Tartan App Logo
Help Center / Setup & Configuration

Impersonation Attacks

Impersonation Attacks add internal phishing simulations where emails appear to come from trusted district roles (Leadership, Finance/HR, IT/Tech, or Employees). This helps you test social engineering risk across reporting lines, not just external threats.

What are Impersonation Attacks?

Impersonation Attacks add internal phishing simulations where emails appear to come from trusted district roles (Leadership, Finance/HR, IT/Tech, or Employees). This helps you test social engineering risk across reporting lines, not just external threats.

Video Walkthrough

Watch our step-by-step video guide to see the Impersonation Attacks setup process in action.

Availability

  • The feature is off by default.
  • Available only when Email Delivery Method is set to Google Workspace DMI (Recommended).
  • If your delivery method is not DMI, the Impersonation Attacks option is disabled.

How to Enable It

  1. Go to Account settings.
  2. Set Email Delivery Method to Google Workspace DMI (Recommended).
  3. Click the toggle next to the header "Impersonation Attacks"
  4. Optionally add a school signature in the editor.
  5. Click Save.

School Signature

  • The signature editor supports text, images, and links.
  • You can likely copy and paste in your existing email signature.
  • This signature is appended to impersonation emails.
  • You can leave it blank.
  • You can also use placeholders to have the signature dynamically updated with the sender information.
Template placeholders modal showing impersonation-only sender placeholders
Note: table borders in the editor are not visible in delivered emails.

Persona Mapping

Tartan maps existing Department values to standardized personas used by the impersonation scenarios:

  • District Leadership
  • Finance/HR
  • IT/Tech
  • Employees (staff only, no students)

Scenario Coverage (24 total)

Downward attacks (9)

Appears to be fromTargetsScenario themes
District LeadershipEmployeesPolicy Update, Staff Survey, SSN/SIN Request
Finance/HREmployeesTax Form Incomplete, Banking Correction, Address Confirmation
IT/TechEmployeesGoogle Password Sync, Tech Handbook Review, Security Compliance

Lateral attacks (6)

Appears to be fromTargetsScenario theme
IT/TechDistrict LeadershipHardware Upgrade
IT/TechFinance/HRInvoice Inquiry
Finance/HRIT/TechSoftware Audit
Finance/HRDistrict LeadershipBenefit Enrollment
District LeadershipFinance/HRUrgent Wire Transfer
District LeadershipIT/TechDomain Renewal

Upward attacks (9)

Appears to be fromTargetsScenario themes
EmployeesDistrict LeadershipResource Proposal, Contract Article 14, Outreach Proposal
EmployeesFinance/HRPayroll Diversion, Life Event Update, Reimbursement
EmployeesIT/TechTrouble Ticket, App Approval, Wi-Fi Help

Email Style

  • Impersonation emails are generated in a plain-text Gmail-like style.
  • Content is minimal and usually includes a link-based call to action.
  • School signature (if configured) is added at the bottom.

How Campaign Generation Works

When Impersonation Attacks are enabled, Tartan's AI generation engine draws from both:

  • Standard Phishing Simulation templates
  • Impersonation Attacks templates

Both pools are weighted equally. There is no built-in priority, so counts vary by campaign due to random selection and overall campaign/service configuration.

Need help with these instructions?

Contact Support