1 in 10 Phishing E-mails Fool Users in Education Field

In a recent study, 10 percent of simulated phishing e-mails sent to users in education institutions were successful, triggering the recipient to click on a fraudulent link. That's according to the 2018 State of the Phish report from Wombat Security Technologies, in which researchers measured the average click rates on phishing tests across various industries. Education had an average click rate of 10 percent; the industries that performed worst in the tests were telecommunications and retail, with 15 percent and 14 percent average click rates, respectively. 

The study, which looked at user awareness and behavior around phishing and other data security issues, gathered data from several sources:

  • Analysis of tens of millions of simulated phishing attacks sent through Wombat's Security Education Platform between Oct. 1, 2016, and Sept. 30, 2017;
  • Survey responses from 10,000-plus information security professionals in more than 16 industries; and
  • A third-party survey of about 3,000 technology users in the United States, United Kingdom and Germany.

Other findings include:

  • Across all industries, 76 percent of organizations experienced phishing attacks in 2017;
  • Nearly half of information security professionals believe the rate of attacks has increased compared to 2016;
  • 76 percent of organizations now measure their susceptibility to phishing, up from 66 percent in 2016;
  • 95 percent of organizations train their end users on how to identify and avoid phishing attacks; and
  • 61 percent of users in the U.S. could correctly define what phishing is, while just 46 percent knew what ransomware is.

The report also pointed to one area where awareness is particularly low among U.S., U.K. and German adults: "smishing," or SMS/text message phishing. Just 16 percent of survey participants could correctly define smishing, while 67 percent couldn't even venture a guess.

"Smishing (SMS/text message phishing) has generally been considered a regional, consumer-based threat as opposed to a global cybersecurity concern," the report noted. "However, media coverage of successful smishing attacks rose during 2017 — a trend that's sure to increase in 2018 given that awareness of this threat vector is low."

The full report is available on the Wombat site (registration required).

About the Author

Rhea Kelly is editor in chief for Campus Technology, THE Journal, and Spaces4Learning. She can be reached at [email protected].

Featured

  • A panel discussion from SXSW EDU 2025

    12 Ways to Dive into AI at SXSW EDU

    This March 9-12, the SXSW EDU Conference & Festival returns to Austin, TX, to celebrate innovation, experimentation, and learning across every stage of education.

  • abstract cybersecurity data protection

    Rubrik Intros Google Workspace Data Protection

    Rubrik has announced the launch of Rubrik Data Protection for Google Workspace, a product the company said is designed to help enterprise customers protect data and restore operations across Google Workspace environments.

  • Educational path and career development growth with neon icons for study, idea, graduation, and success

    How to Embrace Lifelong Learning as a Non-negotiable for Career Growth

    In a world shaped by rapid technological change and shifting economic forces, staying curious and committed to learning is the most powerful way to stay prepared.

  • SXSW EDU

    SXSW EDU 2026: Discover How to Incorporate Technology with Impact

    With the proliferation of AI and advanced technology, education leaders have an opportunity to find and implement the right solutions to make a difference for learners. This March 9-12, SXSW EDU 2026 is your chance to discover innovative edtech, connect with trailblazing peers, and find strategies that make an impact.