ScamDrill for Families

Safe Realistic Phishing Simulations - A Firedrill for Scams

Visit Website
June 2, 2026 ScamDrill for Families — phishing simulations for the people you love, not just the office

Hi IH,

I'm Justin, the founder of ScamDrill. Today I'm launching the consumer version of the product — ScamDrill for Families — and I'd love this community's read on it.

The thing that started it

A relative of mine forwarded me a "bank alert" to ask whether it was real. It wasn't. The link was a fake domain, the $1,847 "unauthorized transfer" was the bait, and the 30-minute countdown was the pressure. They almost clicked it. The only reason they didn't is that they happened to ask first.

That's the whole problem in one moment. The people most likely to get hit by a scam text — older parents, busy spouses, teenagers — are the ones who never get any practice spotting one. Meanwhile corporate security teams have been running phishing simulations on employees for fifteen years because they work. Families get nothing but the occasional "be careful out there" warning, which nobody remembers when a real countdown is staring at them.

So I built the corporate playbook for households.

How it works

It's a fire drill, but for scams. You set it up once in about three minutes:

  1. You invite the people you want to protect. They opt in, so they know practice scams are coming — they just don't know when.

  2. Safe, realistic simulations start arriving at unpredictable intervals, by email and by text. Fake IRS notices, bank alerts, delivery-fee texts, "grandkid in trouble" messages — all modeled on real scams reported to the FBI, FTC, and AARP.

  3. If someone clicks, they land on a friendly 60-second debrief that walks through the red flags. If they spot it, they get a bit of positive reinforcement. You see the whole household's progress on a dashboard.

The drills are completely inert. They never ask for a real password, card number, or money, the links go to a debrief page and nowhere dangerous, and we don't touch anyone's real inbox or accounts.

What I think is different

Most "scam protection" products are scanners or blockers — they try to catch the bad message for you. ScamDrill assumes the bad message will eventually get through (it always does) and trains the human instead. The behavior sticks because it's spaced practice on the exact formats people actually fall for, not a one-time quiz they forget by Tuesday.

The other deliberate choice was making it feel kind rather than punitive. No "gotcha," no shame. The early feedback I'm proudest of is people telling me their teenager finds the debriefs funny and their dad now screenshots real scam texts and laughs instead of clicking.

Pricing

There's a free forever tier for one learner with basic email drills, and paid family plans that add SMS drills, the full scam library, multiple learners, and reports. Paid plans start with a 14-day free trial, no card-up-front surprises. (Plans on the page if you want the specifics.)

What I'd love from you

A few things I'm genuinely unsure about and would value IH eyes on:

  • Positioning. Is "phishing simulation for families" clear immediately, or does it need a more everyday framing? I worry "simulation" sounds technical to the non-techy people this is actually for.

  • The opt-in. Everyone has to consent before drills start. It's the ethical call and I won't change it, but I'd love thoughts on how to make that step feel inviting rather than like a hurdle during setup.

  • Who actually buys. My hunch is the buyer is the adult kid protecting a parent, or a parent protecting a teen — i.e. someone buying for the at-risk person, not the at-risk person themselves. Curious whether that matches what you'd expect, and how that should change the messaging.

Happy to answer anything about the build, the scam-data sourcing, or how the B2C side connects to the B2B product. Thanks for reading.

— Justin

1 Comment

  1. 1

    Justin, you already wrote the everyday framing and then hid it behind the technical one. To your first question: "phishing simulation" is the corporate word you are right to worry about, and "a fire drill, but for scams" is the fix, sitting right there in your own post. Everyone understands a fire drill. Even better, lead with the moment, not the mechanism: the relative who almost clicked the $1,847 bank alert with the 30-minute countdown. That story is your ad. Sell the near-miss, not the "simulation."

    On who buys, your hunch is right and it is the most important thing on the page, because it flips the entire message. The at-risk person does not think they are at risk, which is exactly why they are, so you are not selling "protect yourself." You are selling "protect someone you love" to the adult kid who lies awake knowing that one day their dad clicks something and the savings are gone. Speak to the protector's fear and their helplessness, and hand them the one concrete thing they can finally do about a worry they have carried for years. That also makes this a gift, and the trigger is the near-miss, so the moment a family has a scare is the moment they come looking. Your opening story is the whole funnel.

    That reframes your opt-in worry too. Consent feels like a hurdle only when it reads like terms of service. But the opt-in is the handoff from the buyer to the person they love, so make it the warm invitation it actually is: not "please consent to receive simulated phishing messages," but "your daughter set this up because she is looking out for you, want to get sharp together?" The kindness you are already proud of, the funny debriefs, the no-shame tone, is what makes that invite land. Consent stops being friction the moment it arrives as love from the person who bought it, instead of a legal step from an app.

About

ScamDrill exists because many of my own family members have fallen victims to scammers and have lost thousands. I wanted a way to help them recognize these scams to build real world defenses.