Phishing, Social Engineering and Scam Awareness

For all employees, especially finance, HR and admin staff: spot phishing in every channel, verify before you pay, and report fast.

For: All employees, with extra depth for finance, accounts payable, payroll, HR, executive assistants and office administrators

  • 2 contact hours
  • 7 modules
  • 9 interactives
  • 4 job aids
  • Updated October 7, 2026

What you will be able to do

  • Recognize the main phishing and social-engineering attack types, including spear phishing, whaling, smishing, vishing, callback phishing, QR-code phishing, MFA fatigue and business email compromise, and the persuasion tactics they use.
  • Identify warning signs in emails, texts, calls, links, attachments and QR codes using a repeatable five-point inspection routine.
  • Verify payment, bank-change and sensitive-data requests out of band before acting, and apply business controls that stop payment fraud.
  • Protect work accounts by choosing phishing-resistant MFA where available, responding correctly to unexpected MFA prompts, and following NIST SP 800-63B-4 password practices.
  • Report suspicious messages and incidents correctly, internally first and then through APWG, 7726, ReportFraud.ftc.gov, IC3, IdentityTheft.gov or CISA, and respond appropriately to simulated phishing exercises.

Learn how phishing and social engineering really work, from spear phishing and whaling to smishing, vishing, callback scams, QR-code phishing and MFA push bombing. You will practice reading suspicious emails, texts and calls with a repeatable inspection routine, verify payment and data requests out of band, and walk through what to do in the first hour after a click.

This course is built for every employee, with extra depth for the people attackers target most: accounts payable, payroll, HR, executive assistants and office managers. Supervisors will also find guidance on responding to reports and running fair phishing simulations.

Phishing is the doorway to most costly fraud. In 2025, the FBI's Internet Crime Complaint Center (IC3) logged more than one million complaints and about $20.9 billion in reported losses, including about $3.05 billion from business email compromise. This course uses only defanged examples, current CISA, FTC, FBI and NIST guidance, and practical tools you can use on Monday: a phishing checklist, an incident report template, an account security checklist and a callback script.

What you’ll be able to do Monday morning

  1. Run the five-point check (sender, reply-to, request, pressure, payload) on any unexpected message before clicking or replying.
  2. Verify every bank-detail change, wire, gift card request or bulk data request with a callback to a contact you already had.
  3. Deny and report any MFA prompt you did not start, and never read a code aloud to anyone.
  4. Report suspicious messages through your workplace's official channel, including near misses and simulations.
  5. Know exactly what to do in the first hour after a click, using the incident report template.

Curriculum

7 modules · 26 lessons · about 2 contact hours

01Why does phishing still work on smart, careful people?Free preview14 min
  1. What is phishing, and what are criminals really after?
  2. How big is the problem in the United States?
  3. Which psychological buttons do attackers push?
  • Matching activity: Match the persuasion lever

Diagram · In practice checklist · 2-question knowledge check

02What shapes does phishing take beyond email?15 min
  1. How do targeted attacks differ from mass phishing?
  2. How do attackers research you before a targeted attack?
  3. What are smishing, vishing and callback phishing?
  4. What are QR-code phishing, MFA fatigue and in-person social engineering?
  • Spot the issue: Spot the warning signs: Hank's text and call
  • Sort activity: Name that attack

Diagram · In practice checklist · 3-question knowledge check

03How do you read a suspicious message like an investigator?15 min
  1. What should you check first in any email?
  2. How do you read a web address correctly?
  3. How do you check texts, calls and QR codes in the moment?
  4. What do annotated real-world patterns look like?
  • Spot the issue: Spot the warning signs: the W-4 verification email

Diagram · In practice checklist · 2-question knowledge check

04How do business email compromise and payment fraud work, and how do you verify before you pay?16 min
  1. What is business email compromise?
  2. What is out-of-band verification, and how do you do it right?
  3. What do strong verification habits look like in payroll, HR and admin roles?
  4. Which business controls stop payment fraud even when someone is fooled?
  • Decision tree: Should I act on this request?
  • Branching scenario: The Friday wire

Diagram · In practice checklist · 2-question knowledge check

05How do you protect your accounts when a phish gets through?15 min
  1. Why does MFA matter, and why are some types stronger than others?
  2. What do you do when MFA prompts you didn't request keep coming?
  3. Which everyday account habits shut the door on phishers?
  • Self-assessment: How strong are your phishing defenses?

Diagram · In practice checklist · 3-question knowledge check

06What should you do in the first hour after you click?14 min
  1. Why is reporting fast more important than feeling embarrassed?
  2. What are the right steps for each kind of mistake?
  3. How did Teodora's story end, and what should you document?
  4. How should coworkers and supervisors respond when someone reports a click?
  • Decision tree: I think I fell for a phish: what now?

Diagram · In practice checklist · 2-question knowledge check

07Where do you report scams, and how do phishing simulations help?14 min
  1. Where does each kind of report go?
  2. What are simulated phishing exercises, and what are they for?
  3. What should a workplace phishing and reporting policy include?
  4. How should you respond to simulations, and how do they stay fair?
  • Matching activity: Match the situation to the reporting route

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 70% to pass, then your certificate

Try it now, no account needed

The Friday wire

A branching scenario from this course. Your choices are not saved.

Free sample activity

The Friday wire

Obinna Udeh is the controller at a family-owned marine supply distributor in Port Arthur, Texas. The owner, Lucinda Marsh, is at a trade show in Las Vegas this week. It is 3:30 p.m. on Friday.

Inside the course

Practice activities

  • Matching activity2
  • Spot the issue2
  • Sort activity1
  • Decision tree2
  • Branching scenario1
  • Self-assessment1

Job aids you keep

  • Phishing Checklist: Pause, Inspect, Verify, ReportChecklist
  • Suspected Phishing Incident ReportTemplate
  • Account Security ChecklistChecklist
  • Callback Verification Pocket CardPocket card

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 2 contact hours of instruction. It has not been approved or accredited by IACET, NASBA, any state board of accountancy, any licensing board or any other accreditor, and it is not a government training program. It is general awareness training aligned with public guidance from CISA, the FBI's IC3, the FTC and NIST. Check with your employer, licensing board or professional body whether this course can count toward your security-awareness training records or continuing education.

Pathways we are pursuing or may pursue include IACET accreditation of our course development process and, where eligible, registration as a NASBA continuing professional education (CPE) sponsor. No approval exists today; we will show any approval on this page only after it is granted.

Our full approvals list

Questions about this course

Who is this course for?

It is for all employees, with extra depth for people who handle money, data or access: accounts payable, payroll, HR, executive assistants, office managers and front-desk staff. Supervisors will find guidance on responding to reports and supporting phishing simulations. No technical background is needed, and the course uses only defanged, non-clickable examples.

Does this course earn CE or CPE credit?

You receive a certificate of completion for 2 contact hours of instruction. The course is not currently approved or accredited by IACET, NASBA, a state board or any other accreditor. Check with your employer, board or professional body whether it can count toward your training or continuing education records.

Will this satisfy my employer's annual security-awareness training?

That depends on your employer's policy, contracts and any industry rules that apply to them. Many employers accept outside awareness courses, but some require their own training. Ask your manager, IT or compliance team before enrolling, and share the course outline and objectives with them if helpful.

How long does it take?

Plan on about 2 hours, including seven short modules, interactive practice activities, knowledge checks and a 23-question final assessment with a 70% pass mark. You can pause and return at any time, and your progress is saved.

Is the content different by state?

The skills taught here follow federal guidance from CISA, the FBI, the FTC and NIST, and apply nationwide. Related rules, such as data breach notification laws, vary by state; your organization's privacy or legal team decides how those apply after an incident.

Does the course teach hacking or how to run attacks?

No. The course covers prevention, recognition, verification and reporting only. All example links are defanged so they cannot be clicked, and simulated phishing is discussed only from the point of view of employees and the organizations that run fair, announced programs.

This course is general education and cybersecurity awareness training from CE Courses Hub. It is not legal, financial or professional advice and does not replace your employer's security policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.