Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How to Negotiate Your Salary Before You Say Yes

    July 29, 2026

    Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books

    July 29, 2026

    The Download: a chip talent battle, and deflating AI hype

    July 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How to Negotiate Your Salary Before You Say Yes
    • Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books
    • The Download: a chip talent battle, and deflating AI hype
    • Global AI Digital Divide Shapes Who Builds AI
    • More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’
    • The AI Hype Index: Unsexy AI
    • OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
    • Why Scientists Redesigned the Botox Enzyme With AI
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»The best-funded companies open the most phishing attachments
    Cybersecurity

    The best-funded companies open the most phishing attachments

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 25, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one.

    That silence is the exposure. Across 13.9 million simulated phishing messages, one in ten recipients flagged the attempt to their security team. The rest let it through, and a live attacker needs only one of them.

    John Wilson, senior fellow for threat research at Fortra, has tracked phishing from its early days of copied login pages into a paid service industry. Phishing-as-a-Service platforms sell templates, hosting, and kits that defeat multi-factor authentication for pocket change. The skill required to run a campaign has fallen to a few clicks.

    Wilson counts people as one flawed control among several. “The human layer is already an inadequate control surface, as are technical controls,” he told Help Net Security. “Both can be circumvented by a determined attacker.” His prescription is to keep technology controls updated and users tested on a regular schedule, so both operate at peak performance.

    That reporting rate looks reassuring, and it tells you less than you think

    The benchmark treats reporting rate as the vital sign of a security program. The reasoning is simple. A single report can kill a campaign mid-flight, and nine in ten simulated attempts produced no report.

    The sector data muddies that picture. Financial banks reported phishing at 30.98 percent, the top reporting mark in the study, with a form-completion rate near the bottom.

    Defense employees reported at close to a quarter, then clicked simulated links at 13.02 percent. Strong reporting and heavy clicking live in the same workforce.

    Wilson lands on one metric above the others. “Although form completion represents the worst outcome for traditional credential phishing, an organization can be compromised by malware through a single click, without the user ever submitting their login credentials,” he said. “For this reason, I believe clickrate is the most important metric when evaluating training effectiveness.”

    Wilson weighs each priority in turn. “Prioritizing form entry could lead to a malware infection brought on by a single click, while prioritizing reporting could lead to excessive false positives, overburdening the SOC,” Wilson said. “This has the potential of a critical incident not receiving adequate attention or urgency.”

    Chasing the latest lure is a losing game

    New phishing techniques ship constantly. Wilson runs threat research at Fortra. His read on what stays fixed:

    “While there have been numerous technical innovations in phishing, such as Device Code phishing, Hybrid Vishing, Phishing-as-a-Service, Service Abuse, and OAuth client ID spoofing, the underlying social engineering techniques of urgency, authority, fear, greed, etc. haven’t changed,” he said. “Phishing simulation training needs to focus on these core social engineering techniques, rather than any specific phishing lures, which will no doubt continue to adapt and evolve over time.”

    Training built on this week’s template ages by next week. Training built on urgency and authority holds.

    Who falls for it depends on where they sit

    The same phishing email lands differently depending on who opens it. Language draws one line. French-language recipients in France reported at 19.55 percent, roughly double the English-language cohort.

    Industry draws another. Insurance employees opened malicious attachments at 12.65 percent, a rate that towers over every other sector in the study. One habit can define an entire workforce.

    Company size draws a third, and this line runs on money. Small and medium businesses clicked more, submitted more passwords, and reported the least. Their training budgets sit in the low six figures. The largest firms spend into eight figures.

    What defenders do with this

    The employee who typed her password into a fake login page never told her security team. Around 250,000 people did the same across these simulations. That gap is what every phishing kit on the market is built to widen.

    attachments bestfunded Companies open Phishing
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • How to Negotiate Your Salary Before You Say Yes
    • Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books
    • The Download: a chip talent battle, and deflating AI hype
    • Global AI Digital Divide Shapes Who Builds AI
    • More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’

    How to Negotiate Your Salary Before You Say Yes

    July 29, 2026

    Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books

    July 29, 2026

    The Download: a chip talent battle, and deflating AI hype

    July 29, 2026

    Global AI Digital Divide Shapes Who Builds AI

    July 29, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.