Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Interactive 3D

Interactive 3D Training

Most security training is a video with a quiz at the end. RansomLeak drops each person into an immersive 3D scene with a working desktop and phone, where they open the real phishing email, answer the suspicious call, and find out what their choices set off. It runs in any browser. No headset, no install.

How an interactive 3D exercise works

Four steps that feel less like a course and more like a Tuesday at work.

01

Step into the scene

Each exercise opens in a 3D room, a home office or the dual room where you also see the attacker. The scenario plays out around you, narrated as it unfolds.

02

Use a real desktop and phone

Click the monitor to open a working email client, browser, terminal, or password manager. Pick up the phone to take the call or read the text. It behaves like the real thing.

03

Make the call yourself

Open the attachment or do not. Answer the call or hang up and verify. Type the command, approve or deny the prompt. You perform the action, you do not watch a recording of it.

04

Live the consequence

The simulation reacts: a fake login captures your credentials, a bad approval triggers the ransom screen, the right move contains the damage. A short knowledge check locks in the lesson.

Where the training actually happens

Every exercise is set in a room the learner can look around. Pick the one that matches how your people work, or let the scenario pick it.

Isometric 3D render of a home office with a two-monitor desk, a bed, a bookshelf, a router on the shelf and a whiteboard
Isometric 3D render of an open-plan office with three desks, a shared whiteboard, a printer, a paper shredder and a water cooler
Isometric 3D render of the attacker’s room: a dark bedroom with hexagonal wall lights, a single monitor on a desk, a bed and a skateboard on the floor
The dollhouse layout: the learner’s home office above, and the attacker’s room below it, both rooms visible in one scene

Home office

A desk with two monitors, a bed in the corner, the router sitting on the shelf where nobody has touched it since it was installed. Remote work is where most of these attacks land, so this is the room most exercises open in.

  • Two monitors
  • Laptop
  • Phone
  • Router
  • Whiteboard
  • USB drive
  • External SSD
  • Headphones

Your administrator sets the default room for the whole organisation. Learners can switch rooms in their own settings, and a scenario that only makes sense in one of them pins itself there.

A real computer, not buttons on a video

The attack happens where work happens, on a simulated desktop that behaves like the one in front of you.

The simulated Windows desktop on the 3D monitor inside the scene, a full desktop with app icons and a taskbar, the same kind of workspace the attack plays out on

A full working desktop

Outlook, a browser with hundreds of real-looking sites, a terminal, a file manager, a password manager, an HTTP inspector, even AI assistant and agent consoles. More than twenty apps, all live.

You do the real thing

Hover the real sender domain, read the real headers, run the real command, toggle the real setting. Every input is checked against what a careful person would actually do.

No autofill, no shortcuts

The fake login pages defeat password managers on purpose, so people practice spotting a lookalike instead of letting the browser fill it in for them.

And a real phone in your hand

Smishing, vishing, and MFA fatigue play out on the device people actually fall for them on.

A 3D phone in the scene showing an incoming call from an unknown number with a slide-to-answer control, the way a vishing call actually arrives

Calls, texts, and push prompts

A simulated phone with messages, calls, an authenticator, and a banking app, locked behind a PIN, so a vishing call or a fraudulent MFA push lands exactly as it would in real life.

Answer it, or do not

You pick up the unknown caller, read the text from the bank, approve or deny the login prompt. The same small decision the breach hinged on is the one you practice here.

One scene, two screens

The desktop and the phone are part of the same room, so a scam that starts with a call and finishes in your inbox is one continuous exercise, not two disconnected modules.

See the attack from both sides

Start inside the incident, then watch the attacker work the other end of it in real time.

The dual-room view: the employee office above and the attacker room below, where the threat actor works the other side of the same incident

The wall drops away

You begin as the employee. On the first turn the camera pulls back and the attacker’s room appears below yours, where they scan for your leaked key, craft the lure, and move on the same incident.

Understand the why, not just the what

Seeing both ends of an attack is what turns "do not click links" into a real instinct for how these attacks are actually built and run.

Built for the threats people face now

Over 200 exercises across phishing, ransomware, deepfakes, GDPR and the EU AI Act, and a full OWASP track for web, LLM, and agentic AI attacks, including AI agent goal hijacking. Browse the catalogue.

Interactive 3D against video and quiz

Both count as training on a compliance report. Only one of them rehearses the decision.

An interactive 3D exercise

  • You decide whether to click, on a desktop that behaves like the one in front of you.
  • The fake login defeats your password manager on purpose, so you have to read the domain yourself.
  • A wrong move plays out: credentials captured, the ransom screen, or the damage contained.
  • The phone rings during the exercise, so a scam that starts with a call and ends in your inbox stays one story.
  • You watch the attacker work the other end of the same incident.
  • The knowledge check asks about the decision you just made.

A video with a quiz

  • You watch an actor click, then answer questions about the video.
  • Autofill quietly solves the lookalike domain the lesson was about.
  • The consequence is described rather than experienced, so it stays abstract.
  • Phishing, smishing and vishing arrive as three unrelated modules.
  • The attacker is a stock photo in a hoodie, not a working method.
  • The quiz asks whether you were paying attention.

Every object in the room is part of the lesson

Open the email, pick up the router, plug in the USB you found, set up the backup drive. Every prop and every screen is interactive, and each one hides a habit worth practicing.

The Outlook email client on the 3D desktop with a phishing email open and a Report button in the toolbar
A phishing email in the inbox. Report it, or click the link and find out.
A fake bank login page open in the simulated browser, asking for an email address and password
A lookalike bank login in the browser, built to harvest the password you type.
The simulated phone messages app showing a smishing text with a fake parcel-delivery link
A smishing text with a fake delivery link, waiting in the messages app.
Close-up of the 3D router in the scene, its label sticker showing the admin password still set to the factory default of admin
The router still has its factory password on the sticker. Change it before someone else reads it.
A whiteboard in the 3D office with a password written on it in marker, in plain view
A password written on the whiteboard, in plain view of anyone who walks past.
3D headphones in the scene with a glowing blue light showing they are left discoverable to nearby devices
Headphones left discoverable, broadcasting to every device in range.
A laptop in the 3D scene showing a Windows lock screen with a PIN prompt
A second machine, locked behind a PIN. Walk away and it stays that way.
A USB flash drive labelled Confidential, Salary Data, the kind left in a lobby as bait
A USB drive labelled "Confidential" you find in the lobby. Plug it in, or do not.
An external SSD with a backup shield, connected to the PC to keep a copy of your files
An external SSD for backups. The line between a bad afternoon and a lost quarter.

What is interactive 3D security awareness training?

Interactive 3D security awareness training is security training delivered as a browser-based 3D simulation rather than a video. The learner stands in a rendered room with a working computer and phone, and handles a real attack by taking the actual steps: opening the email, checking the sender, answering the call.

What is in the room

  • 3D environment
  • Working desktop
  • Working phone
  • The attacker
  • Knowledge check

Nothing is narrated at you. The desktop runs more than twenty applications, the phone rings mid-scenario, and the simulation answers what you actually did rather than what a script expected.

It runs on WebGL in an ordinary browser, so there is no headset and nothing to install. Exercises take 5 to 15 minutes and end in a scored knowledge check, which is what makes them assignable as monthly training instead of a one-off event.

Frequently asked questions

What does it need to run, and do learners need a headset?

No headset and nothing to install. The 3D runs on WebGL in any modern browser, on the laptops and desktops people already have, including integrated graphics.

Application security exercises can also render as a flat 2D device view instead of the 3D room, which is the better fit when the work is reading code rather than walking around an office.

Can we choose which environment our people train in?

Yes. An administrator sets the default room for the whole organisation, and each learner can switch rooms in their own settings.

A scenario that only works in one of them, a shredder exercise for instance, pins itself to that room and quietly ignores both settings.

What topics and how many exercises are there?

Over 200 interactive exercises spanning phishing, smishing, vishing, business email compromise, ransomware, deepfakes, device and password security, GDPR and EU AI Act compliance, and the OWASP Top 10 for web, LLM, and agentic AI applications.

New exercises are added as the threats change, including AI-era attacks like prompt injection and AI agent goal hijacking. See the full catalogue, or the microlearning drills for the shorter format.

Does it map to the frameworks we report against?

Every exercise carries its own mapping to OWASP, CWE, MITRE ATT&CK, CIS Controls, NIST CSF, GDPR and the EU AI Act, so "do you cover this control?" is answered from data rather than from a sales claim.

Completions and quiz scores feed the same records, and the compliance mapping page shows which frameworks each track satisfies.

What languages is it available in, and how is it delivered?

Exercises are available in seven languages: English, Ukrainian, Dutch, Italian, German, French, and Spanish, with more on request.

Each exercise is a SCORM package, so it runs in any LMS via SCORM, or on the Cloud LMS with no integration work. Either way, completion and quiz scores report back to your records.

How long does an exercise take?

Most exercises run about 5 to 15 minutes. Each ends with a short knowledge check scored against a pass threshold.

That makes them short enough to assign as a monthly nudge and substantial enough to count as real training. Pair them with phishing simulations and the results roll into human risk management.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.

Isometric view of the 3D training room Desktop only

Best experienced on desktop

Our immersive 3D training room is built for larger screens. On a phone you get a simplified version of the tour.

  • 3D room
  • Widgets
  • Simulation