JATZO LEARNING
Learn to spot it
before it costs you.
Most people never get taught what a scam message actually looks like. These are short, practical lessons built around situations you will recognise, with feedback that explains every answer. No jargon, no security background needed.
Try lesson one freeThe first lesson of Phishing fundamentals is free. No card needed to try it.

WHY IT IS WORTH LEARNING
A check tells you about one message. Training changes every decision after it.
THE CATALOGUE
One catalogue. Start with the fundamentals.
Every module is self-paced and ends in an assessment.
Start with Phishing fundamentals, where the first lesson is free.

Phishing fundamentals
The entry point to the catalogue and the module a new starter should do first. What phishing actually is, why convincing messages get past capable people, the places it arrives beyond email, and the single habit that answers almost all of it. Written for everybody in an organisation, with no technical background assumed.
For anyone who uses email, at home or at work. Start here.
- Recognise what a suspicious message is asking you to do, whatever story it tells.
- Check an unexpected request through a route the message cannot reach.
- Report quickly and confidently, including when you have already clicked.

Protecting your work account
Your work account is the thing attackers want, whether your organisation signs in with Microsoft 365 or with Google Workspace. This module covers the four ways such an account is actually taken, including the attacks that keep working when multi-factor authentication is switched on.
For people who handle money, account access or sensitive information at work.
- Tell a genuine notification from your provider apart from an imitation of one.
- Recognise the sign-in, code and permission requests that defeat multi-factor authentication.
- Verify and report a suspect message without needing a technical background.

Invoice and payment fraud
How a criminal turns a real invoice into a payment they receive, why so much of that money is never returned, and the single control that stops it. For anyone who can pay a supplier, change a bank detail or approve a transfer.
For people who handle money, account access or sensitive information at work.
- Recognise a redirected payment request, including one inside a genuine conversation.
- Verify a change of bank details through a route the message cannot reach.
- Act in the first hour after a payment has gone to the wrong account.

QR code phishing
How a printed square moves an attack from a computer your organisation defends onto a phone it often cannot see, why QR codes were a blind spot for mail filters and what attackers now do about it, why a phone hides where a link goes, and what to do instead. For everybody, at a desk and in a car park.
For people who handle money, account access or sensitive information at work.
- Recognise a QR code as a request to continue on a device your organisation may not protect.
- Read a destination properly on a small screen, or decide not to open it.
- Spot a tampered physical code, and report a scan you regret quickly.

Social engineering
How a plausible story gets a careful person to do something they would never otherwise do, the levers underneath every version of it, and the process that holds even when the story is perfect. For everybody in an organisation, whatever their job.
For people who handle money, account access or sensitive information at work.
- Name the pressure a request is using, and treat that as information rather than as proof.
- Verify a person through a route you chose, not the one the request offered.
- Refuse a code, a prompt or a remote session without having to prove it was an attack.

Suspicious attachments
What really happens when you open a file, which attachment types are carrying attacks in 2026 rather than the macro era everybody still teaches, and how to find out whether a file is safe without opening it to see. For everybody in an organisation, with no technical background assumed.
For people who handle money, account access or sensitive information at work.
- Explain why a file name, an icon and a familiar sender prove nothing about a file.
- Recognise the attachment types doing the damage in 2026, including the ones that look harmless.
- Check, or report, an unexpected attachment without ever opening it.
What you get, and what we do not claim.
Every module is six lessons and an eight question assessment, with a personal completion record when you finish. The first lesson of Phishing fundamentals is free.
Training is included with Business Pro, for everyone on the subscription, along with any module added later. If you would rather learn on your own, the whole catalogue is £149 as a one-off purchase for one person, which includes twelve months of updates. There is no per-module price, because finishing one module and skipping the rest is not the same as being trained. A course purchase does not include checks, and a plan below Business Pro does not include training. Checkout is not enabled yet.
Polished messages can still be fraudulent, and unusual messages can be genuine. These modules teach independent verification, useful reporting and practical account protection. No course and no email checker can guarantee that every phishing attempt will be caught. The completion record is a personal record of progress, not an accredited qualification.
For teams, Business Pro gives every person their own access. Individual learning records are available now; the administrator view of who has completed what is not built yet.
