news.mlab.sh
Back to the feed
threat-intel

Phishing Research Challenges Conventional Security Awareness Testing

Medium
Summary

A report from Pistachio, a Norwegian cybersecurity firm, reveals that traditional phishing simulation testing, heavily reliant on user clicks, provides a misleading picture of an organization’s true phishing resistance. The study of over 123,000 employees across 1,200 organizations found that while many employees reported suspicious emails, a significant percentage still leaked credentials. Notably, tech and IT employees, who should be more resistant, performed worse than other sectors, highlighting the need to move beyond simple click rates and focus on a broader assessment of employee behavior, including credential leakage and reporting.

A report from Pistachio, a Norwegian cybersecurity firm, reveals that traditional phishing simulation testing, heavily reliant on user clicks, provides a misleading picture of an organization’s true phishing resistance. The study of over 123,000 employees across 1,200 organizations found that while many employees reported suspicious emails, a significant percentage still leaked credentials. Notably, tech and IT employees, who should be more resistant, performed worse than other sectors, highlighting the need to move beyond simple click rates and focus on a broader assessment of employee behavior, including credential leakage and reporting.

Between June 1, 2025 and May 31, 2026, Pistachio sent 2.47 million simulated phishing attempts to employees in over 1,200 organizations, analyzing user responses like clicks, credential leaks, and reports. The research demonstrated that a low click rate doesn’t necessarily indicate a strong security posture, as a substantial portion of employees still provided sensitive information after a successful phishing attempt.

Specifically, 30% of tech development and IT employees clicked at least one of the simulations, while nearly 20% of construction and real estate employees leaked credentials. Financial services, surprisingly, demonstrated the most resilience, outperforming all other sectors in terms of click, credential leaking, and reporting rates. However, the study also found that technical teams were not automatically low risk, with 30.27% of tech development users and 28.53% of IT users clicking at least once.

The report emphasizes that phishing resilience is not solely determined by a low click rate; it’s a result of fewer clicks and leaks, coupled with increased reporting. By the end of the 12-month program, users reported suspicious emails nearly twice as often as they clicked them, indicating that sustained and effective training can build vigilance.

Despite the study’s breadth, it lacked geographic analysis, noting that it couldn’t determine if different global areas were more or less susceptible to phishing. The research suggests that global organizations might consider providing additional training to specific locations based on local vulnerabilities.

Overall, this report serves as a critical reminder that organizations should carefully evaluate their phishing simulation testing programs and move beyond simplistic metrics to gain a more accurate understanding of employee behavior and overall security posture.

Read the full article at SecurityWeek