Why are organizations moving beyond traditional email phishing?
Traditional security awareness programs were built for an era when phishing arrived almost exclusively in an inbox. Modern threat actors no longer restrict their operations to email alone. According to threat intelligence data from CrowdStrike, voice phishing activity surged 442% between the first and second halves of 2024. Attackers are combining email lures with inbound telephone calls, SMS messages, and synthetic audio to bypass automated security filters and manipulate employees directly.
The rapid evolution of generative AI has lowered the technical barrier for high-conviction social engineering. According to research from McAfee Labs, voice cloning tools can synthesize a convincing replica with an 85% voice match using as little as three seconds of reference audio. When malicious actors combine public organizational data with synthetic media, standard phishing recognition training fails to prepare workforce members for multi-vector engagement.
- Voice phishing (vishing): Attackers impersonate IT helpdesk staff or executive leadership over live phone calls to harvest credentials or bypass multi-factor authentication.
- Telephone-oriented attack delivery (TOAD): Hybrid campaigns lure victims via email to initiate an outbound call to an attacker-controlled call center.
- SMS and messenger lures (smishing): Mobile vector attacks exploit personal or corporate mobile devices outside traditional perimeter controls.
- Deepfake video conferencing: Synthetic audio and video streams simulate executive presence during real-time virtual meetings to authorize fraudulent financial transfers.
Relying exclusively on email simulations leaves critical blind spots in enterprise risk management. Chief Information Security Officers must evaluate whether their security awareness platform can replicate the dynamic, multi-channel environment that threat actors actively exploit.
How does Hoxhunt approach human risk management?
Founded in Helsinki in 2016, Hoxhunt has established itself as a prominent human risk management platform built around behavioral science and gamification. The company expanded its market footprint following a $40 million Series B funding round led by Level Equity Management in May 2022. Its operational model focuses on transforming passive employees into active threat detectors by rewarding user participation through micro-learning modules and instant feedback loops.
Hoxhunt excels in global environments with primarily English-speaking workforces. By integrating directly into email clients such as Microsoft Outlook and Google Workspace, the platform delivers personalized phishing simulations adapted to individual skill levels. Its gamified architecture encourages high engagement rates across broad user bases, leveraging leaderboards, stars, and achievement badges to sustain participation.
- Gamified engagement engine: Utilizes positive reinforcement to motivate employees to report suspicious messages.
- Multichannel simulation: Hoxhunt's published product material lists email, smishing, vishing and callback, Microsoft Teams, and deepfake video.
- Adaptive difficulty: Adjusts campaign difficulty dynamically based on historical user performance.
- Global ecosystem integrations: Features strong technical co-selling partnerships with major technology vendors and global consultancies.
Hoxhunt has also extended well past the inbox. Its published product material describes executive-impersonation scenarios built with AI-generated or cloned voices alongside its email, SMS and Teams simulations. For buyers, the meaningful question is therefore not which channels each vendor can reach — both cover the ground that matters, including vishing attacks — but how scenarios are generated, where data is processed, and how reporting is anonymised.
What makes an OSINT-driven platform different?
An OSINT-driven platform is engineered to address modern generative AI threats across every digital touchpoint. Unlike tools that rely on static template libraries, this approach deploys an automated engine that synthesizes scenarios based on current threat intelligence and open-source intelligence (OSINT) data. It maps real external attack surface details to build role-specific simulations.
Through the Awareness Playlist pillar, security teams can execute coordinated, multi-channel scenarios that span email, SMS, voice, and deepfake video without manual campaign design. When an employee encounters a simulation, the platform delivers real-time micro-learning directly in the flow of work, reinforcing defensive habits at the precise moment of interaction.
- Native voice and deepfake engine: Conducts automated vishing and video simulations using customizable voice models and synthetic media.
- Continuous OSINT risk profiling: Analyzes publicly available organizational data to simulate real-world spear phishing tactics accurately.
- Role-specific learning paths: Delivers targeted training via the Academy module to align with individual department risk profiles.
- Unified risk monitoring: Aggregates real-time interaction metrics into actionable Human Firewall Index benchmarks for CISOs.
By evaluating employee responses across multiple communication channels simultaneously, security leaders gain a realistic measurement of organizational vulnerability rather than an isolated metric on email click rates.
How do Hoxhunt and revel8 compare on core features?
Evaluating security awareness vendors requires comparing how each platform addresses threat vector coverage, content localization, and technical architecture. The matrix below outlines the core functional differences between the two options.
| Feature / Capability | Hoxhunt | revel8 Platform |
|---|---|---|
| Primary Focus | Gamified threat reporting grounded in behavioral science | Multi-channel AI attack simulation and human risk profiling |
| Voice Phishing (Vishing) | Vishing and callback simulation listed as a standard capability | Native automated voice-AI simulation engine |
| Deepfake Video Simulation | Deepfake spear phishing with AI-generated or cloned voices, listed as a standard capability | Native scenario builder for synthetic video lures |
| Attack Contextualization | Adaptive engine tailoring simulations to each employee's behavior, role, and history | Dynamic OSINT risk profiling adapted to target attack surface |
| Data Residency & Hosting | Global cloud infrastructure | Sovereign European cloud hosting on STACKIT in Germany |
| Works Council Privacy Controls | Standard reporting anonymization | Default group-level reporting with minimum cohort limits |
Both vendors cover the modern channel spectrum. Where Hoxhunt leans on gamification mechanics to drive engagement and reporting rates, revel8 leans on OSINT-derived targeting and European data sovereignty — which is where the two diverge for a DACH buyer.
Which platform offers better compliance for DACH enterprises?
For enterprises operating in Germany, Austria, and Switzerland (DACH), regulatory alignment and data sovereignty are essential purchasing criteria. Global awareness platforms frequently rely on translated English content and host data on non-European infrastructure, which can introduce friction during privacy reviews and regulatory audits.
The revel8 Platform is built for European sovereign compliance. It is hosted on STACKIT, whose company headquarters, data centers and servers are located exclusively in Europe, placing the infrastructure under European and German law, so enterprise data stays within European jurisdiction. This architecture simplifies alignment with NIS2 requirements, DORA, and ISO 27001 mandates that require strict data control and audit-ready reporting.
- European data residency: Data processing occurs locally on sovereign German cloud infrastructure available on the STACKIT Marketplace.
- Works council (Betriebsvereinbarung) readiness: Features pre-packaged agreement templates and privacy-first configurations to accelerate worker council approvals.
- Default reporting anonymization: Enforces minimum reporting group sizes of five employees to protect individual privacy while giving management aggregate risk metrics.
- Native DACH context: Content is authored specifically for German regulatory frameworks and regional business practices.
By embedding privacy controls into the core platform by default, security teams can deploy continuous simulations without incurring lengthy legal delays or pushback from employee representatives.
When does each security awareness solution fit best?
Choosing between Hoxhunt and revel8 ultimately depends on your organization's primary threat model, geographical footprint, and regulatory requirements. Both platforms offer proven capabilities, but they serve distinct operational priorities.
- Select Hoxhunt if: Your organization is global and primarily English-speaking, and you want to drive employee engagement through gamification. It is a mature solution, with a multichannel simulation set behind it, if your main objective is building a positive security culture around threat reporting using leaderboards and rewards.
- Select the revel8 Platform if: You are a European or DACH enterprise that needs sovereign cloud infrastructure, works council-ready privacy defaults, native German content, and simulations generated from continuous OSINT profiling of your own external attack surface.

.avif)



