If you have to simulate a phishing attack on your org, at least try to get something useful from it

"we can't use anything as realistic in these exercises as the real phishers do, so most of our people can tell its a phish as it looks amateur"

I wonder how much this actually makes things worse. It's essentially teaching people that phishing looks like obvious fakes, potentially making them more likely to fall for real phishing which doesn't have the same restrictions.

