Custom HTML for Custom Phishing: Make the Fake Feel Real

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress has launched Custom HTML for Custom Phishing, a feature in its Managed SAT platform that lets admins build fully custom phishing simulation emails from scratch using a direct HTML editor, matching their own organization's vendors, tone, and branding. Early customers in financial services, healthcare, and manufacturing have used it to mimic internal IT requests, vendor portals, and operational alerts. Custom scenarios saw 10-20% click-to-compromise rates, while Huntress's own Managed Phishing scenarios, built from real SOC data, averaged 25% or higher, with one Google Drive invite scenario hitting 65%. The feature is positioned as a complement to, not replacement for, Managed Phishing.

4m read timeFrom huntress.com
Post cover image
Table of contents
Custom HTML for Custom Phishing: Get hands-on with your own risk factorsEarly successBuild your own, but don't skip Managed PhishingStart building your own custom phishing scenarios

Questions this post answers

What click-to-compromise rate do custom-built phishing simulation scenarios typically achieve compared to vendor-curated ones?

Custom HTML phishing simulations built by organizations themselves achieve click-to-compromise rates around 10% to 20% for the better-performing scenarios, while professionally curated Managed Phishing scenarios average 25% or higher. One deepfake meeting invite scenario hit 33%, and a Google Drive document invite scenario reached 65% across hundreds of thousands of users, showing curated, threat-intelligence-driven scenarios tend to outperform self-built ones. Security teams weighing DIY versus managed phishing simulations can track real-world benchmarks like these on daily.dev.

26 Impressions