Pistachio's 2.47 Million Simulated Attacks Undercut the Click-Rate Metric
Pistachio, an Oslo-founded human risk management and security awareness vendor, has published a year-long analysis of 2.47 million simulated phishing attempts sent to more than 123,000 employees across over 1,200 organizations, arguing that the metric most security awareness programs are judged on — click rate — measures the wrong thing. The company's 2026 Phishing Behaviour Report, covering simulations delivered between June 1, 2025, and May 31, 2026, found that a low click rate can mask a workforce that still hands over credentials at meaningful rates, and that reporting behavior, not click avoidance, is the strongest signal of a mature program.
Findings at a Glance
| Metric | Finding |
|---|---|
| Dataset size | 2.47 million simulated phishing attempts, June 1, 2025 – May 31, 2026 |
| Participants | Over 123,000 employees across 1,200+ organizations |
| Delivery channels | Email and Microsoft Teams, via an AI-driven simulation platform |
| Highest click-rate department | Construction & Facility Management — 41.31% |
| Lowest click-rate department | Design — 26.35% |
| Highest credential-leak rate | Construction & Facility Management — 16.47% |
| Most resilient sector overall | Financial services (best across click, leak, and report rates) |
| Tech/IT click behavior | 30% of employees clicked at least one simulation |
| Lowest reporting rate | Health — 13.17% |
| Report-to-click ratio, 3 to 12 months | Rose from 1.3 to 1.8 over a 12-month program |
Methodology
Pistachio delivered its simulations through both email and Microsoft Teams, personalizing the difficulty and content of each phishing lure based on the recipient's role and their prior responses to earlier simulations — an approach the company says produces a more realistic picture of resilience than a single, uniform template blasted across an entire organization. A subset of the data with complete 12-month participation records — 648 organizations, 123,692 users, and roughly 355,000 simulations tracked as part of a longitudinal "journey" analysis — was used to study how behavior changes over the course of a sustained program rather than a single test.
To keep the comparison fair, Pistachio also controlled for test difficulty: harder simulations made up between 44% and 52% of all sends across the 16 named departments, meaning no single department was systematically handed an easier or harder mix of lures. That matters because departmental click-rate comparisons are only meaningful if every group faced comparable difficulty.
What the Data Actually Showed
Departmental results varied widely. Construction and facility management employees clicked simulated phishing links at the highest rate in the dataset — 41.31% — and also leaked credentials most often, at 16.47%. Design employees, by contrast, clicked least often, at 26.35%. Financial services outperformed every other sector across all three measured behaviors: clicking, credential leaking, and reporting.
One result stood out as counterintuitive: nearly a third of employees in technology and IT development roles — 30% — clicked at least one phishing simulation, a rate Pistachio's researchers flagged as surprising given that group's presumed technical fluency. Meanwhile, health-sector employees combined a comparatively low click rate with the lowest reporting rate in the dataset, 13.17%, and logistics employees paired an above-average click rate with a below-average report rate of 17.11% — two patterns that a click-rate-only dashboard would present very differently, and less accurately, than the fuller picture.
Why Click Rate Alone Misleads
The report's central argument is that click rate, by itself, is an incomplete and sometimes misleading proxy for organizational risk. Clicking a link is only the first step in a longer behavioral chain; what happens next — whether the employee enters credentials, recognizes the ruse and backs out, or reports the message to security — is what determines actual exposure. Pistachio CEO Joe Jones put it directly: a low click rate "can create a false sense of security," because "clicking a phishing link is just one moment in a longer chain of behavior. What matters is whether employees report the attack, recognize it, or prevent further action."
The longitudinal data reinforces that point. Comparing the six-month mark to the twelve-month mark of sustained programs, clicks fell by 27% and credential leaks fell by a much larger 41%, while reporting also declined, by 19%. Falling click rates over time can therefore reflect employees simply learning to recognize a vendor's repeated templates rather than genuine improvement in judgment against unfamiliar attacks — a distinction that a click-rate trend line cannot show on its own. The report-to-click ratio, which Pistachio treats as a more reliable resilience signal, rose steadily across the same period, from 1.3 at three months to 1.8 at twelve months, indicating that reporting behavior grew relative to clicking even as both declined in absolute terms.
Impact Assessment
| Stakeholder | Impact |
|---|---|
| Security awareness and GRC teams | Programs benchmarked solely on click-rate reduction may be reporting false progress while credential exposure and reporting behavior go unmeasured |
| CISOs and risk owners | Departmental variance (construction, health, logistics, IT) suggests one-size-fits-all training cadences under-serve higher-risk groups |
| Vendors and procurement | Buyers evaluating awareness platforms should ask how a tool measures leak and report rates, not just whether it can report a declining click percentage |
| Incident response teams | A workforce that reports suspicious messages at a high rate shortens detection time for real phishing campaigns, independent of click behavior |
| Boards and auditors | Click-rate-only KPIs in board reporting may understate residual credential-theft risk tied to phishing exposure |
Recommendations
For Security Awareness Program Owners
- Track credential-leak rate and reporting rate alongside click rate in every simulation cycle, not click rate in isolation
- Treat the report-to-click ratio as a primary maturity indicator; Pistachio's data suggests mature programs should see reporting occur nearly twice as often as clicking
- Vary simulation difficulty and templates over time so declining click rates reflect genuine judgment improvement rather than template familiarity
- Segment metrics by department and role, since resilience varies significantly between groups such as construction, IT, and financial services
For CISOs and Security Leadership
- Prioritize remediation resources toward departments showing the combination most correlated with real risk: above-average click or leak rates paired with below-average reporting, as seen in this data for logistics and health
- Avoid presenting click-rate reduction alone as program success to executives or boards; pair it with leak and report trends for an accurate risk picture
- Investigate root causes when technically skilled groups (e.g., IT/development) underperform expectations, since assumed technical fluency does not reliably translate into phishing resilience
- Ensure simulation vendors apply consistent difficulty distribution across business units so cross-departmental comparisons are statistically fair
Key Takeaways
- Pistachio's 2026 Phishing Behaviour Report analyzed 2.47 million simulated phishing attempts sent to over 123,000 employees across 1,200-plus organizations between June 2025 and May 2026.
- Click rate alone is a misleading resilience metric; the report argues organizations must also track credential-leak rate and reporting rate to understand real risk.
- Departmental results varied sharply — construction and facility management had the highest click (41.31%) and leak (16.47%) rates, while 30% of tech/IT employees clicked at least one simulation, and financial services was the most resilient sector overall.
- Health and logistics departments combined comparatively low or average click rates with weak reporting rates (13.17% and 17.11% respectively), a pattern invisible to click-rate-only dashboards.
- Over a 12-month program, clicks fell 27% and credential leaks fell 41% from the six-month mark, while the report-to-click ratio rose from 1.3 to 1.8 — evidence that reporting behavior is the more durable resilience signal.
- Pistachio recommends measuring clicks, credential leaks, and reporting together, and using consistent simulation difficulty across departments to keep comparisons fair.