Breaking
SecurityDeveloping Story

Phishing Tests Miss What Happens After the Click

New Pistachio research argues click rate alone misleads, and that credential leaks and reporting matter just as much.

··1 hour ago·6 min read
a computer keyboard with a padlock on top of it
Photo by Sasun Bughdaryan on Unsplash

Most security awareness programs are graded on a single number: how many employees clicked the fake email. A new analysis from the phishing simulation vendor Pistachio argues that this number, on its own, tells you almost nothing about whether an organization is actually getting harder to phish.

The company studied 2.47 million simulated phishing attempts sent to more than 123,000 employees across more than 1,200 organizations between 1 June, 2025 and 31 May, 2026, and its takeaway is that click, leak, and report behaviors have to be read together.

The Scale Behind the Findings

Pistachio was founded in Oslo, Norway, in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations, and the dataset behind the report comes from its own customer base rather than a lab experiment.

The simulations were delivered through Pistachio's AI-driven training platform over channels including email and Teams. Content and difficulty were tailored to the recipient's role within the company and to how that person had responded during earlier simulated phishing attempts.

The company's analysis states that running the same testing regimen manually would have taken 23 years rather than 12 months to complete, a figure the company uses to illustrate the role artificial intelligence played in the program.

Why a Click Is Not the Risk

The report draws a distinction that many in-house testing programs blur. A user clicking a simulated phishing link, in Pistachio's framing, is merely a waste of that employee's time — the actual risk appears only when the user submits credentials or the other information the attacker requested.

That gap between clicking and leaking is what the report says organizations should be measuring. A program that watches clicks alone, it argues, can hand leadership a false picture of how resistant the workforce really is.

Pistachio's own report puts the point directly: "Click rate, the metric most phishing programs are judged on, is only part of the picture. A strong indicator of improvement needs to go beyond click rate, and should look at how click, leak and report behaviors change together over time."

Joe Jones, CEO and co-founder at Pistachio, expanded on why the single metric can mislead. "A low click rate can create a false sense of security. Clicking a phishing link is just one moment in a much longer chain of employee behavior, and on its own it says little about whether someone, or the organization as a whole, is actually getting more resilient. What matters more is what happens next: does the employee hand over credentials, recognize the attack and stop, or report it so the wider business can act?"

"A low click rate can create a false sense of security. Clicking a phishing link is just one moment in a much longer chain of employee behavior, and on its own it says little about whether someone, or the organization as a whole, is actually getting more resilient. What matters more is what happens next: does the employee hand over credentials, recognize the attack and stop, or report it so the wider business can act?"

— Joe Jones, CEO and co-founder at Pistachio

The First Simulation Surprise

One of the report's findings concerns what happens on a user's very first simulation. More users report the message than click it on that first outing. But that early vigilance does not eliminate leakage: 1.57% still hand over their credentials.

The report translates that rate into headcount. A company with 500 employees, it estimates, likely has 8 people who will give up their login details.

That framing matters because it is easy for a business to treat a single-digit percentage as noise. Pistachio's point is that the same percentage scales into a concrete number of exposed accounts at any reasonably sized employer.

Tech Teams Are Not Automatically Safe

The assumption that technical staff are inherently harder to fool does not hold up in the data. In the Pistachio testing program, 30.27% of tech development users and 28.53% of IT users clicked at least once.

Those figures sit above the rates recorded for several other functions, which the report treats as one of its more counterintuitive results given that technology and IT employees are expected to recognize phishing attempts.

The same test also produces different results in different teams. Click rates ranged from 26.35% in Design to 41.31% in Construction. The report's conclusion is that organizations do not have a single phishing risk profile — the risk is distributed unevenly across departments.

Other sector-level results reinforce the point. Nearly 20% of construction and real estate employees leaked credentials after a successful phishing attempt, while financial services proved the most resilient, outperforming all other sectors on click, credential leaking, and reporting rates.

Some of the numbers behind those findings:

  • 2.47 million simulated phishing attempts were sent during the program.
  • More than 123,000 employees at more than 1,200 organizations took part.
  • 30.27% of tech development users clicked at least once, along with 28.53% of IT users.
  • Click rates spanned 26.35% in Design to 41.31% in Construction.
  • 1.57% of first-simulation users leaked credentials, which the report equates to about 8 people at a 500-employee company.
  • Nearly 20% of construction and real estate employees leaked credentials after a successful phishing attempt.

Resilience Builds Slowly, Then Pays Off

Pistachio defines phishing resilience as the combination of fewer clicks and fewer leaks, plus more reporting — not any one of those behaviors on its own.

By the end of the 12-month program, users reported suspicious emails nearly twice as often as they clicked them. The company reads that as evidence that a sustained program can build vigilance rather than simply suppressing clicks.

The trajectory of the program complicates the usual picture of steady improvement. In the Pistachio test, click and leak rates rose through the first six months before beginning to decline.

The implication the report draws is that training has to continue past a single batch of simulated attacks. A program that stops after the first round of simulations would capture users at the point when their click and leak rates are still climbing.

What the Data Cannot Show

The report itself flags a limitation. The size of the Pistachio program implies it spans multiple countries, but the analysis contains no geographic breakdown.

That omission leaves a real question unanswered. While the research distinguishes between industry sectors and between teams, it does not separate results by location. There is no general proof that different global regions are better or worse at resisting phishing, but the report notes that its own data could confirm or deny that.

In the more serious case, the report suggests, a geographic view could indicate whether global organizations should direct additional training to specific locations rather than applying the same program everywhere.

What This Means for Awareness Programs

For security leaders, the practical argument in the report is that a dashboard built around click rate is measuring a proxy, not an outcome. The number that matters is how many people actually hand over credentials, and whether colleagues who spot an attack tell anyone about it.

That has consequences for how in-house phishing tests are designed. If a test only records clicks, it may report improvement while leak rates stay flat, and it may miss entirely whether reporting behavior is changing over time.

The program's own shape offers a second warning: if resilience only begins to improve after the first six months, then short campaigns may be measuring the wrong part of the curve. A company that tests once and declares its workforce trained could be looking at the phase when click and leak rates are still on the way up.

The sector and team differences point in the same direction for anyone planning a program. A single organization-wide score hides the fact that a construction team and a design team can sit at opposite ends of the same test, and that technology staff are not exempt from the risk. The report's overall recommendation is that its findings and analysis be consulted before any phishing simulation test is developed, whether that test is built in-house or run through Pistachio's own services.

#phishing#security awareness#simulation#human risk#credential theft

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories