SECURITY Week reports on Pistachio’s phishing behaviour study, which analysed 2.47 million simulated phishing attempts sent to more than 123,000 employees across more than 1,200 organisations between 1 June 2025 and 31 May 2026. Delivered through Pistachio’s AI-driven training platform via email and Teams, the simulations were tailored to recipients’ roles and past responses.
The analysis looked at three outcomes: clicking, credential leaks, and reporting, highlighting that the traditional focus on click-through rates may significantly understate phishing risk.
The findings show domain-specific and role-based variation in risk. Nearly 30% of tech development staff and 28.5% of IT workers clicked at least once, with broader differences by team (26.35% in Design to 41.31% in Construction). Financial services emerged as the most resilient sector across clicks, credential leaks, and reporting.
Notably, even after initial simulations, leakage persisted: 1.57% of users leaked credentials, implying that in a 500-person organisation, about eight individuals might hand over login details. Importantly, more users reported suspicious emails than clicked by the end of the program, indicating that sustained training can build vigilance. However, the report cautions that a decline in clicks does not automatically equate to comprehensive phishing resilience, as attacks often unfold beyond the initial link click.
The analysis also notes the programme’s multinational scale but lacks geographic differentiation, which the authors describe as a drawback.