 2 / ISO 27001 evidence.

01 · Learn

Three-minute lessons on the threats your annual video skips.

A skill tree of today's threats: voice clones, deepfakes, prompt injection, agent abuse. New ones become lessons within a week of their first documented use in the wild.

lesson · spot the tellsocial engineering · 3 min

The Slack from your designer is grammar-perfect, tone-exact, and asking for the staging credentials. What's the tell?

AI-written phishes don't have the broken English or copy-paste artifacts your team learned to spot. The signals shifted, so the training has to shift with them.

1 A typo in the company name
2 The request bypasses your usual approval channel
3 The Slack handle has a number suffix
4 The timing is unusual for that teammate

02 · Practice

A real phish lands in their inbox, days after the lesson.

Built from your channels, your tools, your team's writing style. Practice is part of the path. Not a separate product, not a separate campaign, not a separate dashboard to log into.

Alex Mendez <[email protected]>Today, 9:42 AM
to: you

Q3 audit invoice: quick sign-off before EOM close

Hey, finance flagged this for your sign-off before the EOM close on Friday. The Slack thread in #procurement is moving fast, so could you take a look today?

I attached the vendor breakdown. Same format as last quarter. The numbers track with what we projected in the Q2 review.

Alex

This is a simulation. AI-generated to reference a real channel (#procurement) and your team's writing cadence. In the wild, you'd spot the domain (vendor-portal.io, not your real vendor) and the urgency-as-pressure tactic. Catch it: streak grows. Fall: 2-min debrief, no manager email.
live · simulationscheduled · 4 business days after module completion · references #procurement, #finance

03 · Debrief

Catch or fall. Both teach.

No manager notification. No record against the employee's review. Shame-based testing teaches people to hide clicks, and hidden clicks are worse than being phished.

debrief · q3 audit invoicemissed · 3 signals · no manager email

Three things this phish counted on you missing:

1
Sender domainvendor-portal.io spoofs your real vendor portal (vendor.heed-corp.com). On mobile you saw the display name, not the domain.
2
Urgency cue“EOM close on Friday” and “moving fast” press past your usual verify-before-approve instinct. Real internal asks rarely lead with urgency.
3
Reference to real channelThe mention of #procurement signals familiarity. Attackers who scrape your Slack metadata can do this. Familiarity isn't authentication.

Founding cohort. One-on-one. This summer.

Get on the list and we'll reach out before the beta opens.