Phishing Research Challenges Conventional Security Awareness Testing

Cybersecurity experts have long relied on simulated phishing tests to gauge an organization’s vulnerability to these types of attacks. But new research from Pistachio, a company specializing in automated human risk management and employee security awareness training, is challenging conventional wisdom about what these tests can reveal.

Pistachio sent over 2.47 million simulated phishing attempts to more than 123,000 employees across 1,200 organizations between June 2025 and May 2026. The results of their analysis were striking: nearly 30% of tech development and IT employees clicked on at least one of the simulations, while nearly 20% of construction and real estate employees leaked credentials after a successful phishing attempt. Financial services, on the other hand, outperformed all other sectors in click, credential leaking, and reporting rates.

The data suggests that organizations cannot assume they have a single phishing risk profile based solely on industry or job function. The proportion of employees who clicked at least once ranged from 26% in Design to 41% in Construction, highlighting the variability within different teams. What’s more, click rate alone is not a reliable indicator of phishing resistance – it’s the submission of credentials or other requested information that creates the actual risk.

Pistachio’s simulated phishing attacks were delivered through their AI-driven training platform via email and Teams channels, with content and difficulty tailored to each recipient’s role and previous responses. The use of artificial intelligence enabled the company to complete the testing program in just 12 months – a fraction of the time it would have taken to do manually.

However, the report also warns that simulated phishing tests may provide organizations with a misleading idea of their true phishing resistance. A strong indicator of improvement should look beyond click rate and consider how click, leak, and report behaviors change together over time. “Click rate is only part of the picture,” explains Joe Jones, CEO and co-founder at Pistachio. “A low click rate can create a false sense of security – it’s what happens next that matters.”

The research challenges several conventional assumptions about security awareness training:

* More users report than click on their first simulation, but still leak credentials.

* Technical teams are not automatically low risk: in the Pistachio testing program, 30.27% of tech development users and 28.53% of IT users clicked at least once.

* Phishing resilience is the result of fewer clicks and leaks, and more reporting – not just sustained programs can build vigilance.

To take away from this research, organizations should focus on building a culture of continuous security awareness training that goes beyond a single sending of simulated attacks. By sustaining their efforts over time, companies can see real improvements in their employees’ ability to detect and report suspicious emails – rather than just reducing the number of clicks.


Source: SecurityWeek — 2026-09-11