About the game
White hats vs black hats on Skull Island
Phish Wars is a free cyber security artillery game you play right here in your browser. Your three ninja fish, the White Hat Tuna (Nori, Wasabi and Miso), take on the computer's Black Hat Barracudas (Clickbait, Spoofy and Malwhere) across Skull Island, which you can blast, dig and tunnel through. Take turns to walk, aim and fire: every weapon is a real attack technique, from the Brute Force Blaster and the Ransomware Puffer to the Spear-Phish Missile and the Zero-Day Nuke, and your shields, the MFA Bubble and Patching, are real security controls.
Then the battle stops for a message from HQ. Crates parachute in with an email, a text or a team-chat message, and walking into one opens it for you to judge: report a phish for double loot, open a genuine message for its loot, and if you open a phish, it's a Trojan that blows up in your fins. Knock out all three Barracudas to win the battle for Skull Island.
- Genre
- Turn-based artillery
- Play time
- About 10 minutes
- Teams
- 3 ninja fish a side
- Messages
- 70 emails, texts and chats
- Languages
- 75, pick at the start
- Price
- Free, no sign-up
How to play
Aim, fire, report
- Press Play, then Play on the title screen. Your White Hat Tuna always move first, and a turn lasts up to 45 seconds.
- Walk, aim and fire. Walk with the arrow keys, aim with up and down, then hold Space to power up and let go to fire. Watch the wind gauge: the wind pushes your shots.
- Pick the right weapon. Press 1 to 9 or 0, or click one: six attacks, two shields and two tools. Raising an MFA Bubble or using Patching doesn't end your turn, so shield up, then attack. Greyed-out weapons have no ammo yet: messages from HQ bring more.
- Judge every message from HQ. Walk into a crate to read its email, text or team-chat message. Report a phish for double loot, open a genuine one for its loot, and never open a phish: it's a Trojan that blows up in your fins.
- Knock out all three Barracudas. Blast them, or knock them into the sea, before they do the same to your fish. Win the battle for Skull Island, then claim your spot on the leaderboard.
How your score adds up
Your score is 5,000 points for a victory, plus 10 for every point of damage you deal, 400 for every phish you report and 150 for every genuine message you open, and on a win 600 for every fish still standing and a speed bonus of up to 3,000 that shrinks by 6 points a second, minus 6 for every point of damage your fish take and 750 for every phish you open. A battle you end early, with End battle or with Close game while it is on, keeps half its score; a battle you play to the end keeps it all, even a defeat.
5,000 for a win+
10 × damage dealt+
400 × phish reported+
150 × genuine opened+
600 × fish left+
Speed bonus−
6 × damage taken−
750 × phish opened=
Your score
Keyboard controls
- ←→ or ADWalk
- ↑↓ or WSAim
- SpaceHold to power up, let go to fire
- EnterJump
- 1–9 0Pick a weapon
- BackspaceEnd your turn
- Esc or PPause
- ?How to play
Pro tip: Ending a battle early halves your score, but a defeat keeps everything you earned, so play every battle out. Unsure about a message? Report it: a genuine message you report only loses its loot, while a phish you open costs 750 points. And the Zero-Day Nuke waits in the skull's right eye: dig in with the Pickaxe, then judge its message right to win it. On a touch screen, play with the buttons under the battlefield.
What you'll learn
70 messages to judge, 10 field notes from real life
Every crate is a phishing test, from obvious to subtle, and after each call the game shows the red flags, or why the message was genuine, with a tip for real life. Every weapon, shield and tool in your arsenal stands for something real too, and the field notes on the results screen explain each one you used.
Messages from HQ
Email, texts and team chat
- Check the sender letter by letter
- See where a link really goes
- Slow down for pressure and secrecy
- Never share a sign-in code
Attacks
Six real attack techniques
- Brute force: bots guessing passwords
- Ransomware: files locked for money
- Botnets and DDoS: hijacked gadgets
- Spam: mass email blasts
- Spear phishing: a phish just for you
- Zero-day exploits: flaws nobody has patched
Shields and tools
Real controls and habits
- MFA: a second proof it's really you
- Patching: updates that close the holes
- Pickaxe: dig deeper before you trust
- VPN Jetpack: a VPN on public Wi‑Fi
Messages from HQ, and the right call
- Sensei Koi, from a free mail address: buy six gift cards and keep it quiet.Report it. Check odd requests from a boss by calling a number you already have.
- Dojo Payroll asks you to confirm your bank details, from doj0.reef.Report it: that's a zero, not an o. Read sender addresses letter by letter.
- A text from DOJO: tap Approve on the sign-in we just sent you.Report it. Only approve sign-in prompts you started yourself.
- Wasabi, in team chat: buy vouchers for the raffle, and don't tell Sensei.Report it. Even a real colleague's account can be hijacked, so check another way.
- A supplier emails new bank details for this month's order.Report it, and confirm any change of bank details on a number you already have.
- URGENT: fire drill at 11am today. No reply needed.Open it: it's genuine. Urgency alone doesn't make a message fake.
FAQ
Phish Wars questions
Is Phish Wars free to play?
Yes. It is completely free and runs in your web browser, with no download, account or sign-up. You only pick a gamer alias if you want to put a top score on the public leaderboard. Organisations that use CanIPhish can also assign it to employees as security awareness training, with a private company leaderboard.
What does Phish Wars teach?
How to spot a phish, above all. Every crate that parachutes in carries a message from HQ to judge, drawn from 70 emails, texts and team-chat messages: lookalike domains, links that go somewhere else, reply-to tricks, fake invoices and new bank details, a boss who wants gift cards, QR codes, requests to approve a sign-in or share a code, and genuine messages that sound urgent but check out. After every call the game shows the red flags, or why the message was genuine, with a tip for real life. The weapons and shields teach the rest: each is a real attack or control, from brute force, ransomware, botnets and zero-day exploits to multi-factor authentication and patching, with a plain-language note about the real thing.
How is my score calculated?
You score 5,000 points for a victory, 10 for every point of damage you deal, 400 for every phish you report and 150 for every genuine message you open, and you lose 6 for every point of damage your fish take and 750 for every phish you open, because it's a Trojan. Win, and every fish still standing adds 600 and a quick win adds a speed bonus of up to 3,000. A battle you end early (End battle, or Close game while a battle is on) keeps half its points; a battle you play to the end keeps them all, even a defeat. Your best score can go on the leaderboard, which lists the top 50 players of all time.
How long does a game of Phish Wars take?
A battle takes about 10 minutes, and 3 knockouts win it: knock out all three Barracudas before they knock out your fish. Each turn lasts up to 45 seconds, the battle clock stops while you read a message from HQ, and you can pause at any time. After 30 turns the tide starts rising, so every battle comes to an end.
What devices and languages does it support?
It runs in any modern browser on desktops, laptops and tablets, and on phones held sideways, although a larger screen is best. Play with the keyboard, or with the on-screen buttons on a touch screen. You can play in 75 languages: choose yours from the language picker on the title screen.
Using Phish Wars for security awareness training at work? Bring it to your team or start a free CanIPhish account.