A new study by Fortra analyzing 13.9 million simulated phishing messages reveals that employees at well-funded companies are significantly more likely to open malicious attachments than other organizations.
Key Points
- Researchers analyzed 13.9 million simulated phishing emails to evaluate employee reporting and click-through rates.
- Only 10% of recipients reported phishing attempts, leaving the vast majority of simulated attacks undetected by security teams.
- Insurance industry employees opened malicious attachments at a rate of 12.65%, the highest among all sectors studied.
- Phishing-as-a-Service platforms have lowered the barrier to entry for attackers, allowing them to bypass multi-factor authentication easily.
- Fortra senior fellow John Wilson identifies click-through rate as the most critical metric for measuring the effectiveness of security training.
- Social engineering tactics like urgency and authority remain more effective than specific technical lures, which evolve rapidly.