Authorized adversary simulation
Your attacker starts with what is already public.
Espyonaj runs the reconnaissance, the phone calls, and the email campaigns that a real intrusion begins with. Under written authorization, on a fixed scope, with a report you can hand to your board, your insurer, or your regulator.
Every engagement is authorized in writing before a single call is placed.
public sources
The sequence
Modern attacks do not break in. They call ahead.
Recent breaches across automotive, healthcare, and professional services followed the same three moves. Espyonaj runs all three, in order, so you find out where the chain holds and where it snaps.
Collect
Public records, job postings, social profiles, DNS, document metadata, and breach corpora. No access required, no laws bent, no permission asked. It is all sitting there.
Convince
A caller who already knows your vendor, your help desk's nickname, and your manager's name is not a stranger. That is the entire trick. Multifactor does not fail here. The person in front of it does.
Collect again
A code read aloud, a push approved, a reset performed, a link opened. From there the attacker is inside using valid credentials, during business hours, looking like an employee.
Services
Three engagements. Buy one or run the full chain.
Each stands alone. Run together, the reconnaissance feeds the pretexts, which makes the phone and email tests far more realistic than a generic template campaign.
Open source reconnaissance
The dossier an attacker would build on you, assembled from public sources, with a takedown or mitigation action attached to every finding.
See the service →Vishing simulation
Live calls against the help desk, the front office, and anyone who can reset a password. Scored on procedure, reported by department.
See the service →Phishing simulation
Campaigns built from your real vendors and invoice cycle, measured on submission and report rates rather than clicks alone.
See the service →How an engagement runs
No surprises for you. Only for the people we are testing.
You approve every pretext before it runs, you hold a stop command throughout, and you know the window in advance.
Authorization
A signed rules of engagement and an authorization letter from someone with authority to consent for the organization. It names the scope, the window, the approved pretexts, the numbers and mailboxes in play, and the emergency stop contact.
Reconnaissance
We build the dossier. If you bought OSINT alone, this is where the engagement ends and the report begins.
Pretext approval
You see every scenario in writing and sign off before anything goes out. Anything you veto does not run.
Execution
Defined hours, defined pace, live logging. One word from your stop contact ends it immediately, no questions asked.
Readout and retest
A live debrief with leadership, a written report mapped to your compliance obligations, and a retest once the fixes are in so you can prove the change.
Rules of engagement
Deception is the method. It is not the ethic.
We are asking you to authorize us to lie to your staff. That only works if you can see exactly where the limits sit.
We never impersonate real people
No government agencies, no law enforcement, no bank you actually use, and no named individual at a real vendor. Generic roles only. Third parties do not get pulled into your engagement without their consent.
We do not record calls by default
Consent laws differ by state and your employee has not consented to anything. We score from live notes and call logs. If you want recordings for training, it goes in the rules of engagement and your counsel approves it first.
Results are aggregate, not personnel files
You get rates by department and the procedural gaps behind them. Our contract states that results will not be used as the sole basis for discipline, because a simulation that gets someone fired teaches everyone else to stay quiet.
We stop when you say stop
Your stop contact ends the engagement on one call. If a test reaches someone in genuine distress, or reaches a customer instead of an employee, we stop on our own and tell you why.
Failing is not the finding
The finding is the missing procedure. If a caller talked someone out of a code, the fix is a verification standard, not a lecture. The readout is built to leave your team equipped rather than embarrassed.
Everything is insured and papered
Technology errors and omissions plus cyber liability, with social engineering testing explicitly disclosed to the carrier. Certificates available before you sign.
Who this is built for
Organizations holding data worth a phone call.
If your staff hand out information over the phone all day because that is the job, generic awareness training was never going to hold. These are the environments we know best.
Request a scope
Tell us who answers the phone.
We will come back with a scope, a fixed price, and the authorization paperwork you would need to sign. No obligation to run it.
Or call 888.788.ZERO
An Espyonaj engagement is delivered by Nwaj Tech.
We reply within one business day. We do not run anything without a signed authorization.