Phishing Research Challenges Conventional Security Awareness Testing
Security researchers found that most phishing tests only measure if employees click fake links, not if they lose their real passwords. This means many companies still fail to spot real credential leaks.
- Report priority
- Medium
How it works
- Most phishing tests only check if employees click fake links in emails.
- They do not measure whether employees reuse passwords, share credentials, or fall for real credential-stealing attacks.
- This leaves organizations blind to actual password leaks and weak security habits.
What to do
If your company runs phishing tests to train employees, check if your current tests only measure clicks on fake links instead of real credential leaks or weak password habits. Most phishing tests do not cover these risks.
Update your phishing tests to include real credential-stealing scenarios and password reuse checks. Use tools that measure if employees reuse passwords or share login details. Consult your security vendor's latest guidance on modern phishing test methods.
Technical details
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.