The Password Security Awareness Game That Shows the Attack, Not Just the Rule
"Use a strong password" is advice everyone has heard and almost nobody internalizes, because it's disconnected from any real consequence. BREACH // NOIR takes the opposite approach: instead of telling players a password policy, it puts them in the attacker's seat. You investigate a fictional target's public footprint, pull together the small personal details a real attacker would use, and reconstruct their password yourself. The lesson isn't delivered — it's experienced.
Why Most Password Security Training Doesn't Stick
Standard password security awareness training tells people what a weak password looks like in the abstract — a pet's name, a birthday, a favorite sports team. Almost everyone nods along, and almost everyone still does it anyway, because the training never shows the actual mechanism by which those details get discovered and combined. A cybersecurity awareness game closes that gap by making the discovery process itself the thing you practice. When you've personally watched a handful of public posts turn into a working password guess, "don't use your pet's name" stops being a rule you were told and becomes something you understand from the other side.
How the Password Guessing Mechanic Works
Each case gives you a target and a locked set of Intel Sources — the kind of public information anyone could realistically find. Every source you unlock costs Intel Credits and raises the target's Exposure score, so the game constantly asks you to weigh "is this detail worth the risk of digging for it?" — exactly the calculation a real attacker makes, and exactly the awareness you want your own team internalizing about their own public footprint. Once you think you've pieced together enough, you submit a password guess directly. Get it right, and the case debriefs you with your full score, your investigation timeline, and — for the cleanest solves — a hidden ending most players never see.
The mechanic scales in difficulty across the case catalog, starting with The Streamer's Slip, a deliberately gentle first case built to teach the loop without overwhelming a new player. Difficulty, source count, and password complexity all increase from there.
What This Teaches About Real Password Hygiene
Three habits transfer directly from the game to real password behavior. First, that predictable personal details — names, dates, teams, pets — are the first thing an attacker tries, not a last resort, because they work often enough to be worth trying first. Second, that combining two "safe-looking" pieces of information is usually enough, which is why oversharing any single detail publicly is riskier than it feels in isolation. Third, that a password reused across a public-facing account and a sensitive one means a single successful guess compromises both — a lesson that lands much harder after you've done the guessing yourself than after reading it in a policy document.
Using It for Team Awareness Training
Security teams frequently use BREACH // NOIR as a hands-on session inside a broader awareness program — it pairs naturally with phishing-simulation and policy training because it teaches the same underlying reasoning from the attacker's side. If you're evaluating it specifically for a team or organization, our security awareness training game page covers group use in more depth, and the pricing page explains how the credit system scales for heavier or repeated use.
See How Fast You Can Guess a Password
Free to play, no credit card required — your first case is waiting.
Create Your Free Agent AccountFrequently Asked Questions
Is this a real password cracking tool?
No. Every target and password in BREACH // NOIR is fictional and built specifically for this game. It teaches the reasoning attackers use, not a functioning cracking tool, and never touches any real account or real data.
Do I need a technical background to play?
No. The game is built for a general audience — the skill it teaches is investigative reasoning, not technical hacking, so no coding or security background is required.
Is the password security awareness game free?
Yes. Registration is free and every account receives a daily-refilling credit balance sufficient to play indefinitely. Optional credit packages exist for faster progress but are never required.
How is this different from a phishing simulation?
A phishing simulation tests whether someone clicks a suspicious link. This game teaches a different, complementary skill: recognizing how personal information exposed online becomes a working password guess in an attacker's hands.
Can I run this with my whole security team?
Yes — see our security awareness training game page for details on using it as a team exercise.