Phishing Report Emphasizes Importance of Building a Security Culture

While cybersecurity teams have invested heavily in e-mail protection, endpoint security, and identity controls, new research from Fortra suggests one challenge remains difficult to solve: users.

The company's 2025 Phishing Simulation Benchmark Report analyzed 14 million simulated phishing recipients across more than 7,500 campaigns to examine employees' responses to phishing attempts.

The findings highlight a persistent challenge for security teams: Attackers continue to target people because compromised accounts can provide direct access to enterprise environments.

Across the simulations analyzed, Fortra found a 5.42% click rate and a 1.99% password submission rate, showing that convincing phishing attempts can still persuade users to interact with malicious content.

The report also found that phishing reporting remains a challenge. Only 10.5% of users reported simulated phishing e-mails, meaning many potential threats could go unnoticed without additional security controls.

The findings reinforce why identity security has become central to modern defense strategies.

As organizations move more applications and data into cloud environments, stolen credentials can provide attackers with a path into sensitive systems without requiring malware or traditional exploits.

Multifactor authentication, conditional access policies, user training and identity monitoring can all help reduce risk, but Fortra's research suggests technology alone is not enough.

The report argues that phishing defense requires organizations to treat employees as part of the security perimeter — not simply as potential victims.

"The modern phishing ecosystem is no longer defined by isolated scams, but by rapidly evolving criminal platforms that continuously adapt to defensive improvements," Fortra said.

The challenge is clear: Blocking phishing attacks requires more than stronger e-mail filters. It requires building a security culture where users recognize threats, report suspicious activity and become another layer of defense.

The full report is available here on the Fortra site.

Featured

  • Blurred silhouettes of business people in a modern office with a glowing blue network overlay

    Open Secure AI Alliance Moves to Linux Foundation

    The Open Secure AI Alliance has moved under the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices. The Alliance was launched by NVIDIA in July to develop open security technologies for AI systems and agents.

  • Digital Screen with young woman using a virtual reality headset

    Montclair State U Partners with Dreamscape Learn on New VR Facility

    New Jersey's Montclair State University has announced the completion of a new virtual reality learning facility developed in partnership with Dreamscape Learn. The 2,450-square-foot lab space is inside the College of Communication and Media building and will serve students pursuing careers in digital media, virtual reality, and content creation.

  • closeup of hands using smart phone

    Learning Continuity Built into the LMS Withstands Cloud or Cybersecurity Interruptions

    When your institution's administrative or instructional capabilities face disruption from natural, technical, or malicious events, what measures does your LMS offer to provide a "business as usual" operating and learning environment? Instructure's Ryan Lufkin comments on the LMS and learning continuity.

  • artificial intelligence on laptop

    OpenAI to Combine AI Products into Desktop 'Superapp'

    OpenAI is reportedly developing a desktop application that would combine several of its emerging AI products into a single platform, according to reports, marking the latest step in the company's effort to transform ChatGPT from a standalone chatbot into a broader productivity and automation environment.