Skip to content

Learning to spot phishing by playing: what Firewall Humano teaches

Emails, chats, texts and voice notes across three waves, some legitimate and urgent, others malicious. Nobody classifies them alone. That's a shift of Firewall Humano — and that's how it teaches phishing detection without a single quiz question.

Academy Experiencia RPG Team 5 min read

A shift, not an exam

It's 11:40 PM at Cardal Logística, a fictional company. The night shift is in charge of the shared inbox, and it never stops: emails, internal chat messages, texts, even voice notes keep arriving. Some are legitimate, urgent requests — an invoice due tomorrow, a vendor with a delivery, a coworker who needs a signature. Others are phishing, fraud or impersonation attempts. The team has to decide what to do with each one, in real time, with a deadline ticking down on every message.

That's the premise of Firewall Humano, the first game in the Experiencia RPG Academy line. There are no multiple-choice questions: there's an inbox, and decisions that have to be made.

Why nobody solves it alone

The first difference from a quiz is that no single person has the full picture. The game splits the work across three roles:

Inbox sees every message the way any employee would: the sender's visible name and address, the subject, the body, a link's text (but not where it actually goes) and an attachment's name (but not its real file type). This is the role that decides: comply with the request, report it, request verification, or discard it.

Analyst can inspect the technical layer Inbox can't see: the email's authentication headers (SPF, DKIM, DMARC), a link's real destination, a domain's age, an attachment's real file type. Every inspection costs time off the message's deadline, so choosing what to check first matters.

Context knows the organization: who reports to whom, who's on vacation this week, which vendors have a registered bank account and phone number on file, and what company policy says. Context can call that registered number to confirm an unusual request — verification through a channel other than the one the message arrived on.

No single station, on its own, has what it takes to decide with confidence. People have to talk.

The trap that actually teaches something

Here's the detail that sets this game apart from almost any other awareness material: not everything unusual is malicious, and over-reporting has a real cost. Every wave guarantees at least one legitimate, urgent request. If the team adopts a "flag everything as suspicious" strategy, it loses just as badly as if it complied with everything without looking: there are two meters, Security and Operations, and reporting a legitimate message drops Operations just as much as complying with a malicious one drops Security.

That tension is exactly the one that exists in a real job, where excessive distrust also has consequences: the business stalls, people lose time, and eventually people stop reporting things out of fear of "spending" their credibility on false alarms.

The signals, from obvious to subtle

The game has four levels, and each one stacks new signals on top of the previous ones. At Beginner, the signals are visible at a glance: a generic greeting, spelling mistakes, excessive urgency, a domain that wouldn't fool anyone who looked twice. At Basic, you have to start inspecting: a link whose text doesn't match its real destination, a double-extension attachment, a request that skips the company's usual process. At Intermediate, vendor fraud shows up (a bank-account change request that looks entirely legitimate), along with domains that look almost real and authentication headers that fail. And at Advanced, the hardest signals: homoglyphs — characters that look like other characters, used to build a domain almost identical to the real one — and something very few awareness quizzes even mention: a real internal account that got compromised and keeps sending messages in the following waves, now clean across every technical control.

When the technical read isn't enough

That last point deserves its own explanation, because it's the most honest part of the game. If someone on the team falls for a message that compromises a real internal account, that account — not an impostor, the actual account — keeps sending messages in the waves that follow. They pass every technical control, because they're technically real: authentication checks out, the domain is correct, nothing looks off in the headers. The only way to notice something's wrong is context: why would this person ask for this at three in the morning? Weren't they on vacation? Is this even something they'd normally ask for?

It's a lesson no multiple-choice quiz can teach, because it depends on knowing the organization, not on recognizing a technical pattern. And based on real corporate fraud cases, it's exactly the kind of attack that moves the most money when it works.

It's graded on what you did, not what you answered

Every competency in the curriculum — reporting a phishing email, checking a recently registered domain, spotting a compromised account — gets demonstrated through a concrete action inside the game, logged the moment it happens. A person passes a level when their own decisions, never a bot's, demonstrated those competencies in at least one match. You can play it with your full team or solo, with bots covering the roles you're missing — but passing always depends on what you decided, at the station you played.

If you want the full breakdown of the three roles, the four levels, and how each shift can end, the Firewall Humano "how to play" guide has it all, including the most common mistakes on a first attempt.

#phishing #social engineering #email #academia

Want to try it with your team?

Six cooperative browser games, bots to practice solo, and Game Master facilitation. Nothing to install.

Keep reading