AUTO-UPDATED

The best-funded companies open the most phishing attachments

A new study by Fortra analyzing 13.9 million simulated phishing messages reveals that employees at well-funded companies are significantly more likely to open malicious attachments than other organizations.

Key Points

  • Researchers analyzed 13.9 million simulated phishing emails to evaluate employee reporting and click-through rates.
  • Only 10% of recipients reported phishing attempts, leaving the vast majority of simulated attacks undetected by security teams.
  • Insurance industry employees opened malicious attachments at a rate of 12.65%, the highest among all sectors studied.
  • Phishing-as-a-Service platforms have lowered the barrier to entry for attackers, allowing them to bypass multi-factor authentication easily.
  • Fortra senior fellow John Wilson identifies click-through rate as the most critical metric for measuring the effectiveness of security training.
  • Social engineering tactics like urgency and authority remain more effective than specific technical lures, which evolve rapidly.

Why it Matters

The findings highlight that traditional security training often fails to address the human element, leaving organizations vulnerable to sophisticated, low-cost phishing campaigns. By focusing on click-through rates rather than just reporting, companies can better identify gaps in their defense and mitigate the risk of malware infections.
Help Net Security Published by Mirko Zorz
Read original