Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2761+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Phishing Research Challenges Conventional Security Awareness Testing
Phishing Research Challenges Conventional Security Awareness Testing
NEWS

Phishing Research Challenges Conventional Security Awareness Testing

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.

Dylan H.

News Desk

September 12, 2026
7 min read

Pistachio's 2.47 Million Simulated Attacks Undercut the Click-Rate Metric

Pistachio, an Oslo-founded human risk management and security awareness vendor, has published a year-long analysis of 2.47 million simulated phishing attempts sent to more than 123,000 employees across over 1,200 organizations, arguing that the metric most security awareness programs are judged on — click rate — measures the wrong thing. The company's 2026 Phishing Behaviour Report, covering simulations delivered between June 1, 2025, and May 31, 2026, found that a low click rate can mask a workforce that still hands over credentials at meaningful rates, and that reporting behavior, not click avoidance, is the strongest signal of a mature program.


Findings at a Glance

MetricFinding
Dataset size2.47 million simulated phishing attempts, June 1, 2025 – May 31, 2026
ParticipantsOver 123,000 employees across 1,200+ organizations
Delivery channelsEmail and Microsoft Teams, via an AI-driven simulation platform
Highest click-rate departmentConstruction & Facility Management — 41.31%
Lowest click-rate departmentDesign — 26.35%
Highest credential-leak rateConstruction & Facility Management — 16.47%
Most resilient sector overallFinancial services (best across click, leak, and report rates)
Tech/IT click behavior30% of employees clicked at least one simulation
Lowest reporting rateHealth — 13.17%
Report-to-click ratio, 3 to 12 monthsRose from 1.3 to 1.8 over a 12-month program

Methodology

Pistachio delivered its simulations through both email and Microsoft Teams, personalizing the difficulty and content of each phishing lure based on the recipient's role and their prior responses to earlier simulations — an approach the company says produces a more realistic picture of resilience than a single, uniform template blasted across an entire organization. A subset of the data with complete 12-month participation records — 648 organizations, 123,692 users, and roughly 355,000 simulations tracked as part of a longitudinal "journey" analysis — was used to study how behavior changes over the course of a sustained program rather than a single test.

To keep the comparison fair, Pistachio also controlled for test difficulty: harder simulations made up between 44% and 52% of all sends across the 16 named departments, meaning no single department was systematically handed an easier or harder mix of lures. That matters because departmental click-rate comparisons are only meaningful if every group faced comparable difficulty.

What the Data Actually Showed

Departmental results varied widely. Construction and facility management employees clicked simulated phishing links at the highest rate in the dataset — 41.31% — and also leaked credentials most often, at 16.47%. Design employees, by contrast, clicked least often, at 26.35%. Financial services outperformed every other sector across all three measured behaviors: clicking, credential leaking, and reporting.

One result stood out as counterintuitive: nearly a third of employees in technology and IT development roles — 30% — clicked at least one phishing simulation, a rate Pistachio's researchers flagged as surprising given that group's presumed technical fluency. Meanwhile, health-sector employees combined a comparatively low click rate with the lowest reporting rate in the dataset, 13.17%, and logistics employees paired an above-average click rate with a below-average report rate of 17.11% — two patterns that a click-rate-only dashboard would present very differently, and less accurately, than the fuller picture.

Why Click Rate Alone Misleads

The report's central argument is that click rate, by itself, is an incomplete and sometimes misleading proxy for organizational risk. Clicking a link is only the first step in a longer behavioral chain; what happens next — whether the employee enters credentials, recognizes the ruse and backs out, or reports the message to security — is what determines actual exposure. Pistachio CEO Joe Jones put it directly: a low click rate "can create a false sense of security," because "clicking a phishing link is just one moment in a longer chain of behavior. What matters is whether employees report the attack, recognize it, or prevent further action."

The longitudinal data reinforces that point. Comparing the six-month mark to the twelve-month mark of sustained programs, clicks fell by 27% and credential leaks fell by a much larger 41%, while reporting also declined, by 19%. Falling click rates over time can therefore reflect employees simply learning to recognize a vendor's repeated templates rather than genuine improvement in judgment against unfamiliar attacks — a distinction that a click-rate trend line cannot show on its own. The report-to-click ratio, which Pistachio treats as a more reliable resilience signal, rose steadily across the same period, from 1.3 at three months to 1.8 at twelve months, indicating that reporting behavior grew relative to clicking even as both declined in absolute terms.

Impact Assessment

StakeholderImpact
Security awareness and GRC teamsPrograms benchmarked solely on click-rate reduction may be reporting false progress while credential exposure and reporting behavior go unmeasured
CISOs and risk ownersDepartmental variance (construction, health, logistics, IT) suggests one-size-fits-all training cadences under-serve higher-risk groups
Vendors and procurementBuyers evaluating awareness platforms should ask how a tool measures leak and report rates, not just whether it can report a declining click percentage
Incident response teamsA workforce that reports suspicious messages at a high rate shortens detection time for real phishing campaigns, independent of click behavior
Boards and auditorsClick-rate-only KPIs in board reporting may understate residual credential-theft risk tied to phishing exposure

Recommendations

For Security Awareness Program Owners

  • Track credential-leak rate and reporting rate alongside click rate in every simulation cycle, not click rate in isolation
  • Treat the report-to-click ratio as a primary maturity indicator; Pistachio's data suggests mature programs should see reporting occur nearly twice as often as clicking
  • Vary simulation difficulty and templates over time so declining click rates reflect genuine judgment improvement rather than template familiarity
  • Segment metrics by department and role, since resilience varies significantly between groups such as construction, IT, and financial services

For CISOs and Security Leadership

  • Prioritize remediation resources toward departments showing the combination most correlated with real risk: above-average click or leak rates paired with below-average reporting, as seen in this data for logistics and health
  • Avoid presenting click-rate reduction alone as program success to executives or boards; pair it with leak and report trends for an accurate risk picture
  • Investigate root causes when technically skilled groups (e.g., IT/development) underperform expectations, since assumed technical fluency does not reliably translate into phishing resilience
  • Ensure simulation vendors apply consistent difficulty distribution across business units so cross-departmental comparisons are statistically fair

Key Takeaways

  1. Pistachio's 2026 Phishing Behaviour Report analyzed 2.47 million simulated phishing attempts sent to over 123,000 employees across 1,200-plus organizations between June 2025 and May 2026.
  2. Click rate alone is a misleading resilience metric; the report argues organizations must also track credential-leak rate and reporting rate to understand real risk.
  3. Departmental results varied sharply — construction and facility management had the highest click (41.31%) and leak (16.47%) rates, while 30% of tech/IT employees clicked at least one simulation, and financial services was the most resilient sector overall.
  4. Health and logistics departments combined comparatively low or average click rates with weak reporting rates (13.17% and 17.11% respectively), a pattern invisible to click-rate-only dashboards.
  5. Over a 12-month program, clicks fell 27% and credential leaks fell 41% from the six-month mark, while the report-to-click ratio rose from 1.3 to 1.8 — evidence that reporting behavior is the more durable resilience signal.
  6. Pistachio recommends measuring clicks, credential leaks, and reporting together, and using consistent simulation difficulty across departments to keep comparisons fair.

Sources

  • SecurityWeek — Phishing Research Challenges Conventional Security Awareness Testing
  • Help Net Security — Companies may be measuring phishing resilience the wrong way
#Phishing#Security Awareness#Credential Theft#Human Risk Management#Security Metrics

Related Articles

Gophish Phishing Simulation Lab: Security Awareness Testing in Docker

Deploy a self-hosted phishing simulation platform using Gophish in Docker. Build real-world phishing campaigns, track user engagement, and run security...

12 min read

1 Billion CISA KEV Records Reveal Human-Scale Security Has

A Qualys analysis of over one billion CISA Known Exploited Vulnerabilities remediation records shows that most critical flaws are being actively exploited...

5 min read

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Severity scores alone don't measure risk — autonomous penetration testing is shifting prioritization toward exploitable attack paths, not CVSS scores.

3 min read
Back to all News