Pistachio, established in Oslo in 2019 with offices in London and Valencia, has made significant strides in phishing simulations and security awareness. Their recent study, spanning from June 2025 to May 2026, involved 2.47 million simulated phishing emails sent to over 123,000 employees across 1,200 organizations. The study meticulously analyzed employee behaviors, focusing on click rates, credential leaks, and report rates.
Sector-Specific Vulnerabilities
Interestingly, the study highlighted that 30% of tech and IT staff clicked on phishing simulations, a surprising outcome given their expertise. Meanwhile, nearly 20% of construction and real estate employees compromised credentials after phishing attempts. Financial sectors demonstrated the highest resilience, outperforming others in resisting phishing attacks.
The report emphasized that phishing vulnerabilities do not follow a single risk profile, with click rates varying significantly. For instance, 26% of design sector employees clicked on phishing attempts, compared to 41% in construction, showcasing diverse sectoral challenges.
AI-Driven Phishing Simulations
Pistachio leveraged their AI-driven platform to conduct simulations via email and Teams, tailoring content to each employee’s role and previous responses. This approach underscores the efficiency of AI, achieving in one year what would take decades manually.
The findings advocate for a deeper analysis beyond click rates, focusing on user responses post-click. Credential submission poses a significant risk, and misleading results from in-house tests may give organizations a false sense of security.
Behavioral Insights and Improvements
The study found that more employees reported phishing attempts than clicked them initially, yet 1.57% still leaked credentials. This implies that even with 500 employees, a company could see multiple individuals compromising their credentials.
Phishing resilience, as Pistachio concluded, results from minimized clicks and leaks, paired with increased reporting. By the program’s end, reporting rates nearly doubled compared to clicks, illustrating the effectiveness of sustained training. However, the study lacked geographic analysis, missing potential insights into regional vulnerabilities.
Overall, the insights from Pistachio’s research are invaluable for any organization planning phishing simulations, providing a blueprint for resilient security training strategies.
