Phishing Research Challenges Conventional Security Awareness Testing
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.
The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research.
Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations. Between 1 June, 2025 and 31 May, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees in more than 1,200 organizations. Its subsequent analysis looked at clicking, leaking, and reporting.
Thirty percent of tech development and IT employees clicked at least one of these phishing simulations. Nearly 20% of construction and real estate employees leaked credentials after a successful phishing attempt. Financial services were the most resilient, outperforming all other sectors in click, credential leaking and reporting rates.
Source: https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/
Related breach coverage
- Comp AI Raises $34 Million for AI-Native Compliance and Security2026-09-17
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.
- Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta2026-09-08
The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.
- Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says2026-08-28
New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks. The post Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says appeared first on SecurityWeek.
- Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows2026-09-17
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.