# RansomLeak > B2B security awareness training and Human Risk Management platform delivering interactive 3D cybersecurity simulations, gamified learning, and SCORM-compliant packages for enterprise organizations. Founded in 2025 in Estonia by the creator of Kontra Application Security Training. RansomLeak is a security awareness training and Human Risk Management (HRM) platform that measures and reduces the cyber risk introduced by employee behavior. It replaces traditional compliance-only training with interactive 3D simulations, behavioral analytics, and role-based coaching. Exercises cover phishing, ransomware, social engineering, vishing, smishing, business email compromise, deepfake whaling, USB drop attacks, AI prompt injection, GDPR, and the EU AI Act. Training is delivered as SCORM packages for any LMS or through a standalone cloud platform with SSO, analytics, and white-labeling. ## Platform & Product - [Homepage](https://ransomleak.com/): Security awareness training and Human Risk Management platform with interactive 3D cybersecurity simulations and enterprise deployment - [Platform Features](https://ransomleak.com/features/): Interactive 3D simulations, real-time analytics, SSO/MFA, gamification, custom content, third-party content uploads (PDFs, videos, presentations, SCORM packages), multilingual delivery in English, Ukrainian, Dutch, Italian, German, French, and Spanish (additional languages on request), and compliance reporting for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and NIS2 - [Interactive 3D Training](https://ransomleak.com/interactive-training/): Immersive browser-based 3D security awareness training where employees step into a rendered scene with a fully simulated desktop and phone, perform the real action (open the phishing email, answer the vishing call, run the command), and see the consequences; 100+ exercises across phishing, ransomware, deepfakes, GDPR, EU AI Act, and OWASP for web, LLM, and agentic AI, with a dual-room attacker view; no VR headset, runs as SCORM or on the Cloud LMS in 7 languages - [Human Risk Management](https://ransomleak.com/human-risk-management/): Closed-loop human risk management that measures and reduces employee security risk in one program: phishing simulations surface real behavior, a per-person human risk score quantifies it, and risk-based automation assigns the training that brings it down - [Human Risk Score](https://ransomleak.com/human-risk-score/): Per-person 0 to 100 human risk score built from phishing-simulation outcomes, phish reporting, and training and remediation status, with ~90-day recency weighting, a confidence rating, explainable per-person breakdowns, admin-tunable weights and bands, and org, team, and per-person dashboards (requires the phishing-simulations add-on) - [Risk-Based Automation](https://ransomleak.com/risk-based-automation/): No-code rules that auto-enroll high-risk employees in remediation training, deliver just-in-time training the moment someone fails a phishing simulation, and escalate at-risk staff to managers, with a dry-run preview, a full audit log, blast-radius caps, per-person cooldowns, and a global kill switch - [LMS Integration: SCORM & LTI](https://ransomleak.com/lms-integration/): Deliver security awareness training in any LMS via SCORM 1.2 and 2004 packages or an LTI 1.3 launch with automatic completion and score passback (LTI Advantage AGS); verified on Moodle and Canvas, and compatible with Cornerstone, Workday, SAP SuccessFactors, Docebo, Blackboard, and 50+ LMS platforms; free sample SCORM packages download without signup - [Cloud LMS](https://ransomleak.com/cloud-lms/): Hosted training platform with a course catalog, custom learning paths, campaigns with annual recurrence, live analytics and audit-ready compliance reporting, SAML 2.0 SSO, SCIM 2.0 provisioning, enforceable MFA, RBAC, white-label custom domain, and IP allowlisting - [Integrations](https://ransomleak.com/integrations/): Token-authenticated REST API, HMAC-SHA256-signed webhooks across 11 events with retries and delivery logs, HRIS user provisioning (HiBob natively, plus Workday/ADP/Rippling/BambooHR and 80+ systems through Merge), Slack and Microsoft Teams notifications, SIEM event export (JSON/CSV polling), an ICS calendar feed, and live Vanta, Drata, and Datadog evidence - [Okta SAML SSO setup](https://ransomleak.com/integrations/okta-saml-sso/): Configure SAML 2.0 single sign-on between Okta and RansomLeak - [Okta SCIM provisioning](https://ransomleak.com/integrations/okta-scim/): Provision and deprovision RansomLeak accounts from Okta over SCIM 2.0 - [Microsoft Entra SAML SSO](https://ransomleak.com/integrations/entra-saml-sso/): Configure SAML single sign-on between Microsoft Entra ID and RansomLeak - [Microsoft Entra SCIM provisioning](https://ransomleak.com/integrations/entra-scim/): Provision RansomLeak accounts from Microsoft Entra ID over SCIM 2.0 - [Jira Service Management](https://ransomleak.com/integrations/jira/): Assign a RansomLeak lesson from a Jira Service Management ticket and write completion back to the issue - [HiBob HRIS](https://ransomleak.com/integrations/hibob/): Connect HiBob natively so new hires, role changes, and departures drive security training automatically - [Merge HRIS](https://ransomleak.com/integrations/merge/): Connect Workday, ADP, Rippling, BambooHR, and 80+ HR systems through one Merge connection for lifecycle-driven training - [Vanta evidence](https://ransomleak.com/integrations/vanta/): Connect Vanta over OAuth to post training completion as live control evidence for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and CCPA - [Drata evidence](https://ransomleak.com/integrations/drata/): Stream training completion into a Drata Custom Connection and map it to controls with a Custom Test (SOC 2, ISO 27001, HIPAA, PCI DSS, NIS2) - [Datadog](https://ransomleak.com/integrations/datadog/): Turn a Datadog detection into a training assignment through a Workflow action, and stream training and human-risk events into Datadog - [Moodle LTI 1.3 setup](https://ransomleak.com/integrations/moodle-lti/): Connect RansomLeak to Moodle as an LTI 1.3 tool with single sign-on and automatic completion and grade passback to the Moodle gradebook (LTI Advantage AGS) - [Canvas LTI 1.3 setup](https://ransomleak.com/integrations/canvas-lti/): Connect RansomLeak to Canvas via a Developer Key over LTI 1.3 with single sign-on and automatic grade passback to the Canvas gradebook (LTI Advantage AGS) - [Phishing Simulations](https://ransomleak.com/phishing-simulations/): Phishing simulation add-on with M365 and Google Workspace mailbox injection, reporter buttons for Outlook and Gmail, full-funnel analytics (8 stages), automated remediation with learning paths, and legal compliance for GDPR Article 88 and works councils - [Smishing Simulations](https://ransomleak.com/smishing-simulations/): SMS phishing (smishing) simulation add-on with business-hours-gated delivery, click tracking, STOP and REPORT opt-out handling, an SMS analytics funnel, and automated remediation into learning paths - [Training Catalogue](https://ransomleak.com/catalogue/): 100+ free interactive cybersecurity exercises covering phishing, ransomware, AI security, GDPR compliance, and more with no sign-up required - [Free Exercise Library](https://ransomleak.com/learning/): Curated selection of free cybersecurity exercises with no sign-up required - [Open-Source Security Awareness Training](https://ransomleak.com/open-source-security-awareness-training/): 100+ free, CC BY-NC 4.0 licensed SCORM training packages published on GitHub (phishing, ransomware, GDPR, passwords, device security, OWASP Top 10 for LLM and agentic AI applications) that import into any SCORM 1.2 or 2004 LMS; download full course packages or individual exercises, fully white-labeled with no logos or backlinks - [Partnership Program](https://ransomleak.com/partners/): MSSP and technology partnerships with white-label training, API integration, and revenue sharing - [Compliance Mapping Guide](https://ransomleak.com/compliance-mapping/): See which RansomLeak exercises map to SOC 2, ISO 27001, GDPR, the EU AI Act, HIPAA, NIS2, PCI DSS, and DORA compliance requirements - [CISO Buyer's Guide](https://ransomleak.com/ciso-guide/): Evaluation framework for CISOs choosing security awareness training with 10 criteria and vendor comparison questions - [Vendor Comparison Hub](https://ransomleak.com/compare/): 15 security awareness training and Human Risk Management platforms compared across 7 evaluation dimensions, with links to seven head-to-head matchups and three multi-vendor roundups - [Industries Hub](https://ransomleak.com/industries/): Security awareness training tailored to 10 verticals (healthcare, financial services, government, manufacturing, retail, education, legal, SaaS, MSPs, non-profits) with industry-specific threat patterns, compliance frameworks, and featured exercises - [Use Cases Hub](https://ransomleak.com/use-cases/): 10 operational programs (employee onboarding, annual compliance, cyber-insurance readiness, audit evidence prep, remote workforce, contractor training, breach-response rehearsal, M&A due diligence, LMS migration, board reporting) with rollout playbooks, evidence packages, and recommended exercises - [Threat Library](https://ransomleak.com/threats/): Pillar guides on the cyber threats that drive most enterprise breaches, with attack stages, real-world case studies, defense framework, and recommended training scenarios - [Phishing Pillar](https://ransomleak.com/threats/phishing/): How phishing attacks work in 2026 across email, SMS, voice, QR, and chat, with named incidents (2024 Arup $25M deepfake, 0ktapus, Pepco €15.5M), 8-layer defense framework, and exercise sequence - [Ransomware Pillar](https://ransomleak.com/threats/ransomware/): How ransomware attacks unfold from initial access through encryption and double extortion, with named incidents (Change Healthcare, MGM, Cl0p MOVEit, LockBit), 9-control defense framework, and exercise sequence - [Deepfake Pillar](https://ransomleak.com/threats/deepfake/): How AI voice and video deepfake attacks impersonate executives to authorize wires, with named cases (Arup $25M, Ferrari challenge-phrase block, UK energy firm voice clone), 8-control defense framework, and exercise sequence - [Social Engineering Pillar](https://ransomleak.com/threats/social-engineering/): Cialdini six-principle framework, named cases (MGM Resorts 2023, 0ktapus / Twilio campaign, FACC and Toyota Boshoku CEO fraud), 8-layer defense framework, and channel-specific training (vishing, smishing, BEC, deepfake whaling) - [Business Email Compromise Pillar](https://ransomleak.com/threats/business-email-compromise/): The 5 BEC subtypes mapped to FBI taxonomy (CEO fraud, vendor invoice, attorney impersonation, payroll diversion, data theft), named cases (2024 Pepco €15.5M, 2024 Arup $25M, 2016 FACC €42M), DMARC and dual-authorization defense - [AI Prompt Injection Pillar](https://ransomleak.com/threats/ai-prompt-injection/): OWASP LLM01 explained for enterprise AI rollouts, named disclosures (Bing Chat / Sydney 2023, Slack AI 2024, Microsoft 365 Copilot EchoLeak 2024), direct vs indirect injection, and the 8-control defense framework - [Smishing Pillar](https://ransomleak.com/threats/smishing/): How SMS phishing exploits mobile trust and the missing email gateway, with named campaigns (0ktapus, Smishing Triad USPS and toll-road kits), FTC and FBI IC3 loss data, a 6-control defense framework, and exercise sequence - [Vishing Pillar](https://ransomleak.com/threats/vishing/): How voice phishing manipulates help desks and finance teams by phone, with named cases (MGM and Caesars 2023, Retool deepfake voice, Arup $25M), a 6-control defense framework, and training scenarios - [Compliance Frameworks Hub](https://ransomleak.com/compliance/): Framework pillar guides for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIS2, and the EU AI Act, with control references, audit failure modes, named enforcement actions, and exercise sequences that satisfy each framework - [SOC 2 Compliance Pillar](https://ransomleak.com/compliance/soc-2/): How SOC 2 Common Criteria CC1.4 governs security awareness for the SaaS trust attestation, with role-based training depth, Type I vs Type II evidence, and the auditor-ready exercise sequence - [ISO 27001 Compliance Pillar](https://ransomleak.com/compliance/iso-27001/): How ISO 27001:2022 Annex A 6.3 plus Clause 7.3 and 7.2 govern awareness, education, training, and competence, with the Stage 1 / Stage 2 / surveillance audit cycle and the October 2025 transition deadline - [HIPAA Compliance Pillar](https://ransomleak.com/compliance/hipaa/): How HIPAA §164.308(a)(5) and §164.530(b) govern security awareness and privacy training for PHI workforces, with named OCR settlements (Anthem $16M, Banner Health $1.25M, Lafourche $480K) and BA flow-down - [GDPR Compliance Pillar](https://ransomleak.com/compliance/gdpr/): How GDPR Article 39 and Article 32 govern employee data protection training across EU controllers and processors, with named DPA fines (H&M €35.3M, BA £20M, Uber €290M) and the Article 83(2)(d) mitigation calculus - [PCI DSS Compliance Pillar](https://ransomleak.com/compliance/pci-dss/): How PCI DSS v4.0.1 Requirement 12.6 governs the formal security awareness program for cardholder data environments, with v4.0 transition deadline (March 2025) and named breach cases (Target $202M, Home Depot $179M, Heartland $140M) - [NIS2 Compliance Pillar](https://ransomleak.com/compliance/nis2/): How NIS2 Article 21(2)(g) governs cyber hygiene and cybersecurity training across EU essential and important entities, with Article 20 management-body personal liability and the €10M / 2% turnover penalty regime - [EU AI Act Compliance Pillar](https://ransomleak.com/compliance/eu-ai-act/): How EU AI Act Article 4 (effective February 2025) makes AI literacy training mandatory for every provider and deployer, with the staged 2024-2027 timeline, Article 14 human-oversight training, and the Article 99 penalty regime up to €35M / 7% turnover ## Industries - [Healthcare Security Training](https://ransomleak.com/industries/healthcare/): HIPAA-aligned training for hospitals, clinics, and healthcare providers covering PHI handling, ransomware on clinical systems, and Security Rule § 164.308(a)(5) workforce training requirements - [Financial Services Security Training](https://ransomleak.com/industries/financial-services/): Training for banks, credit unions, asset managers, and insurers covering wire fraud, BEC, SOX 404, NYDFS Part 500, and FFIEC IT examination expectations - [Government & Public Sector Security Training](https://ransomleak.com/industries/government/): FISMA-aligned awareness training for federal, state, and local agencies with NIST 800-53 AT-2 mapping and CISA-aligned threat content - [Manufacturing Security Training](https://ransomleak.com/industries/manufacturing/): Training for OT/IT-converged manufacturers covering ransomware on production systems, supply-chain phishing, and ISO 27001 / IEC 62443 requirements - [Retail Security Training](https://ransomleak.com/industries/retail/): PCI DSS 4.0 awareness training for retailers covering point-of-sale skimming, e-commerce fraud, and Requirement 12.6 staff awareness mandate - [Education Security Training](https://ransomleak.com/industries/education/): FERPA-aligned training for K-12 districts, universities, and EdTech vendors covering student-data ransomware, payroll diversion, and research IP exfiltration - [Legal Sector Security Training](https://ransomleak.com/industries/legal/): Training for law firms covering client-data breaches, privileged-document mishandling, ABA Model Rule 1.6, and BEC against trust accounts - [SaaS & Tech Security Training](https://ransomleak.com/industries/saas-tech/): SOC 2 / ISO 27001 awareness training for SaaS companies covering production credential hygiene, source-code exfiltration, and customer-data incident response - [MSP & MSSP Security Training](https://ransomleak.com/industries/msp/): White-label training for MSPs and MSSPs covering multi-tenant client delivery, per-tenant evidence packs, and supply-chain attacks like Kaseya VSA - [Non-Profit Security Training](https://ransomleak.com/industries/non-profit/): Affordable training for non-profits covering donor-data privacy, payroll diversion, BEC, and limited-budget compliance for SOC 2 and ISO 27001 ## Use Cases - [Employee Onboarding Security Training](https://ransomleak.com/use-cases/employee-onboarding/): HRIS-triggered onboarding sequence (Workday, BambooHR, Rippling, ADP, SuccessFactors) covering the first 30-90 days with per-hire evidence packets for SOC 2 CC1.4, HIPAA § 164.308(a)(5), and ISO 27001 A.7.2.2 - [Annual Compliance Training](https://ransomleak.com/use-cases/annual-compliance-training/): Yearly refresher cycles aligned to SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR with audit-ready completion reports and per-employee certificates - [Cyber-Insurance Readiness Training](https://ransomleak.com/use-cases/cyber-insurance-readiness/): Awareness training that satisfies AIG, Chubb, Beazley, and Marsh cyber-policy questionnaires on workforce training, with documentation that maps directly to insurer attestation requirements - [Audit Evidence Prep](https://ransomleak.com/use-cases/audit-evidence-prep/): SOC 2 Type II, ISO 27001, and HIPAA audit evidence packages covering completion logs, training-curriculum exports, and quiz scores ready for auditor review - [Remote Workforce Training](https://ransomleak.com/use-cases/remote-workforce-training/): Home-office and BYOD security awareness training for distributed teams covering home-Wi-Fi hardening, device hygiene, and remote phishing patterns - [Contractor & Vendor Training](https://ransomleak.com/use-cases/contractor-vendor-training/): Awareness training for 1099 contractors, vendors, and third-party staff with access to systems, with attestation tracking and per-vendor evidence rollups - [Breach-Response Rehearsal](https://ransomleak.com/use-cases/breach-response-rehearsal/): Tabletop incident-response rehearsals for ransomware, BEC, and data-loss scenarios with NIST SP 800-61 alignment and post-exercise gap reports - [M&A Due Diligence Training](https://ransomleak.com/use-cases/m-and-a-due-diligence/): Rapid-onboarding training for acquired-company staff with security-posture gap closure, integration-period awareness coverage, and per-acquisition evidence - [LMS Migration Training](https://ransomleak.com/use-cases/lms-migration/): SCORM 1.2 / 2004 packages for migrating to any LMS (Cornerstone, Workday, SuccessFactors, Docebo, Moodle, Canvas) with one-click export and zero re-authoring - [Board Quarterly Reporting](https://ransomleak.com/use-cases/board-quarterly-reporting/): HRM metrics for board-of-director quarterly reviews covering training coverage, behavioral risk score, phishing-susceptibility trend, and incident-rate change ## Training Catalogue - [Security Awareness Training Catalogue](https://ransomleak.com/catalogue/): Browse 100+ free interactive exercises organized into 7 active training categories, with Cloud Security launching soon - [Security Awareness Training](https://ransomleak.com/catalogue/security-awareness/): 42 interactive exercises across 10 structured courses covering phishing, ransomware, social engineering, passwords, device security, and more - [Privacy & Compliance Training](https://ransomleak.com/catalogue/privacy-compliance/): Free interactive exercises covering GDPR (breach response, DSAR processing, privacy by design, cross-border transfers, processor vetting), the EU AI Act (AI literacy, risk classification, FRIA, transparency, human oversight, GPAI), and OWASP Top 10 Privacy Risks - [AI & LLM Security Training](https://ransomleak.com/catalogue/ai-security/): Interactive exercises on prompt injection, deepfake detection, AI-generated phishing, and LLM manipulation - [Real-World Incident Case Studies](https://ransomleak.com/catalogue/real-world-incidents/): Interactive case studies reconstructing actual security breaches including the MGM Resorts $100M attack - [Application Security Training for Developers](https://ransomleak.com/catalogue/application-security/): 22 hands-on exercises across the OWASP Top 10 for web applications; run the exploit in a real browser against a deliberately vulnerable app, then write the fix. Available in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin - [API Security Training](https://ransomleak.com/catalogue/api-security/): 10 hands-on exercises across the OWASP API Security Top 10 (broken object level authorization, broken authentication, unrestricted resource consumption, SSRF, and more). Available in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin - [Git & Repository Security Training](https://ransomleak.com/catalogue/git-security/): 8 hands-on exercises on secrets in commit history, an exposed .git directory, committed secret files, commit author spoofing, branch protection bypass, leaked access tokens, malicious pull requests, and CI/CD secret exposure ## Free Interactive Exercises - [Phishing Detection](https://ransomleak.com/exercises/phishing/): Identify and respond to phishing emails in a realistic simulation - [Ransomware Response](https://ransomleak.com/exercises/ransomware/): Handle a live ransomware attack scenario and learn containment steps - [Social Engineering](https://ransomleak.com/exercises/social-engineering/): Recognize manipulation tactics used in social engineering attacks - [Vishing (Voice Phishing)](https://ransomleak.com/exercises/vishing/): Detect phone-based social engineering in simulated voice calls - [Smishing (SMS Phishing)](https://ransomleak.com/exercises/smishing/): Spot fraudulent text messages and SMS-based attacks - [Business Email Compromise](https://ransomleak.com/exercises/business-email-compromise/): Prevent CEO fraud, invoice manipulation, and account compromise - [Barrel Phishing](https://ransomleak.com/exercises/double-barrel-phishing/): Defend against two-stage phishing attacks that bypass spam filters - [Deepfake Whaling](https://ransomleak.com/exercises/whaling-with-a-deepfake/): Identify deepfake-powered executive impersonation attacks - [Data Leakage Prevention](https://ransomleak.com/exercises/data-leakage/): Protect sensitive data from accidental or intentional leakage - [Social Media Oversharing](https://ransomleak.com/exercises/social-media-oversharing/): Understand how social media posts create attack vectors - [OneNote Email Attack](https://ransomleak.com/exercises/onenote-email-attack/): Detect malicious OneNote attachments used to deliver malware - [MGM Resorts Breach Case Study](https://ransomleak.com/exercises/mgm-resorts-security-breach/): Analyze the real-world MGM Resorts cyberattack and its social engineering tactics - [USB Drop Attack](https://ransomleak.com/exercises/usb-drop-attack/): Respond safely to suspicious USB devices found in the workplace - [Mobile Device Security](https://ransomleak.com/exercises/mobile-device-security/): Defend against smishing and fake MDM enrollment pages that steal credentials from phones - [IoT & Smart Device Security](https://ransomleak.com/exercises/iot-smart-device-security/): Audit default credentials, segment IoT devices from work networks, and detect botnet recruitment - [MFA Fatigue Attack](https://ransomleak.com/exercises/mfa-fatigue-attack/): Reject push-bombing and replace tap-to-approve MFA with phishing-resistant factors - [AI Prompt Injection](https://ransomleak.com/exercises/clawdbot-prompt-injection/): Learn how prompt injection attacks target AI assistants and chatbots - [Invoice & Payment Fraud](https://ransomleak.com/exercises/invoice-payment-fraud/): Catch a fraudulent vendor invoice using the 3-way match before it reaches the payment file - [Verification Procedures](https://ransomleak.com/exercises/verification-procedures/): Stop a vendor banking BEC by using your authoritative directory and an out-of-band callback - [Deepfake Audio Detection](https://ransomleak.com/exercises/deepfake-audio-detection/): Catch an AI-cloned executive voice on the phone before the wire goes out - [Calendar Invite Scams](https://ransomleak.com/exercises/calendar-invite-scams/): Spot spoofed calendar invites before the fake meeting page harvests your credentials - [Mobile App Permissions](https://ransomleak.com/exercises/mobile-app-permissions/): Audit and revoke over-permissioned apps that quietly harvest contacts, microphone, and location - [Log Sensitivity Awareness](https://ransomleak.com/exercises/log-sensitivity-awareness/): Recognize PII, JWTs, and secrets in production logs and sanitize before sharing externally - [Metadata Awareness](https://ransomleak.com/exercises/metadata-awareness/): Strip tracked changes, comments, and author metadata from documents before any external share - [Safe GenAI Usage](https://ransomleak.com/exercises/safe-genai-usage/): Use generative AI without leaking sensitive client data into consumer chatbots - [Secure Online Meetings](https://ransomleak.com/exercises/secure-online-meetings/): Spot the drop-in attendee, remove them, lock the meeting, and file the report ## GDPR Compliance Exercises - [Marketing Consent Management](https://ransomleak.com/exercises/gdpr-marketing-consent-management/): Handle GDPR consent for marketing communications - [Data Breach Response](https://ransomleak.com/exercises/gdpr-data-breach-response/): Execute proper breach notification under GDPR timelines - [Privacy by Design Review](https://ransomleak.com/exercises/gdpr-privacy-by-design-review/): Evaluate systems for GDPR privacy-by-design compliance - [DSAR Processing](https://ransomleak.com/exercises/gdpr-legitimate-dsar-processing/): Process data subject access requests correctly - [PII Document Redaction](https://ransomleak.com/exercises/gdpr-pii-document-redaction/): Redact personally identifiable information from documents - [Fraudulent DSAR Detection](https://ransomleak.com/exercises/gdpr-fraudulent-dsar-detection/): Identify and handle fraudulent data subject requests - [Third-Party Processor Vetting](https://ransomleak.com/exercises/gdpr-third-party-data-processor-vetting/): Evaluate third-party data processors for GDPR compliance - [Security Incident Response](https://ransomleak.com/exercises/gdpr-security-incident-response/): Manage security incidents within GDPR requirements - [Cross-Border Data Transfers](https://ransomleak.com/exercises/gdpr-cross-border-data-transfers/): Navigate cross-border data transfer rules and mechanisms - [Data Protection Impact Assessment](https://ransomleak.com/exercises/gdpr-data-protection-impact-assessment/): Conduct Data Protection Impact Assessments - [Data Mapping & Records of Processing](https://ransomleak.com/exercises/gdpr-data-mapping-and-records-of-processing/): Create and maintain records of processing activities ## EU AI Act Compliance Exercises - [AI Literacy Essentials](https://ransomleak.com/exercises/ai-literacy-essentials/): Earn the AI literacy mandated by Article 4 before touching company AI tools - [AI Risk Classification](https://ransomleak.com/exercises/ai-risk-classification/): Sort real AI deployments into the four EU AI Act risk tiers - [Prohibited AI Practices](https://ransomleak.com/exercises/prohibited-ai-practices/): Stop banned AI deployments before they go live under Article 5 - [High-Risk AI Deployer Obligations](https://ransomleak.com/exercises/high-risk-ai-obligations/): Block a high-risk AI launch with compliance gaps in any of seven areas under Article 26 - [Provider vs. Deployer Responsibilities](https://ransomleak.com/exercises/provider-vs-deployer/): A compliant vendor product does not make your deployment compliant - [AI Transparency and Disclosure](https://ransomleak.com/exercises/ai-transparency-and-disclosure/): Label AI chatbots and synthetic media correctly under Article 50 - [Meaningful Human Oversight](https://ransomleak.com/exercises/meaningful-human-oversight/): Override an AI loan recommendation when the evidence does not match under Article 14 - [AI Data Governance](https://ransomleak.com/exercises/ai-data-governance/): Block AI training that uses a leaky, biased, or oversharing dataset under Article 10 - [AI and Data Protection](https://ransomleak.com/exercises/ai-and-data-protection/): Run a healthcare AI through both EU AI Act and GDPR at once - [AI Bias and Discrimination](https://ransomleak.com/exercises/ai-bias-and-discrimination/): Investigate proxy variables hiding inside a resume-screening model - [Fundamental Rights Impact Assessment](https://ransomleak.com/exercises/fundamental-rights-impact-assessment/): Run a FRIA before a social housing AI ever assigns a benefit decision under Article 27 - [AI Incident Reporting](https://ransomleak.com/exercises/ai-incident-reporting/): Report a discriminatory AI rejection pattern under Article 62 - [AI Governance in Your Organization](https://ransomleak.com/exercises/ai-governance-in-your-organization/): Build an AI registry and shut down shadow AI in your company - [General-Purpose AI Model Obligations](https://ransomleak.com/exercises/general-purpose-ai-models/): Map GPAI provider and downstream deployer duties for systemic-risk models - [Using AI Tools Responsibly at Work](https://ransomleak.com/exercises/responsible-ai-use-at-work/): Make compliant AI choices through a normal working day - [EU AI Act Penalties and Enforcement](https://ransomleak.com/exercises/ai-act-penalties-and-enforcement/): Map the three-tier penalty structure to real enforcement scenarios ## Blog & Guides - [Security Awareness Training: The 2026 Guide](https://ransomleak.com/blog/security-awareness-training-guide/): Implementation strategies, ROI measurement, and interactive training methods that build a human firewall - [Does Security Awareness Training Work? What 47 Studies Say](https://ransomleak.com/blog/security-awareness-training-effectiveness/): Analysis of 47 peer-reviewed studies on awareness training ROI and what actually changes employee behavior - [12 Common Cybersecurity Training Exercises](https://ransomleak.com/blog/cybersecurity-awareness-exercises/): Proven exercises that cut phishing clicks by 80%, including phishing simulations, tabletop scenarios, and a 90-day rollout plan - [15 Cyber Security Activities for Employees](https://ransomleak.com/blog/cyber-security-activities-for-employees/): Hands-on team activities that turn awareness into action with time estimates, materials, and facilitator notes - [Building a Human Firewall: The Complete Pillar Guide](https://ransomleak.com/blog/human-firewall-training/): Seven pillars of behavior that stop attacks before tools kick in, a 90-day build plan, KPIs, and why pure SAT fails to produce one - [Phishing Simulation Training Guide](https://ransomleak.com/blog/phishing-simulation-training/): How phishing simulation training works and why it outperforms passive awareness content - [How to Spot Phishing](https://ransomleak.com/blog/phishing-detection/): Visual and technical signs that reveal phishing websites and emails - [Barrel Phishing: Two-Stage Attacks](https://ransomleak.com/blog/barrel-phishing/): How barrel phishing bypasses spam filters by sending a harmless email before the real attack - [Vishing Attacks Explained](https://ransomleak.com/blog/vishing-awareness/): How voice phishing exploits phone conversations and why it fools even trained employees - [Smishing Attacks Explained](https://ransomleak.com/blog/what-is-smishing-cybersecurity/): How text message phishing works and organizational defense strategies - [Whaling Attacks on Executives](https://ransomleak.com/blog/what-is-whaling-cybersecurity/): Why C-suite executives are prime targets and how to protect high-value individuals - [Social Engineering Attacks](https://ransomleak.com/blog/social-engineering-attacks/): How hackers exploit human psychology with real examples and defense strategies - [Business Email Compromise Training](https://ransomleak.com/blog/bec-training/): Preventing million-dollar wire fraud from CEO fraud, invoice manipulation, and account compromise - [Email Security Training Guide](https://ransomleak.com/blog/email-security-training/): Protecting organizations from phishing, BEC, and email-based threats through effective training - [Mobile Security Training](https://ransomleak.com/blog/mobile-security-training/): Protecting remote and mobile workers from smishing, mobile phishing, and BYOD security risks - [Compliance Training for Regulated Industries](https://ransomleak.com/blog/compliance-training/): Meeting HIPAA, PCI DSS, SOC 2, GDPR, ISO 27001, and NIST requirements through employee training - [Free Security Awareness Training Resources](https://ransomleak.com/blog/free-security-awareness-training/): Quality free training options, their limitations, and when to upgrade to enterprise solutions - [SCORM Security Training: LMS Integration Guide](https://ransomleak.com/blog/scorm-security-training/): Deploying security training to any LMS with SCORM 1.2 vs 2004 comparison and setup guides - [Open Source LMS for Security Training](https://ransomleak.com/blog/open-source-lms-security-training/): Moodle, Canvas, and Open edX compared for SCORM security training with real cost analysis - [KnowBe4 Alternatives Compared](https://ransomleak.com/blog/knowbe4-alternatives/): Top security awareness training platforms compared by features, pricing, and use cases - [Hoxhunt Alternatives: 7 Platforms Compared](https://ransomleak.com/blog/hoxhunt-alternatives/): Feature-by-feature breakdown of Hoxhunt and six direct alternatives covering phishing simulation scope, training breadth, pricing, and ideal buyer - [Best Security Awareness Training Platforms 2026](https://ransomleak.com/blog/best-security-awareness-training-2026/): Eight vendors compared across training method, AI coverage, SCORM support, pricing band, and procurement-ready evaluation criteria - [Best Secure Coding Training Platforms 2026](https://ransomleak.com/blog/best-secure-coding-training-2026/): Eight application security training vendors compared across hands-on practice depth, language coverage, OWASP Top 10:2025 mapping, pricing, and stack breadth past web - [OWASP Top 10 for LLM Applications](https://ransomleak.com/blog/owasp-llm-top-10/): All ten OWASP LLM risks explained with practical training recommendations for prompt injection, data poisoning, excessive agency, and more - [OWASP LLM Top 10 Training Course Launch](https://ransomleak.com/blog/owasp-llm-top-10-training-course/): All 10 OWASP LLM risk categories now have free interactive exercises covering prompt injection, data poisoning, RAG exploitation, and more - [GDPR Training for Employees](https://ransomleak.com/blog/gdpr-employee-training/): Why most GDPR training fails, what employees actually need to know, and how to measure training effectiveness beyond completion rates - [The 7 GDPR Data Protection Principles in Practice](https://ransomleak.com/blog/gdpr-data-protection-principles/): The seven Article 5 principles from data minimization to accountability, mapped to everyday work habits and interactive privacy exercises - [Remote Work Cybersecurity: A Practical Training Guide](https://ransomleak.com/blog/remote-work-cybersecurity/): Home network, VPN, patching, and device habits that close the gaps attackers target in distributed teams, with scenario-based exercises - [AI Coding Assistant Security Risks](https://ransomleak.com/blog/ai-coding-assistant-security-risks/): Prompt injection, data exfiltration, and security risks from AI coding tools that most organizations overlook - [AI Data Leakage: Employees Exposing Secrets to ChatGPT](https://ransomleak.com/blog/ai-data-leakage-employees/): How employees leak confidential data into ChatGPT, Claude, and Copilot, why traditional DLP misses it, and the four-layer control model that actually works - [Ransomware Awareness Training for Employees](https://ransomleak.com/blog/ransomware-awareness-training/): How ransomware attacks work, what employees should do in the first 60 seconds, and why backup strategy is the best defense - [Credential Stuffing: How Leaked Passwords Work](https://ransomleak.com/blog/credential-stuffing-awareness/): How attackers use stolen credentials from data breaches to break into corporate accounts, and why password reuse is the root cause - [Callback Phishing (TOAD): No Links, All Danger](https://ransomleak.com/blog/callback-phishing/): How callback phishing bypasses email security with clean emails and phone numbers, and why TOAD attacks are growing fast - [Insider Threat Awareness Training](https://ransomleak.com/blog/insider-threat-training/): How to recognize insider threat behavioral indicators, report suspicious activity, and build a program employees support - [Clawdbot (Moltbot) Security Risks](https://ransomleak.com/blog/clawdbot-security-risks/): Critical vulnerabilities in Clawdbot including plaintext credential storage, prompt injection, and infostealer targeting - [Deepfake Social Engineering](https://ransomleak.com/blog/deepfake-social-engineering/): How voice cloning and video deepfakes power social engineering attacks, with employee verification strategies for the deepfake era - [Shadow IT Security Risks](https://ransomleak.com/blog/shadow-it-security-risks/): How unauthorized SaaS tools create data leakage, credential sprawl, and compliance blind spots, with discovery and remediation strategies - [OWASP Agentic AI Top 10](https://ransomleak.com/blog/owasp-agentic-ai-top-10/): Security risks when AI agents act autonomously, covering cascading failures, goal hijacking, rogue agents, and all ten OWASP Agentic AI risk categories - [OWASP Agentic Top 10 Training Course Launch](https://ransomleak.com/blog/owasp-agentic-top-10-training-course/): All 10 OWASP Agentic AI risk categories now have free interactive exercises covering goal hijacking, cascading failures, rogue agents, and more - [AI-Powered Phishing](https://ransomleak.com/blog/ai-powered-phishing/): How LLMs help attackers craft personalized phishing at scale, eliminating the typos and grammar errors employees were trained to spot - [Password Security Training](https://ransomleak.com/blog/password-security-training/): Why password training fails when it teaches rules instead of habits, and how to build lasting password hygiene with managers, MFA, and behavior measurement - [Data Classification Training](https://ransomleak.com/blog/data-classification-training/): Teaching employees to classify data by sensitivity and apply correct handling procedures, with practical frameworks and measurement strategies - [Quishing (QR Code Phishing): How It Works and How to Stop It](https://ransomleak.com/blog/quishing/): Why quishing bypasses email filters, how the attack shifts to unmanaged phones, detection guidance, and enterprise defenses - [Shadow AI: The Hidden Risk of Employee LLM Use](https://ransomleak.com/blog/shadow-ai/): How unsanctioned AI tool adoption leaks confidential data, fractures compliance evidence, and what four controls actually contain it - [ChatGPT Security Risks for Enterprise](https://ransomleak.com/blog/chatgpt-security-risks/): Eight enterprise risks from employee ChatGPT use including data leakage, insecure code, prompt injection, and hallucinated legal citations - [Typosquatting Awareness](https://ransomleak.com/blog/typosquatting-awareness/): How lookalike domains exploit typing mistakes and visual similarity to steal credentials, with detection techniques and defense strategies - [Is SCORM Still Relevant in 2026?](https://ransomleak.com/blog/is-scorm-still-relevant/): Why SCORM 1.2 remains the default enterprise LMS standard despite xAPI and cmi5, and when newer standards actually win - [Can AI Detect Deepfake Video Calls in Real Time?](https://ransomleak.com/blog/ai-deepfake-detection-realtime/): Honest look at real-time deepfake detection accuracy, enterprise vendor options, and why process-based verification beats detection for most organizations - [RansomLeak vs KnowBe4](https://ransomleak.com/blog/ransomleak-vs-knowbe4/): Honest comparison of interactive 3D simulations vs video-based content library, with feature tables, pricing, and buyer guidance - [RansomLeak vs Hoxhunt](https://ransomleak.com/blog/ransomleak-vs-hoxhunt/): Full-spectrum interactive training vs AI-adaptive phishing simulations, compared on scope, gamification, SCORM, and ideal buyer profiles - [RansomLeak vs Proofpoint](https://ransomleak.com/blog/ransomleak-vs-proofpoint/): Standalone interactive training vs email security suite integration, with feature comparison, vendor lock-in analysis, and deployment flexibility - [RansomLeak vs Usecure](https://ransomleak.com/blog/ransomleak-vs-usecure/): Enterprise interactive simulations vs MSP-focused automated training, compared on audience, features, multi-tenant management, and pricing - [RansomLeak vs Phished](https://ransomleak.com/blog/ransomleak-vs-phished/): Hands-on 3D simulations vs AI-automated phishing, compared on training depth, topic breadth, GDPR compliance, and automation approach - [RansomLeak vs Ninjio](https://ransomleak.com/blog/ransomleak-vs-ninjio/): Interactive practice vs Hollywood micro-learning videos, compared on learning method, topic depth, skill building, and engagement model - [RansomLeak vs SoSafe](https://ransomleak.com/blog/ransomleak-vs-sosafe/): Europe-focused HRM suite vs interactive 3D simulations, compared on regulatory fit (NIS2, DORA, TISAX), data residency, AI coverage, and buyer profile - [NIS2 Training Requirements: Complete Guide for EU Organizations](https://ransomleak.com/blog/nis2-training/): Directive (EU) 2022/2555 training obligations, management accountability, deadlines, penalties, and how to operationalize NIS2 awareness - [HIPAA Security Awareness Training Requirements](https://ransomleak.com/blog/hipaa-security-awareness-training/): 45 CFR 164.308(a)(5) training rule explained: who needs training, what to cover, retention, breach notification, and audit readiness - [FTC Safeguards Rule Training Requirements](https://ransomleak.com/blog/ftc-safeguards-rule-training/): 16 CFR Part 314 training obligations for financial institutions, including the nine program elements, qualified individual role, and penalties - [EU AI Act Timeline: Compliance Deadlines to 2027](https://ransomleak.com/blog/eu-ai-act-compliance-deadlines/): Staged EU AI Act deadlines from 2024 to 2027, what each one requires, the Article 99 penalty tiers, and how to prepare your workforce for the 2 August 2026 high-risk regime - [EU AI Act Risk Categories: The 4 Levels Explained](https://ransomleak.com/blog/eu-ai-act-risk-categories/): The four EU AI Act risk levels (unacceptable, high, limited, minimal), what each tier requires, and how to classify your AI systems by intended purpose - [EU AI Act and GDPR: Where the Two Laws Overlap](https://ransomleak.com/blog/eu-ai-act-gdpr/): How the AI Act stacks on top of GDPR, the DPIA vs FRIA split, shared data governance and records, cross-border transfers, and training one mapped program for both - [AI Literacy Training: Meeting EU AI Act Article 4](https://ransomleak.com/blog/ai-literacy-training/): What the Article 4 AI literacy duty requires, who it reaches, what training must cover by role, and how to evidence it for an auditor - [Deepfakes and the EU AI Act: Article 50 Transparency](https://ransomleak.com/blog/eu-ai-act-deepfakes/): How Article 50 regulates synthetic media through disclosure, the provider vs deployer labeling split, art and law-enforcement exceptions, and the link to deepfake fraud ## Reference - [Cybersecurity Glossary](https://ransomleak.com/glossary/): Clear definitions of 25 key cybersecurity terms including phishing, vishing, smishing, quishing, clone phishing, whaling, BEC, CEO fraud, pretexting, MFA fatigue, ransomware, social engineering, deepfake, SCORM, and more ## Company - [About RansomLeak](https://ransomleak.com/about-us/): Founded in Estonia by Dmytro Koziatynskyi (CEO) and Maksym Khamrovskyi (CMO), previously creators of Kontra Application Security Training - [Contact & Demo](https://ransomleak.com/contact-us/): Request a personalized demo or get an enterprise training quote with typical response within 24 hours - [Learning Platform](https://learning.ransomleak.com): Standalone cloud LMS with user management, analytics, campaign management, and SSO ## Key Facts - Founded: 2025, Tallinn, Estonia - Founders: Dmytro Koziatynskyi (CEO) and Maksym Khamrovskyi (CMO), previously creators of Kontra Application Security Training - Free exercises: 100+ interactive cybersecurity simulations covering phishing, ransomware, social engineering, vishing, smishing, BEC, deepfake whaling, USB drop attacks, AI prompt injection, and GDPR compliance - SCORM compliance: Full SCORM 1.2 and SCORM 2004 support, tested with 50+ LMS platforms - Compliance frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIS2 - Content uploads: Organizations can upload their own images, PDFs, presentations, videos, and third-party SCORM packages alongside RansomLeak exercises - Delivery options: SCORM packages for existing LMS infrastructure or standalone cloud LMS with SSO, analytics, campaign management, and white-labeling ## Frequently Asked Questions Q: What is security awareness training? A: Security awareness training is a structured education program that teaches employees to recognize, avoid, and report cybersecurity threats such as phishing, social engineering, ransomware, and data breaches. Effective programs use interactive simulations and hands-on exercises rather than passive videos, building practical skills that reduce human-caused security incidents. Q: How does RansomLeak differ from other security training providers? A: RansomLeak uses interactive 3D simulations that place employees directly in realistic attack scenarios rather than relying on videos or slideshows. Multiple studies show that active, experiential learning outperforms passive content for knowledge retention. The platform also supports full SCORM 1.2 and 2004 compliance for integration with any existing LMS. Q: Is there a free version available? A: Yes. RansomLeak offers 100+ free interactive cybersecurity exercises at ransomleak.com/catalogue with no signup required. These cover phishing, ransomware, social engineering, vishing, smishing, business email compromise, deepfake whaling, USB drop attacks, AI prompt injection, and GDPR compliance scenarios. Q: What compliance frameworks does RansomLeak support? A: RansomLeak training satisfies security awareness requirements under SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and NIS2. The platform includes compliance-specific reporting, completion tracking, and audit-ready documentation. SCORM integration ensures training data flows into your existing LMS compliance workflows. Q: What is SCORM and why does it matter? A: SCORM (Sharable Content Object Reference Model) is an international standard that lets e-learning content work across any compliant Learning Management System without custom integration. RansomLeak supports both SCORM 1.2 and SCORM 2004, tested with 50+ LMS platforms including Moodle, Cornerstone, Workday, SAP SuccessFactors, and Docebo. Q: How do you measure training effectiveness? A: RansomLeak tracks exercise completion rates, knowledge assessment scores, time to report suspicious emails, and behavioral change over time. The real-time analytics dashboard shows progress by department, team, or individual, with audit-ready reports for SOC 2, ISO 27001, and HIPAA compliance. ## Profiles & Reviews - [LinkedIn](https://linkedin.com/company/ransomleak) - [YouTube](https://www.youtube.com/@RansomLeak) - [G2 Reviews](https://www.g2.com/products/ransomleak-security-awareness-training/reviews) - [Gartner Peer Insights](https://www.gartner.com/reviews/product/ransomleak-448460066) - [Trustpilot](https://www.trustpilot.com/review/ransomleak.com) - [Capterra](https://www.capterra.com/p/10036558/RansomLeak/) - [SourceForge](https://sourceforge.net/software/product/RansomLeak/) - [Crunchbase](https://www.crunchbase.com/organization/ransomleak) - [Wikidata](https://www.wikidata.org/wiki/Q138781295) ## Optional - [Security & Compliance](https://ransomleak.com/security-compliance/): Enterprise-grade security with GDPR compliance, encryption, and alignment with NIST, SOC 2, and NIS2 frameworks - [Security Advisories](https://ransomleak.com/security-advisories/): Published security advisories, severity levels, coordinated disclosure process, and how to report a vulnerability - [Privacy Policy](https://ransomleak.com/privacy-policy/): Data protection practices and GDPR compliance details - [Terms of Service](https://ransomleak.com/terms-of-service/): Terms governing use of the platform and services