Your people approve the wires. Train them like it.
Wire fraud, business email compromise, and credential phishing all route through one place: an employee's judgment under time pressure. ScamDrill drills that judgment with realistic email and SMS attacks — before a real one finds it.
From $449/yr for teams up to 25 · 30-day free trial (card required) · full pricing · cancel in one click
What a drill looks like
ScamDrill sends your staff safe, realistic fakes of the scams that actually target banks and financial firms — by email and text. Anyone who clicks gets a 60-second lesson on the spot, and you see who’s improving. This is the kind of message your team learns to catch:
Why financial firms are the prize target
Attackers go where the money is wired. The FBI's IC3 logged a record $20.9 billion in cyber-enabled losses in 2025, and business email compromise alone took $3.05 billion of it — the second-costliest category, landing squarely on the people who approve payments.
BEC pays better than malware
A convincing "updated wire instructions" email costs an attacker nothing and clears six figures when it works — IC3 puts the average BEC loss above $122,000, with 86% of the money leaving by wire or ACH. It works when the approver hasn't practiced spotting it.
Your org chart is on LinkedIn
Attackers map who handles payments, who reports to whom, and when the CFO travels. Spear phishing in finance is researched, not sprayed.
The attack moved to the phone
Smishing and MFA-fatigue texts now reach employees directly, around your email gateway. Training that only covers the inbox covers half the threat.
Simulation built for how finance gets attacked
Realistic pressure, role-aware targeting, and the records your examiners expect.
Finance-grade scenarios
Wire-instruction changes, executive impersonation, payroll diversion, fake compliance notices, and customer-impersonation requests — over email and SMS.
Target by department
Drill the treasury team differently than the branch staff. Compare risk across functions and watch the gap close.
Verification habits, not just suspicion
Lessons after a miss teach the control that matters: out-of-band verification before money moves.
Examiner-ready reporting
Per-person training records, simulation outcomes, and trend lines — exportable for audits, exams, and board reporting.
Webhooks & API
Feed simulation events into your SIEM or GRC tooling. Deliveries are HMAC-signed — details on our security page.
Published pricing
Evaluate without a procurement cycle: prices are public, plans are simple annual tiers from $449/yr, and the trial is 30 days.
Where drills fit your compliance program
Awareness training stopped being optional for financial institutions years ago. The differentiator now is whether it changes behavior.
GLBA Safeguards Rule
The FTC's amended Safeguards Rule (16 CFR § 314.4(e)) requires security awareness training for personnel — and FTC guidance is explicit that static, once-a-year training that hasn't kept pace with current threats doesn't satisfy it. ScamDrill supplies the recurring, threat-current training and the documentation trail.
NYDFS Part 500
New York–regulated banks, insurers, and licensees must run annual cybersecurity awareness training that specifically covers phishing and social engineering, per the Second Amendment to 23 NYCRR 500.14 finalized in November 2023. Simulated phishing plus role-based lessons map directly to that expectation.
FFIEC exams & interagency standards
Banks and credit unions are examined against the interagency information-security guidelines and FFIEC guidance, which expect ongoing awareness training and testing against social engineering. Per-person records and trend lines give examiners a concrete answer, not a sign-in sheet.
SOC reviews & vendor due diligence
Counterparty questionnaires and SOC reviews routinely ask how your staff are trained against phishing. Export outcomes and completion records to answer with evidence — our security & trust page covers controls and data handling.
From signup to a trained first line
Most institutions send their first simulation the same afternoon they sign up.
Create your organization
Self-serve, 30-day free trial. Your compliance team can review our security page in parallel.
Load your roster
CSV or directory export, grouped by branch or function.
Run role-aware campaigns
Wire-fraud scenarios for approvers, credential phishing for everyone, smishing where you enable it.
Report up and out
Board-ready trends and per-person records for examiners.
Common questions from financial institutions
Yes. Scenarios include payment-instruction changes, executive impersonation, and vendor banking updates — the BEC patterns behind most fraud losses — targeted at the teams that approve money movement.
Send your questionnaire via the contact page. Our security & trust page covers controls, data handling, and our compliance roadmap honestly — including what's not certified yet.
Not yet — today's channels are email and SMS (where most volume lives). Voice is on the roadmap; the training modules already cover vishing red flags.
Yes — ScamDrill started as a consumer product. Many institutions point customers to our family plans and free resources for fraud-prevention outreach.
For most institutions, monthly or at least quarterly — frequent enough to build a habit, varied enough that staff can't pattern-match to "the training email." Regulators increasingly expect training that reflects current tactics rather than a static annual module, so ScamDrill rotates scenarios as the threats shift.
It supplies the awareness component both expect: recurring, documented training plus simulated phishing and social-engineering tests, with exportable per-person records. Your compliance officer still owns the program and the attestation — we make its training and testing demonstrable with evidence an examiner will accept.
The next wire-fraud attempt is already written
Make sure the person who receives it has seen one before. 30-day free trial, published pricing.
From $449/yr · card required for the trial · cancel in one click, pay nothing