Contact
How to get in touch
If you work for a participating organisation
Questions about a training email, a simulation, or whether a message was authorized should go first to your organisation’s IT / security team through your normal internal channel. They own the programme for your staff and can confirm what was sent.
Security researchers & operators
To report a vulnerability, Safe Browsing false positive, or infrastructure concern related to domains operated by SecurityTools, email:
Please include the hostname, approximate time, and what you observed. Do not send live credentials.