Decoding the world of cybersecurity

· ·

Phishing study challenges click-rate metrics

A 12-month dataset covering more than 123,000 users suggests falling phishing click rates can conceal credential exposure and weak reporting behaviour when simulation difficulty is ignored.

Phishing study challenges click-rate metrics
Summary
  • Pistachio's like-for-like cohort covers 648 organisations, 123,692 users, and more than 2.47 million phishing simulations over 12 months.
  • Click rates rose as simulation difficulty increased before falling later, complicating simple before-and-after measurements.
  • Credential leakage, reporting rates, and department-level variation can reveal exposure that a headline click percentage does not.

A falling phishing click rate can create a misleading picture of employee resilience when it is separated from credential leakage, reporting behaviour, and the difficulty of the simulations being used, according to a large 12-month dataset published by Norwegian security company Pistachio.

The company’s 2026 phishing behaviour research draws on 2,473,158 simulated attacks sent across 1,288 organisations. Its principal analysis uses a like-for-like cohort of 648 organisations with a complete 12-month record, covering 123,692 users.

The figures come from Pistachio’s own commercial platform rather than an independent population study, which limits how confidently they can be generalised beyond its customer base. The size and continuity of the cohort nevertheless provide a useful test of how familiar awareness metrics behave when the difficulty of the exercises changes over time.

Pistachio says 1.57% of users disclosed credentials during their first simulation, before training had taken effect. Click and credential-leak rates then rose around the middle of the programme as the simulations became more difficult before declining later.

That pattern complicates a common way of measuring security-awareness programmes. A falling click rate may indicate that users are improving, but it may also reflect familiar message templates, easier tests, or changes in the population being measured. Conversely, a temporary increase can occur when simulations become more convincing and expose weaknesses that simpler exercises failed to reach.

The company’s data also found substantial differences between departments given a broadly similar mix of test difficulty. Cumulative click rates ranged from 26.35% in one department to 41.31% in another.

Technical teams did not sit outside the problem. Pistachio says 30.27% of technology-development users and 28.53% of IT users clicked at least one simulation during the year. Those figures do not establish that technical employees are inherently more vulnerable, but they weaken the assumption that familiarity with security concepts consistently prevents a user from interacting with a convincing message during ordinary work.

Credential disclosure is also materially different from clicking. A user may open a link without progressing to a login page, while another may hand an attacker information that can immediately be tested against corporate identity systems. Treating both outcomes as one failure category obscures the operational difference between interaction and potential account compromise.

Reporting provides a third signal. By month 12, Pistachio says users were reporting suspicious messages nearly twice as frequently as they were clicking them. Reporting is less visually convenient than a simple failure percentage, but it can affect incident detection because a suspicious message escalated quickly by one recipient may expose a campaign that has reached dozens of others.

The study therefore reaches beyond awareness training into a broader governance problem around cyber metrics. Measurements selected because they are easy to present to management can lose the context required to explain whether underlying exposure is improving.

A board-level chart showing that click rates fell from one quarter to the next says little if the simulations became easier, credential leakage remained unchanged, or suspicious-message reporting deteriorated at the same time. Department averages can also conceal a small part of the organisation where exposure is concentrated.

Pistachio has a commercial interest in adaptive phishing simulations and training, so its conclusions should be read with that incentive in mind. The useful part of the dataset is narrower: employee security behaviour does not move along a single axis, and apparently positive movement in one metric can coexist with weaker performance elsewhere.

That makes the quality of the measurement as important as the percentage it produces. Clicks, credential leakage, reporting, difficulty, and organisational context describe different parts of the same risk, and compressing them into one number can create more certainty than the data supports.

×