Overview
Exercise 3D interface
Immersive 3D security training exercise with interactive isometric office environment. Employees navigate realistic cyber attack scenarios.
Exercise 3D interface
Tenant analytics
Compliance dashboard
Course catalogue
Campaign management
Campaign details
Phishing analytics
Phishing email templates
Phishing landing pages
SCORM integration
RansomLeak Security Training
Platform walkthrough
OWASP Top 10 for LLM Applications
OWASP Top 10 for Agentic Applications

Product video
Immersive 3D Security Awareness Training
RansomLeak replaces passive video training with interactive 3D simulations that run in any browser, with no installation or headset. Employees work inside a fully simulated desktop (mail client, browser, terminal, password manager, and more than twenty applications) and a simulated phone (calls, texts, authenticator), handle realistic ransomware, BEC, and social engineering attacks, and learn by doing. Each 5-to-15-minute exercise ends with a scored knowledge check.
100+ hands-on exercises across 14 courses and 4 categories: security awareness, privacy and compliance (including a 16-exercise EU AI Act course), AI/LLM security, and real-world incidents. Available in 5 languages out of the box: English, German, Dutch, Italian, and Ukrainian, with additional locales on request and monthly content updates.
Microlearning Drills
Short 2-to-3-minute, authorable drills complement the 3D curriculum across six formats: email phishing, smishing, vishing, AI deepfake (voice and video), chat-based social engineering (Teams and Slack lookalikes), and MFA fatigue. Every plan includes unlimited drill authoring.
Simulation Campaigns
Phishing simulations: direct mailbox injection via Microsoft 365 Graph API and Google Workspace (no allowlisting fights with secure email gateways), 10 sender persona pools, difficulty levels 1 to 5, and 8-stage funnel analytics from delivery through click, credential submission, OAuth grant, BEC reply, and user report. Outlook and Gmail report buttons, repeat-offender tracking, and automatic remediation training with deadlines and grace periods.
Smishing simulations: real SMS campaigns with business-hours delivery in each recipient's timezone, per-recipient tap and report tracking, and STOP/REPORT opt-out registries.
Vishing simulations (coming soon): voice-call phishing campaigns with callback-verification training.
Human Risk Score & Risk-Based Automation
Every person gets an explainable 0-100 risk score built from phishing susceptibility, remediation debt, and training hygiene, with team and organization rollups. A no-code rule builder turns scores into action: auto-enroll risky users in remediation paths, deliver just-in-time training after a failed simulation, and escalate to managers. Dry-run mode, blast-radius caps, per-person cooldowns, and a full audit log keep automation safe.
Compliance Evidence
Learning paths and reports mapped to 13 frameworks: SOC 2, ISO 27001, ISO 27701, NIST CSF 2.0, GDPR, EU AI Act, CCPA/CPRA, HIPAA, HITRUST CSF, NIS2, PCI DSS, DORA, and CMMC. Audit-ready PDF and CSV evidence with timestamps and control references, scheduled report delivery, and a live Vanta integration that streams training status.
Enterprise Platform
- Hosted Cloud LMS, or SCORM 1.2/2004 export tested with 50+ LMS (Moodle, Cornerstone, Workday, SAP SuccessFactors, Docebo, and more)
- SSO/SAML 2.0 (Entra ID, Okta, Google Workspace), SCIM 2.0 user provisioning, MFA
- Role-based access control with custom roles, team management, and manager dashboards scoped to direct reports
- Multi-tenant isolation, white-label custom domains and branding, IP allowlisting
- REST API with scoped tokens, HMAC-signed webhooks (11 event types), Slack and Microsoft Teams notifications, SIEM data export
- Gamification (points, badges, leaderboards, streaks) and verifiable PDF certificates
Deployment
Fully managed SaaS on AWS. No installation required. Free tier available for evaluation; per-seat contracts for 12, 24, or 36 months.
Highlights
- Immersive 3D security awareness training in any browser: employees handle realistic ransomware, BEC, and social engineering attacks inside a fully simulated desktop and phone, learning by doing instead of watching videos. 100+ hands-on exercises across 14 courses in English, German, Dutch, Italian, and Ukrainian (more locales on request), including dedicated GDPR, EU AI Act, and AI/LLM security courses. Hosted Cloud LMS or SCORM 1.2/2004 export tested with 50+ LMS.
- Phishing and smishing simulation campaigns with direct Microsoft 365 and Google Workspace mailbox injection, real SMS delivery, and 8-stage funnel analytics; vishing campaigns coming soon. Separate 2-to-3-minute microlearning drills across six formats including AI deepfake. A per-person Human Risk Score drives automated remediation, just-in-time training, and manager escalation with dry-run mode and guardrails.
- Compliance evidence mapped to 13 frameworks (SOC 2, ISO 27001, HIPAA, GDPR, NIS2, EU AI Act, DORA, and more) with audit-ready reports and a live Vanta integration. Enterprise controls: SSO/SAML, SCIM 2.0, RBAC, white-label custom domains, REST API and signed webhooks. Multi-tenant SaaS on AWS with a free evaluation tier.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
User Seat | Per-user access to the RansomLeak security awareness training platform including all interactive 3D training modules, phishing simulation campaigns, deepfake drills, compliance learning paths, and real-time analytics. | $15.00 |
Free User | Free tier access to interactive 3D security exercises, quizzes, certificates, and learning progress tracking. Upgrade to User Seat for admin features, campaigns, analytics, and compliance reporting. | $0.00 |
Vendor refund policy
We offer a 30-day refund policy from the date of subscription. To request a refund, contact support@ransomleak.com with your AWS account ID and subscription details. Refunds are processed within 5-10 business days.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Support Channels
Email Support: support@ransomleak.com - Available Monday through Friday, 9:00 AM to 6:00 PM CET. Response time within 24 business hours.
Website: https://ransomleak.com - Product documentation, knowledge base, and FAQs.
Support Tiers
- Standard Support: Email-based support included with all subscriptions. Covers onboarding assistance, technical issues, and general inquiries.
-
- Priority Support: Available for Enterprise tier customers. Includes dedicated account manager, priority response times (4-hour SLA), and scheduled onboarding calls.
Getting Started
New customers receive guided onboarding support including tenant setup, SSO/SAML configuration, SCIM provisioning, and initial campaign configuration at no additional cost.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.