Phishing research challenges conventional security awareness tests

The message is simple: refine future internal phishing simulation tests through Pistachio’s research findings and analysis.

Pistachio was founded in Oslo, Norway in 2019, with additional offices in London and Valencia. Specializes in automated human risk management, employee security training and phishing simulations. Between June 1, 2025 and May 31, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees at more than 1,200 organizations. Her next analysis look at clicks, leaks and reporting.

Thirty percent of technology development and IT employees clicked on at least one of these phishing simulations. Nearly 20% of construction and real estate workers have had credentials leaked after a successful phishing attempt. Financial services was the most resilient, outperforming all other sectors in clicks, credential leaks and reporting rates.

While it’s not surprising that financial services performed better, it’s more surprising that technology and IT (which really should know better) performed so poorly. The differences identified in the report suggest that organizations do not have a uniform phishing risk profile. The proportion of employees who clicked at least once varied from 26% in design to 41% in construction.

Pistachio’s simulated phishing attacks were delivered through its own AI-driven training platform through channels including email and Teams. Content and difficulty are based on the recipient’s role within the company and how they have previously responded during other simulated phishing attempts. (As an aside, this demonstrates the power of artificial intelligence. If the process had been done manually, it would have taken 23 years, not 12 months, to complete.)

However, the report also demonstrates the importance of simulated phishing tests to look beyond the user click to the user response. Clicking itself is just a waste of employee time without significant phishing risk. Submitting credentials or other requested information creates a risk of phishing. This in turn warns that internal phishing tests can provide organizations with a misleading picture of true phishing resistance.

Advertising. Scroll to continue reading.

“Click-through rate, the metric by which most phishing programs are evaluated, is only part of the picture. A strong indicator of improvement should go beyond click-through rate and should look at how click-through, leakage, and reporting behaviors change over time,” the report explains.

Joe Jones, CEO and co-founder of Pistachio, further explains: “A low click-through rate can create a false sense of security. Clicking on a phishing link is just one moment in a much longer chain of employee behavior, and by itself doesn’t say much about whether someone or the organization as a whole is actually becoming more resilient. What’s more important is what happens next: whether the employee hands over the credentials, recognizes the attack and stops or reports it, so the wider business can act?’

Pistachio found several test effects that challenge conventional security awareness training:

More users report than click on their first simulation, but 1.57% still leak credentials. This means that a company with 500 employees probably has 8 people who will hand over their login details.

Technical teams are not automatically low risk. In the Pistachio test program, 30.27% of technology development users and 28.53% of IT users clicked at least once. The same test gives different results in different teams: the click rate varies from 26.35% in design to 41.31% in construction.

Phishing resistance is the result of fewer clicks and bounces and more reporting. By the end of the 12-month program, users reported suspicious emails almost twice as often as they clicked on them, showing that effective and sustainable programs can build vigilance, not just fewer clicks. However, training needs to be sustained beyond sending simulated attacks once: in Pistachio’s test, click and leak rates rose during the first six months of the program before starting to decline.

It is worth noting that the size of the Pistachio program suggests that it is multinational in degree, but there is no ‘geographic breakdown’. This is disappointing. While the analysis highlights differences across industry sectors and teams, it does not distinguish between geographic locations. To be honest, there is no general proof that different global areas are better or worse in terms of susceptibility to phishing, but this research may prove or disprove it. At worst, it could perhaps indicate whether global organizations need to provide additional training to individual locations.

Overall, this is a report that should be considered before developing a phishing simulation test, whether in-house or through Pistachio’s own services.

Connected: Trezor says 347,000 users received phishing emails after Brevo hack

Connected: A new phishing attack creates malicious pages in the victim’s browser

Connected: A new phishing toolkit uses passwords to maintain access after a password reset

Connected: Over 500 organizations affected in long-running phishing campaign

Leave a Reply

Your email address will not be published. Required fields are marked *