← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Pistachio Research Challenges Conventional Phishing Simulation Metrics

🔄 Updated 21h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Pistachio conducted 2.47 million simulated phishing attempts.
  • Click rate alone is an insufficient metric for phishing risk.
  • Credential leakage and reporting rates are also critical indicators.
  • Simulations should be tailored to employee roles and past behavior.

Pistachio's Phishing Simulation Study

Pistachio, an Oslo-based company specializing in human risk management and security awareness, conducted a large-scale phishing simulation study. Between June 1, 2025, and May 31, 2026, the company sent 2.47 million simulated phishing attempts to over 123,000 employees across more than 1,200 organizations. The analysis focused on employee clicking, credential leaking, and reporting behaviors.

Varying Sector Performance

The research revealed significant differences in phishing susceptibility across sectors. Thirty percent of tech development and IT employees clicked at least one simulation, while nearly 20% of construction and real estate employees leaked credentials. Financial services demonstrated the highest resilience, outperforming other sectors in all three metrics: click, credential leakage, and reporting rates. The proportion of employees who clicked at least once ranged from 26% in Design to 41% in Construction.

Limitations of Click Rate as a Metric

The study challenges the conventional reliance on click rate as the primary metric for evaluating phishing program effectiveness. Pistachio's findings suggest that a click without subsequent credential submission or information leakage does not pose a significant risk. The report emphasizes that true phishing risk is created when credentials or other requested information are submitted.

Recommendations for Improved Testing

Pistachio recommends that organizations fine-tune future in-house phishing simulation tests by looking beyond just user clicks to include user response, specifically credential leakage and reporting. The report states that a strong indicator of improvement needs to go beyond click rate and should analyze how click, leak, and report behaviors change together over time. Pistachio's simulations were delivered via an AI-driven platform, tailoring content and difficulty based on the recipient's role and previous responses.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Sep 12

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Pistachio's research, based on 2.47 million simulated phishing attempts, indicates that click rate alone is an insufficient metric for assessing phishing risk. The study highlights the importance of also tracking credential leakage and reporting rates, as well as tailoring simulations to employee roles and past responses.