Skip to content
Chinron
Phishing

Phishing your people will actually recognise

Realistic, sector-specific simulations that mirror the attacks targeting your industry — paired with a one-click Report button in every inbox.

Book a demo
Why it matters

The inbox is still the front door

68%

of breaches involve a human element

Verizon 2024 DBIR

<60s

median time to fall for a phishing email

Verizon 2024 DBIR

US$2.9B

reported losses to business email compromise (2023)

FBI IC3

6 min

between cybercrime reports in Australia (2022–23)

ASD ACSC

Phishing simulation

Industry-targeted phishing, not recycled spam

Today’s phishing is personalised and indistinguishable from legitimate mail. A lure only works as training if it looks like something your team would actually receive — so Chinron builds templates from the services, portals and payment flows that circulate in your region, not generic ones recycled from somewhere else.

  • AI-designed full HTML emails — not basic templates. Each simulation is a rich, styled email built to look like a real attack, with 25 style variations so your team never sees the same format twice
  • Real brand colours pulled automatically via Brandfetch — a Microsoft sim uses Microsoft's actual palette, a bank sim uses the bank's colours. Indistinguishable from the real thing
  • One-click Microsoft 365 allowlisting — Chinron configures your Advanced Delivery Policy automatically from inside the platform. No manual Exchange Online setup, no IT ticket required
  • Regional lure libraries — templates built from the services, portals and payment systems that actually circulate in your region
  • Sector-built templates: financial-fraud lures for accounting, patient-portal spoofs for healthcare, and more across 28 industries
  • Recurring campaigns on a cadence — not a one-off test your team forgets
  • Real-time open and click tracking, with education landing pages the moment a user clicks
  • Shared and personal mailboxes are excluded automatically from live sends
au.chinron.io
Localised · Industry-specific · Framework-aligned

The lure only works if it looks like something your team would actually receive

A phishing simulation built around a delivery notification from a carrier your employees have never used doesn’t train anyone. A fake payment portal for a bank your finance team doesn’t use won’t trigger the right instincts.

Chinron maintains separate regional lure libraries — built around the services, government portals, financial systems and delivery networks that actually circulate in each region’s threat landscape. When a campaign goes out to your team, it uses lures drawn from their world. The simulation only builds the right muscle if it looks real.

au.chinron.io
Australia region example
What it looks like

Built for your industry and region, down to the lure

A couple of examples of how a simulation adapts to the sector and region it’s sent to — because a lure only works as training if it feels familiar.

Finance / Accounting Simulated · Payment redirection
From: accounts@vendor-billing-update.com
Updated remittance details — action required

Please note our banking details have changed. Use the new account for invoice #4471 before close of business…

Healthcare Simulated · Credential harvest
From: no-reply@patient-portal-secure.com
Your patient portal access expires today

To maintain access to patient records, please re-verify your credentials within 24 hours…

Report phishing

A one-click Report button in every inbox

Reporting suspicious email should be effortless. Chinron puts a native Report Phishing button right where your team already works — so threats get flagged, not forwarded around the office.

Microsoft Outlook

Outlook add-in for Microsoft 365 — desktop, web and mobile.

Google Gmail

Gmail add-on for Google Workspace, available across the inbox.

Zoho Mail

Zoho Mail widget for organisations on Zoho.

One click reports a suspicious email — no copy-pasting headers, no confusion about who to tell. The full message is captured for your security team, and the button reinforces the reporting habit your awareness program is building. Admins deploy it once, across the whole organisation.

Trust Check

Not every dodgy-looking email is phishing — and treating it like it is trains the wrong habit

A badly formatted newsletter, an unfamiliar-but-legitimate sender, a link that just looks a bit off. Forced to choose between “report it as an attack” and “do nothing,” most people do neither — they just delete it and stay quiet. That's a missed signal, not a safe outcome.

Chinron's Report button has a second option next to it: “Not sure? Ask IT to check.” No accusation, no red alert — just a quick note to your security team, with optional one-tap reasons (unexpected attachment, asks for payment or login, sender looks wrong, urgent pressure) if they want to add context.

The two paths are handled differently on purpose. A Report is a confident call — it's flagged red and the add-in moves the message to Junk immediately. A Trust Check stays neutral — the message is never moved, because the person hasn't claimed it's an attack, only that they'd like a second opinion.

That distinction protects both directions: genuine phishing doesn't slip through because someone didn't want to “cry wolf,” and your security team's inbox isn't flooded with false-positive phishing alerts for something that just needed a human to glance at it. It's the same one extra click, in the same three add-ins as the Report button — Outlook, Gmail and Zoho Mail — wherever your team already works.

Start training your people on their real risk

Spin up a free trial in your region in minutes — or book a walkthrough tailored to your industry.

Book a demo