Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing Study Reveals New Insights on Security Testing

Phishing Study Reveals New Insights on Security Testing

Posted on September 11, 2026 By CWS

Pistachio, established in Oslo in 2019 with offices in London and Valencia, has made significant strides in phishing simulations and security awareness. Their recent study, spanning from June 2025 to May 2026, involved 2.47 million simulated phishing emails sent to over 123,000 employees across 1,200 organizations. The study meticulously analyzed employee behaviors, focusing on click rates, credential leaks, and report rates.

Sector-Specific Vulnerabilities

Interestingly, the study highlighted that 30% of tech and IT staff clicked on phishing simulations, a surprising outcome given their expertise. Meanwhile, nearly 20% of construction and real estate employees compromised credentials after phishing attempts. Financial sectors demonstrated the highest resilience, outperforming others in resisting phishing attacks.

The report emphasized that phishing vulnerabilities do not follow a single risk profile, with click rates varying significantly. For instance, 26% of design sector employees clicked on phishing attempts, compared to 41% in construction, showcasing diverse sectoral challenges.

AI-Driven Phishing Simulations

Pistachio leveraged their AI-driven platform to conduct simulations via email and Teams, tailoring content to each employee’s role and previous responses. This approach underscores the efficiency of AI, achieving in one year what would take decades manually.

The findings advocate for a deeper analysis beyond click rates, focusing on user responses post-click. Credential submission poses a significant risk, and misleading results from in-house tests may give organizations a false sense of security.

Behavioral Insights and Improvements

The study found that more employees reported phishing attempts than clicked them initially, yet 1.57% still leaked credentials. This implies that even with 500 employees, a company could see multiple individuals compromising their credentials.

Phishing resilience, as Pistachio concluded, results from minimized clicks and leaks, paired with increased reporting. By the program’s end, reporting rates nearly doubled compared to clicks, illustrating the effectiveness of sustained training. However, the study lacked geographic analysis, missing potential insights into regional vulnerabilities.

Overall, the insights from Pistachio’s research are invaluable for any organization planning phishing simulations, providing a blueprint for resilient security training strategies.

Security Week News Tags:AI training, click rate, credential leaking, employee training, IT security, multi-national analysis, Phishing, Pistachio, Resilience, security awareness

Post navigation

Previous Post: Critical GitLab Vulnerability Under Active Exploitation
Next Post: Hackers Exploit CEO Identity in Major Email Scam

Related Posts

SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM Security Week News
Phishing Study Reveals New Insights on Security Testing Diverging Reports Address Cybersecurity Challenges Security Week News
Veeam to Acquire Data Security Firm Securiti AI for .7 Billion Veeam to Acquire Data Security Firm Securiti AI for $1.7 Billion Security Week News
BreachForums Owner Sent to Prison in Resentencing  BreachForums Owner Sent to Prison in Resentencing  Security Week News
Keycard Emerges From Stealth Mode With  Million in Funding Keycard Emerges From Stealth Mode With $38 Million in Funding Security Week News
Windows Bind Link Exploits Bypass EDR Detection Windows Bind Link Exploits Bypass EDR Detection Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing
  • Critical GitLab Vulnerability Under Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing
  • Critical GitLab Vulnerability Under Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark