Skip to content

Technology

Engineers are targeted differently

Nobody is sending your platform team an obvious invoice scam. They are getting OAuth consent screens, package-registry lures, CI token requests and push notifications at 02:00 — and a generic awareness course insults them without teaching anything.

Tier 5
OAuth and CI-token lures
API
campaign automation
SCIM
at any headcount
HOW THIS WORKFORCE IS REACHEDEmail96%OAuth38%SMS16%TRADECRAFT AIMED AT THEMConsent screens, CI tokens, MFA prompt storms18%3%Initech · 1,800 people · three quarters

Credibility

Scenarios that respect the audience

Consent-screen abuse, a dependency that asks for a token, an MFA prompt storm, a recruiter with a take-home repository. If the lure is not plausible to an engineer, the result tells you nothing except that they can spot a bad one.

  • MFA fatigue and push-bombing sequences
  • OAuth consent and device-code flows
  • Package-registry and CI-token pretexts
ReportedOne click, Outlook / GmailSimulationScored · reporter thankedReal threatHeaders, URLs, hashesRisk ScoreSOC / SIEM
The reporter never has to know which it was — classification and routing happen after the click.

Operations

Programme as code

Create audiences, launch campaigns and read results over the API, so the awareness programme lives in the same automation as everything else your team runs rather than in a console somebody logs into monthly.

  • REST + signed webhooks
  • Terraform-friendly tenant configuration
  • Events into your existing SIEM
0%10%20%30%40%Baseline: 33.2% phish-prone33.2%Baseline90 days: 20.1% phish-prone20.1%90 days12 months: 4.2% phish-prone4.2%12 months−87%
Phish-prone rate over 12 months of continuous simulation and training. Source: KnowBe4 2026 Phishing by Industry benchmark (33.2% → 20.1% → 4.2%).

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

1 questions

Our engineers will spot every simulation. Is this pointless?

They spot tier one. Tier five is a thread hijack referencing a real internal project, or a consent screen for an app with a plausible name — and the results are consistently humbling. The interesting metric for engineering populations is report rate, not click rate.

Try a tier-five scenario on your platform team

Pick a test group. We will build something they have not seen before.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.