Executive Overview
In an era defined by aggressive digital transformation, unprecedented cloud migration, and sophisticated artificial intelligence-driven cyberattacks, modern enterprise security architectures have never been more robust. Corporations and government entities alike continue to pour billions of dollars into advanced technological defenses. Firewalls have become smarter, Endpoint Detection and Response (EDR) agents operate with surgical precision, and identity governance platforms manage access controls dynamically. Yet, despite these multi-layered, state-of-the-art technological investments, enterprise security teams continue to face a persistent, highly volatile vulnerability that defies easy remediation: the human element.
According to the newly released 2025 Phishing Simulation Benchmark Report published by cybersecurity leader Fortra, the human vector remains the most exploited and least predictable component of the enterprise security perimeter. Analyzing a massive dataset comprising over 14 million simulated phishing recipients across more than 7,500 distinct campaigns, the report provides a sobering look at how employees respond to social engineering tactics. The findings reveal a landscape where cybercriminals continuously refine their methodologies, exploiting psychological vulnerabilities to bypass technological shields and gain direct access to enterprise environments.
The core thesis of Fortra’s report is unmistakable: traditional technological interventions—while entirely necessary—are fundamentally insufficient on their own. As threat actors pivot toward credential theft and identity-based compromises, organizations can no longer afford to treat employees merely as potential liabilities or weak links. Instead, modern defense strategies demand a paradigm shift. Enterprises must cultivate an integrated, proactive security culture that transforms everyday users from passive targets into an active, vigilant line of defense. This comprehensive report explores the metrics, underlying threat vectors, technological implications, and strategic imperatives necessary to survive the modern phishing ecosystem.
Detailed Chronology: The Evolution of Social Engineering and Phishing Operations
To fully understand the weight of Fortra’s 2025 findings, it is essential to trace the historical evolution of phishing and social engineering. What began decades ago as crude, easily identifiable mass-mailing campaigns—often characterized by glaring grammatical errors and improbable promises of wealth—has transformed into a highly industrialized, automated, and psychologically nuanced criminal enterprise.
From Mass Broadcasts to Precision Targeting
In the early days of email security, phishing was largely a numbers game. Attackers blasted generic messages to millions of addresses, hoping a tiny fraction of recipients would fall for the ruse. Security vendors countered these threats by developing signature-based email filters, spam blockers, and reputation lists that successfully relegated the vast majority of junk mail to quarantine folders.
As email gateways grew more intelligent, threat actors adapted. The advent of spear-phishing introduced personalized attacks tailored to specific individuals by leveraging publicly available information from social media, corporate websites, and professional networks. Attackers researched their targets, impersonating trusted executives, IT personnel, or vendor partners to increase the plausibility of their fraudulent requests.

The Rise of Identity-Centric Attacks
Over the past several years, the global shift toward remote work and cloud-based infrastructure fundamentally altered the corporate attack surface. As organizations migrated applications, databases, and collaboration tools to platforms like Microsoft 365 and Google Workspace, the traditional network perimeter dissolved. The corporate perimeter is no longer defined by physical office walls or internal network firewalls; it is defined by identity.
In this new paradigm, cybercriminals realized that breaking through a heavily fortified network perimeter is often unnecessary if they can simply log in through the front door. By deploying convincing phishing campaigns aimed at harvesting corporate credentials, attackers bypass complex network defenses entirely. A single compromised username and password can grant an unauthorized actor unfettered access to sensitive cloud environments, financial records, and proprietary intellectual property—all without triggering traditional malware alerts or behavioral exploits.
The Modern Phishing Ecosystem
Today, the phishing threat landscape is supported by a robust underground economy characterized by "Phishing-as-a-Service" (PaaS) platforms. These commercialized toolkits allow low-skill cybercriminals to launch sophisticated, multi-stage phishing campaigns complete with automated credential harvesting, bypass mechanisms for multifactor authentication (MFA), and real-time proxy servers.
As Fortra’s research aptly notes, "The modern phishing ecosystem is no longer defined by isolated scams, but by rapidly evolving criminal platforms that continuously adapt to defensive improvements." This continuous evolution ensures that social engineering remains one of the most cost-effective and successful attack vectors available to malicious actors, cementing the urgent need for empirical benchmark data to help security leaders gauge their organizational resilience.
Supporting Context & Metrics: Unpacking the 2025 Benchmark Data
Fortra’s 2025 Phishing Simulation Benchmark Report provides rare, data-driven visibility into real-world user behavior. By examining telemetry from over 14 million simulated phishing recipients and more than 7,500 individual campaigns, the research strips away speculation to reveal how average employees react when confronted with simulated malicious prompts in their day-to-day work environments.
Click Rates: The Allure of Deception
Among the most closely watched metrics in security awareness training is the click rate—the percentage of users who interact with a malicious link embedded within a phishing email. According to Fortra’s analysis, the aggregate click rate across all evaluated simulations stood at 5.42%.

While 5.42% may appear modest at first glance, its true risk magnitude becomes apparent when contextualized within enterprise scale. In an organization with 10,000 employees, a 5.42% click rate means that over 540 individuals are willing to interact with potentially dangerous content. In a large multinational enterprise with 100,000 workers, that number skyrockets to over 5,400 vulnerable touchpoints in a single campaign. Because threat actors only need a single successful interaction to breach a network, a low percentage can still translate into a catastrophic security incident.
Password Submission Rates: The Direct Path to Compromise
Interacting with a link is only the first step in a successful credential-harvesting attack. More critical is the password submission rate—the percentage of users who not only click the malicious link but proceed to enter their corporate credentials into a fake landing page designed to mimic a legitimate login portal.
Fortra’s report recorded a 1.99% password submission rate across the analyzed campaigns. This metric underscores a sobering reality: nearly one in fifty employees tested will willingly surrender their access credentials when presented with a sufficiently convincing pretext. In the hands of an automated adversary, harvested credentials can be leveraged instantly to initiate session hijacking, lateral movement, and data exfiltration before security operations centers (SOCs) have even detected the anomaly.
The Reporting Deficit: A Missed Opportunity for Defense
Perhaps one of the most revealing and concerning findings in the 2025 benchmark report centers on incident reporting. Detecting and blocking inbound threats is only half the battle; timely notification from employees who spot anomalies is essential for enterprise-wide threat mitigation.
Fortra found that only 10.5% of users reported simulated phishing emails. This means that nearly 90% of recipients who received a suspicious email chose to ignore it, delete it quietly, or—worse—interact with it, rather than alerting their security teams.
This stark reporting deficit highlights a critical operational blind spot. When employees fail to report suspicious communications, security teams lose invaluable early-warning indicators. An unreported phishing email circulating widely among staff members represents an active, uncontained threat. Without robust reporting mechanisms and a culture that encourages vigilance without fear of reprisal, organizations remain dangerously blind to ongoing social engineering campaigns targeting their workforce.

Official Statements and Industry Insights
The release of Fortra’s benchmark report has triggered widespread discussion across the cybersecurity community, prompting industry leaders, researchers, and security practitioners to re-evaluate how organizations approach human-centric defense strategies.
The Shift Toward Identity Security
Security analysts observing the report’s conclusions emphasize that identity has unequivocally become the new security perimeter. As enterprise workloads continue their migration to the cloud, traditional boundary defenses have lost their primacy.
"When applications and data reside in cloud environments, traditional network perimeters dissolve," noted enterprise risk management specialists responding to the report. "An attacker does not need to exploit a zero-day vulnerability in an operating system if they can simply phish an employee’s password and walk right through the front door using valid credentials."
This reality has accelerated adoption rates for advanced identity controls. Technologies such as phishing-resistant multifactor authentication (FIDO2-compliant security keys), strict conditional access policies, user behavior analytics (UBA), and continuous identity monitoring are now foundational components of modern security architectures. However, experts are quick to point out that these tools must be paired with cultural evolution.
Technology Alone Is Not Enough
A recurring theme throughout Fortra’s findings is the persistent limitation of technological silver bullets. While email filtering technologies have grown exceptionally sophisticated—leveraging artificial intelligence and machine learning to intercept malicious payloads before they ever reach an inbox—threat actors continually devise creative workarounds.
Attackers utilize zero-hour domains, obfuscated URLs, legitimate cloud storage services to host payloads, and conversational AI tools to craft flawless, grammatically pristine phishing lures that effortlessly slip past traditional email gateways.

"Technology can block millions of threats, but it cannot read human intent," security architects emphasize. "Multifactor authentication, conditional access, and automated filtering are indispensable, but they are defensive layers—not impenetrable walls. When a sophisticated attack inevitably breaches technological controls, the final barrier standing between the adversary and the corporate crown jewels is the employee sitting at the keyboard."
Redefining the Employee’s Role
To bridge this persistent gap, Fortra and broader industry thought leaders argue for a fundamental re-imagining of the employee’s role within the organization. Rather than viewing staff members as the weakest link in the security chain—a designation that fosters anxiety and disengagement—enterprises must embrace a philosophy where employees are treated as an integral part of the security perimeter.
This requires moving away from compliance-driven, check-the-box annual training videos toward dynamic, continuous, and empathetic security awareness programs. Employees must be empowered with the knowledge, tools, and psychological safety required to identify threats, question anomalies, and report suspicious activity without fear of punitive measures.
Future Outlook: Building a Resilient Security Culture
Looking toward the remainder of 2025 and beyond, the trajectory of social engineering attacks suggests that human-targeted threats will only increase in frequency and sophistication. The rapid democratization of generative artificial intelligence and large language models has lowered the barrier to entry for cybercriminals, enabling them to launch hyper-personalized, multi-language phishing campaigns at an unprecedented scale.
In light of these emerging trends, how can organizations operationalize the insights from Fortra’s 2025 Phishing Simulation Benchmark Report? Building a resilient security culture requires a deliberate, multi-faceted strategic roadmap.
1. Transition from Compliance to Continuous Engagement
Traditional security awareness training—often administered once a year as a mandatory, unengaging video tutorial—has proven largely ineffective against modern social engineering techniques. Organizations must transition toward continuous, bite-sized, and contextually relevant learning experiences. Regular, randomized phishing simulations should not be used as punitive "gotcha" tests to shame employees who fall for lures, but rather as diagnostic learning opportunities designed to reinforce safe behaviors in real time.

2. Streamline and Encourage Incident Reporting
The finding that only 10.5% of users reported simulated phishing emails indicates a massive opportunity for improvement. Organizations must make reporting suspicious communications as frictionless as possible. Implementing a prominent "Report Phish" button directly within email clients—paired with automated backend triage that acknowledges and thanks employees for their vigilance—can dramatically increase reporting rates. When employees see that their reports lead to tangible protective actions, their engagement and sense of ownership naturally increase.
3. Implement Phishing-Resistant Authentication
Given the persistent success of credential harvesting (evidenced by the 1.99% password submission rate), organizations must move beyond vulnerable authentication methods like standard SMS-based or push-notification MFA, which remain susceptible to adversary-in-the-middle (AitM) attacks. Migrating toward phishing-resistant authentication mechanisms—such as hardware security keys (FIDO2/WebAuthn) or certificate-based authentication—ensures that even if an employee is successfully phished and surrenders their password, the attacker cannot reuse harvested session tokens or credentials to access sensitive systems.
4. Foster a Just Culture of Psychological Safety
Perhaps the most critical component of a robust security culture is psychological safety. If employees fear disciplinary action, public embarrassment, or termination for accidentally clicking a malicious link or submitting credentials, they are far more likely to hide their mistake, delaying incident response and allowing attackers valuable time to move laterally within the network. Enterprises must cultivate a "just culture" where honest mistakes are treated as learning moments, and rapid reporting is universally celebrated as a vital contribution to corporate security.
Conclusion
Fortra’s 2025 Phishing Simulation Benchmark Report serves as both a diagnostic mirror and a strategic roadmap for the cybersecurity community. While the data demonstrates that human vulnerability remains a stubborn challenge—highlighted by a 5.42% click rate, a 1.99% credential submission rate, and a low 10.5% reporting rate—it also points the way forward.
As cybercriminals leverage increasingly sophisticated platforms to target enterprise identities, technology alone will never be enough to secure the modern organization. By moving beyond traditional compliance mindsets, investing in phishing-resistant authentication, streamlining reporting mechanisms, and actively building a security culture that empowers every employee as a defender, organizations can transform their greatest vulnerability into a formidable layer of resilience.
To review the complete data sets, methodology, and comprehensive analysis, the full 2025 Phishing Simulation Benchmark Report is available directly through the Fortra resource portal.
