Phishing Research Challenges Conventional Security Awareness Testing
The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research.
Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations. Between 1 June, 2025 and 31 May, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees in more than 1,200 organizations. Its subsequent analysis looked at clicking, leaking, and reporting.
Thirty percent of tech development and IT employees clicked at least one of these phishing simulations. Nearly 20% of construction and real estate employees leaked credentials after a successful phishing attempt. Financial services were the most resilient, outperforming all other sectors in click, credential leaking and reporting rates.
While it is not surprising that financial services performed better, it is more surprising that tech and IT (who really should...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE