1 in 10 Phishing E-mails Fool Users in Education Field

In a recent study, 10 percent of simulated phishing e-mails sent to users in education institutions were successful, triggering the recipient to click on a fraudulent link. That's according to the 2018 State of the Phish report from Wombat Security Technologies, in which researchers measured the average click rates on phishing tests across various industries. Education had an average click rate of 10 percent; the industries that performed worst in the tests were telecommunications and retail, with 15 percent and 14 percent average click rates, respectively. 

The study, which looked at user awareness and behavior around phishing and other data security issues, gathered data from several sources:

  • Analysis of tens of millions of simulated phishing attacks sent through Wombat's Security Education Platform between Oct. 1, 2016, and Sept. 30, 2017;
  • Survey responses from 10,000-plus information security professionals in more than 16 industries; and
  • A third-party survey of about 3,000 technology users in the United States, United Kingdom and Germany.

Other findings include:

  • Across all industries, 76 percent of organizations experienced phishing attacks in 2017;
  • Nearly half of information security professionals believe the rate of attacks has increased compared to 2016;
  • 76 percent of organizations now measure their susceptibility to phishing, up from 66 percent in 2016;
  • 95 percent of organizations train their end users on how to identify and avoid phishing attacks; and
  • 61 percent of users in the U.S. could correctly define what phishing is, while just 46 percent knew what ransomware is.

The report also pointed to one area where awareness is particularly low among U.S., U.K. and German adults: "smishing," or SMS/text message phishing. Just 16 percent of survey participants could correctly define smishing, while 67 percent couldn't even venture a guess.

"Smishing (SMS/text message phishing) has generally been considered a regional, consumer-based threat as opposed to a global cybersecurity concern," the report noted. "However, media coverage of successful smishing attacks rose during 2017 — a trend that's sure to increase in 2018 given that awareness of this threat vector is low."

The full report is available on the Wombat site (registration required).

About the Author

Rhea Kelly is editor in chief for Campus Technology, THE Journal, and Spaces4Learning. She can be reached at [email protected].

Featured

  • globe surrounded by network connections

    AI Adoption Is Surging, but Infrastructure and Language Gaps Persist

    Artificial intelligence may be spreading faster than previous waves of consumer tech, but a report from Microsoft's AI Economy Institute suggests its benefits are concentrating in a relatively small set of countries, with infrastructure and language emerging as major dividing lines.

  • workshop participants discuss sustainability in open science and research

    Open Source: Advancing Our Digital Commons

    IT leaders are recognizing the benefits of a return to open strategies. CT asked Jack Suess, VP of IT and CIO at UMBC, for his views on returning to the digital commons of open source.

  • college students sitting with laptops at an outdoor table

    How Colleges Are Building More Connected and Responsive Student Support

    Colleges are making steady progress in building more connected and responsive student support systems. By aligning services and improving coordination, institutions are enhancing both the student and staff experience.

  • abstract generative AI technology

    Apple and Google Strike AI Deal to Bring Gemini Models to Siri

    Apple and Google announced they have embarked on a multiyear partnership that will put Google's Gemini models and cloud technology at the core of the next generation of Apple Foundation Models, a move that could help Apple accelerate long-promised upgrades to Siri while handing Google a high-profile distribution win on the iPhone.