A new report found that even the most experienced technology users are falling for phishing attacks.
Pistachio, an AI-powered human-risk platform, recently released a report that analysed 2.47 million simulated phishing attacks sent over 12 months to 123,692 employees across more than 600 organisations.
One of the report’s primary findings was that roughly one in three employees in IT – 28.5% – and technology development – 30.3% – clicked on at least one simulated phishing attack.
Joe Jones, CEO and co-founder of Pistachio, told Inc. that the single biggest predictor of whether someone falls for a phishing simulation comes down to whether they’re paying attention.
“People would assume it’s whether you understand what to look for in an email,” he said. “But the actuality is, you could be an expert at spotting phishing emails, but if you’re not paying attention, or you’ve essentially forgotten to think about it, that’s when you’re most susceptible to falling victim.”
Given that these are some of the most technically skilled professionals in the industry, their susceptibility illustrates how rapidly AI has advanced the sophistication of these scams.
Across most sectors and departments, around one-third of employees who clicked on a simulated phishing scam also submitted their credentials.
Jones said the reason certain jobs get targeted so effectively comes down to relevance: Attackers exploit what someone expects to encounter in day-to-day work.
“If you understand, as a potential hacker, that somebody working in IT is very likely working with Microsoft, there’s an obvious relevant simulation to send,” Jones said. “The more of those things you can uncover, the more relevant you can make the simulation, the more likely it is to pay off.” He added: “There’s a pretty linear graph between the likelihood of you falling for a simulation and the relevance of that simulation to you.”
Beyond IT, construction and real estate emerged as the least resilient industries overall, with 46% of employees clicking on simulated phishing attempts and 19% submitting credentials. Financial services – like employees at banks, insurance companies, investment firms, and similar institutions – performed the best across the board. However, within the group, 25% of employees still fell for a simulated scam.
Jones reasoned that this is most likely due to differing levels in computer literacy. “A construction company is probably going to have the average person there less computer literate than a finance firm,” he said.
He added that financial firms tend to run “security awareness programs for longer than the average construction firm has” because the assets they are protecting – financial data – make the need for that training “a little bit more obvious” compared with other industries.
This gap in awareness matters now more than ever.
Jones said even the most experienced employees need to treat every new email as suspicious until proven otherwise. He said the old standard of watching for bad grammar or spelling mistakes is “almost redundant” in the age of AI. – Inc./Tribune News Service
