Phishing tests: click rates misrepresent risk, study finds

Pistachio analysed 2.47 million simulated phishing attempts on 123,000 employees across 1,200 organisations (June 2025–May 2026) and urges tracking clicks, credential leaks and reports.

Pistachio, a security training firm founded in Oslo with offices in London and Valencia, analysed 2.47 million simulated phishing attempts sent to more than 123,000 employees at over 1,200 organisations between June 1, 2025 and May 31, 2026. The company measured three behaviours — clicking links, submitting credentials or other data, and reporting suspicious messages — and concluded that click rate alone does not reflect overall phishing risk.

Simulations were delivered by email and Microsoft Teams through an AI-driven training platform that adjusted content and difficulty based on each recipient’s role and prior responses. Pistachio says the automation and machine learning used in the programme made the 12-month test feasible; the company estimates a manually run version would have taken about 23 years to complete.

The analysis showed variation between sectors and teams. Financial services had the lowest rates of clicks, credential leaks and low reporting. Technical teams recorded higher click rates than expected: 30.27% of technology development staff and 28.53% of IT staff clicked at least once during the testing period. Click rates across sectors varied from 26.35% in design teams to 41.31% in construction. Almost 20% of employees in construction and real estate submitted credentials after a simulated phishing prompt.

Pistachio reported that, on first simulations, a larger share of users reported suspicious messages than clicked them, but 1.57% of users still submitted credentials. The company used a concrete example to illustrate the risk: at a firm with 500 employees, that leak rate corresponds to roughly eight people who might hand over login details in an attack.

The report tracked behaviour over the year. Click and credential-leak rates rose during the first six months of the programme before declining in the second half. By the end of the 12-month cycle, users were reporting suspicious emails nearly twice as often as they were clicking them.

Pistachio noted that the dataset spans multiple countries but does not include a geographic breakdown. The company said the report does not make claims about differences between countries and suggested regional analysis could help global organisations target training resources.

The report recommends that organisations and vendors measure downstream actions, not just clicks, when assessing phishing resistance. Joe Jones, Pistachio’s CEO and co-founder, warned against relying on a single metric: “A low click rate can create a false sense of security. Clicking a phishing link is just one moment in a much longer chain of employee behavior. What matters more is what happens next: does the employee hand over credentials, recognise the attack and stop, or report it so the wider business can act?”

Articles by this author