Choose your learning path
Pick a starting path such as personal scam resistance, workplace fraud, social media scams or SOC training. All paths are available without a payment lock.
How to play
Cyber Scam Simulator is not a passive learning app. You progress by interacting with calls, texts, emails, social posts and SOC missions. Wrong choices can lead to compromise; correct choices unlock the next challenge.
Pick a starting path such as personal scam resistance, workplace fraud, social media scams or SOC training. All paths are available without a payment lock.
Your guardian sets the tone and tries to push you into mistakes. They are part coach, part adversary. The point is to make you slow down under pressure.
Answer the call, reply to the text, inspect the inbox or handle the social post. Each choice changes the route and the attacker’s next move.
Success and failure screens match the scenario. If you were caught, the game explains exactly how the attacker gained control.
Lessons are bite-sized and followed by quizzes. If you answer incorrectly, the game can rotate to another question so you have to learn the concept, not memorise the order.
Use the tabs to see how different routes work.
Calls use voice output and on-screen transcript text. The caller may become urgent, friendly, frustrated or authoritative depending on your choices. You decide whether to continue, challenge, verify or stop the call.
Texts arrive in a phone-style interface. You can reply, ignore, verify or take an action. The scenario progresses from your response rather than from a static multiple-choice screen.
Emails and social posts are presented as realistic screens. Players must inspect the context, spot route control, resist urgency and avoid fake checkout, investment or support paths.
Small mission briefs set up the operation. Red team tasks explore attacker decision paths in a safe training context. Blue team tasks focus on evidence, containment, reporting and recovery decisions.
Use a known official channel, saved app or existing contact record. Do not verify through a link, number or reply path supplied by the suspicious message.
Codes, passkeys, recovery phrases and approval prompts are control points. The safe move is usually to stop and verify independently.
In SOC modes, avoid both panic and inaction. Preserve evidence, contain confirmed paths and document decisions.
If something in the game resembles a live incident, stop playing and use official routes. Do not call back numbers or use links supplied by the suspicious contact.
Contact your bank through the number on your card or app. Report fraud/cybercrime through Action Fraud where applicable. Forward suspicious emails to report@phishing.gov.uk and scam texts to 7726.
US users can report fraud through the FTC and identity theft through IdentityTheft.gov. European users should use their national cybercrime reporting route or consumer advice network.
This website is informational and educational. It is not emergency, legal, financial or cybersecurity incident-response advice. If you are at immediate risk, contact local emergency services or your bank/platform through known official channels.