ISCAP Proceedings - 2026

Asheville, NC - November 2026



ISCAP Proceedings: Abstract Presentation


ClassMail - A Gamified Approach to Business Email Compromise Awareness


Shawn Zwach
Dakota State University

Cody Welu
Dakota State University

Tyler Flaagan
Dakota State University

Abstract
In the past 10-15 years, organizations have implemented various forms of cybersecurity awareness training. Reasoning behind this varies from generic security hygiene, through mandated compliance with regulations or insurance providers. A component of almost any of these types of training is phishing awareness, in part due to how prevalent business email compromise (BEC) is. Sometimes, this is implemented via fake lures sent to users and then logging their interactions, although some research has shown this style of training to be ineffective. Thus, our focus in several outreach events throughout summer 2026, and continuing into the fall, was to present a live lecture examining real world phishing messages, before transitioning to a simulated webmail environment containing a custom scenario. Core to this plan is the use of LLMs for storyline and UI development. Of note, emails were added or deleted based on current threats experienced in South Dakota. The main storyline currently features five parts that are released to students in sequence. Each part has between four and six messages related to a fictional city, handling a fictional invoice, from a fictional vendor, along with generic workplace noise. Some of the messages are innocuous while some have malicious intent, or markers of such. The web application that powers the scenarios is easy to operate, and storylines are easy to import from JSON. This also makes creating new stories easy. The simulated environment was used to train cities and counties in South Dakota, with a few minor adaptations for usability. Learners can mark any message safe, malicious, or request out-of-band information. Researchers currently track the disposition of each message, the learner’s display name, the event they’re attending, and if they’ve opened the message or not (mostly for usability). Learner names are used in the storyline where appropriate. Early feedback from participants and trainers indicated high engagement and an improved ability to spot social engineering, phishing, and BEC messages. This project demonstrates a practical model for hands-on, scenario-driven cybersecurity training that can be adapted for many different contexts. The combination of a realistic webmail simulation, a narrative storyline, varied phishing techniques, and low-stakes environment with instructor input helped move the training past traditional slide-based instruction and phishing email tests in real inboxes. The researchers would like to hear feedback from ISCAP attendees on their experiences in the cybersecurity awareness space, specifically for a learner without a background in cybersecurity in general. The tool will be available to use by the audience during the presentation.