Executive Overview
In the relentless battleground of modern cybersecurity, enterprises have poured billions of dollars into fortifying their digital perimeters. Advanced email protection gateways, sophisticated endpoint detection and response (EDR) agents, and granular identity and access management (IAM) controls now form the bedrock of corporate defense architectures. Yet, despite these monumental investments in software and hardware, a glaring vulnerability persists at the heart of nearly every organization: the human user.
According to the newly released 2025 Phishing Simulation Benchmark Report published by cybersecurity heavyweight Fortra, employees remain the most challenging and unpredictable variable in the enterprise security equation. Analyzing an impressive dataset comprising 14 million simulated phishing recipients across more than 7,500 distinct campaigns, the report paints a vivid picture of how modern cybercriminals continue to exploit the human psyche.
The findings are both sobering and instructive. Across the millions of simulated attacks analyzed, Fortra’s researchers documented an average click rate of 5.42% and, more alarmingly, a 1.99% password submission rate. These figures demonstrate conclusively that highly convincing, targeted phishing lures can still effortlessly bypass human skepticism and trick employees into interacting with malicious content. Furthermore, the report revealed a critical deficit in proactive defense behaviors: only 10.5% of users actively reported the simulated phishing emails to their security teams.
This comprehensive overview explores the core findings of Fortra’s benchmark study, dissects the evolving mechanics of modern phishing ecosystems, examines the shift toward identity-centric attacks, and underscores the urgent, non-negotiable need for organizations to transition from treating employees as liabilities to cultivating an active, engaged security culture.
Detailed Chronology: The Evolution of Phishing and the Metrics That Matter
To understand the gravity of the statistics presented in the 2025 report, it is essential to trace how phishing has evolved from a blunt, indiscriminate nuisance into a surgical, highly sophisticated enterprise.

From Mass Spam to Targeted Deception
In the early days of the commercial internet, phishing attacks were largely characterized by poorly translated mass-mailing campaigns—often promising windfalls from foreign dignitaries or alerting users to fabricated banking anomalies. These campaigns relied on volume rather than precision, and while they caught out the unwary, they were relatively easy for both basic email filters and savvy users to spot.
Over the subsequent two decades, however, the underground cybercrime economy industrialized. Cybercriminals began leveraging open-source intelligence (OSINT), corporate social media profiles, and data leaks to craft hyper-personalized spear-phishing campaigns. By impersonating trusted executives, IT support desks, or third-party SaaS vendors, attackers could bypass the initial cognitive friction that typically accompanies unsolicited communications.
The Anatomy of the 2025 Dataset
Fortra’s latest research captures the contemporary state of this evolutionary trajectory. By evaluating 14 million simulated phishing recipients across over 7,500 campaigns, the researchers captured a statistically robust cross-section of global organizational behavior.
The mechanics of the study were straightforward yet revealing: organizations deployed controlled, simulated phishing campaigns to test employee resilience. The resulting data points—specifically click rates, credential submission rates, and reporting rates—offer a clinical diagnosis of corporate susceptibility.
- The 5.42% Click Rate: While a single-digit click rate might superficially appear low, scaled across a multinational enterprise with tens of thousands of employees, it represents hundreds of potential compromise points from a single campaign.
- The 1.99% Password Submission Rate: This metric cuts straight to the core of enterprise risk. When nearly 2% of recipients are willing to hand over their corporate credentials on a spoofed landing page, attackers are provided with an immediate, authenticated pathway into the target network.
- The 10.5% Reporting Rate: Perhaps the most concerning metric in the report, this low reporting threshold highlights a profound visibility gap. When nearly 90% of employees choose to simply ignore a suspicious email rather than report it to the security operations center (SOC), security teams are left blind to ongoing reconnaissance and initial-access attempts.
Supporting Context & Metrics: The Pivot to Identity Security
The implications of Fortra’s findings extend far beyond individual user error; they directly inform the architectural shifts currently taking place in enterprise cybersecurity. For years, the traditional security model relied on a "castle-and-moat" philosophy, where perimeter defenses kept threats out, and once inside the network, users were largely trusted.

The mass migration to cloud environments, remote workforces, and decentralized SaaS applications has thoroughly dismantled that model. Today, the corporate perimeter is no longer defined by physical routers and firewalls—it is defined by identity.
Why Identity Has Become the Primary Attack Vector
As endpoint and email security controls have grown increasingly adept at identifying and blocking malicious payloads, malware, and traditional exploits, cybercriminals have shifted their tactics. Why spend days attempting to crack a zero-day vulnerability or bypass complex EDR agents when you can simply log in using legitimate credentials?
Stolen credentials allow attackers to operate living off the land—using native administrative tools and legitimate user accounts to move laterally through an environment without ever triggering malware alarms. This shift places immense pressure on identity security controls.
The Limits of Technological Silos
Modern enterprises have deployed an array of technological countermeasures to combat credential theft:
- Multifactor Authentication (MFA): Widely regarded as a baseline necessity, standard MFA has significantly raised the bar for attackers. However, sophisticated threat actors have adapted by employing MFA fatigue attacks, session-hijacking proxy tools, and Adversary-in-the-Middle (AiTM) phishing kits that capture both credentials and session tokens in real-time.
- Conditional Access Policies: These policies restrict access based on device health, location, and behavior, adding friction to anomalous login attempts.
- Identity Threat Detection and Response (ITDR): Emerging technologies designed to monitor credential usage anomalies and alert security teams to compromised accounts.
Despite the efficacy of these tools, Fortra’s research serves as a stark reminder that technology alone is fundamentally insufficient. Even the most robust conditional access policy or MFA deployment can be undermined if a user willingly grants access or approves an out-of-band prompt due to social engineering.

Official Statements and Industry Insights
The release of the 2025 Phishing Simulation Benchmark Report has sparked widespread discussion across the cybersecurity community regarding the intersection of human behavior and automated defense systems.
Commenting on the structural shifts within the threat landscape, Fortra’s research team highlighted the industrialization of social engineering:
"The modern phishing ecosystem is no longer defined by isolated scams, but by rapidly evolving criminal platforms that continuously adapt to defensive improvements."
This observation underscores a harsh reality for CISOs and security leaders: cybercrime is a business. Phishing-as-a-Service (PaaS) platforms now offer turnkey infrastructure, automated lure generation, and real-time credential harvesting kits to lower-tier threat actors. These platforms iterate and test new evasion techniques continuously, ensuring that static, periodic security awareness training programs are quickly rendered obsolete.
Furthermore, industry analysts have pointed to the report’s 10.5% reporting rate as a critical call to action. Security awareness initiatives have historically focused heavily on the negative—teaching employees what not to click. However, experts argue that organizations must pivot toward positive reinforcement and frictionless reporting mechanisms. If an employee perceives the process of reporting a suspicious email as cumbersome or bureaucratic, they will choose the path of least resistance: deletion and inaction.

Future Outlook: Building a True Security Culture
As organizations look toward the remainder of the decade, the insights provided by Fortra’s 2025 benchmark report point toward a definitive conclusion: technology can patch software vulnerabilities, but only a robust security culture can patch human vulnerability.
Moving Beyond Compliance-Driven Training
Historically, many enterprises treated security awareness training as an annual, compliance-driven check-the-box exercise. Employees were subjected to dry, unengaging slide decks or generic videos once a year, followed by a perfunctory quiz. Unsurprisingly, this methodology has proven largely ineffective against adaptive, psychological social engineering tactics.
Future-proof organizations are transforming their approach by implementing:
- Continuous, Adaptive Simulation: Moving away from static, quarterly campaigns in favor of continuous, data-driven simulations tailored to specific departmental risks and emerging threat trends.
- Contextual, Just-in-Time Education: Providing immediate, non-punitive feedback the moment a user interacts with a simulated phishing lure, turning a mistake into a teachable moment rather than an HR infraction.
- Empowerment and Psychological Safety: Cultivating an environment where employees feel empowered to report suspicious activities without fear of retribution. Recognizing and rewarding high-reporting behavior encourages the entire workforce to act as active sensors within the threat detection apparatus.
The Employee as the Final Layer of Defense
Ultimately, Fortra’s findings challenge organizations to redefine the structural role of their workforce. Employees must no longer be viewed merely as the weakest link in the security chain—the perennial potential victims waiting to be compromised. Instead, they must be intentionally integrated into the enterprise security perimeter as the human firewall.
By combining advanced technological controls—such as robust identity governance, behavioral monitoring, and email filtering—with an engaged, vigilant, and well-trained workforce, organizations can close the visibility gaps exposed by the 2025 benchmark report. In an era where cyber adversaries continually refine their methods to exploit human trust, building a resilient security culture is no longer an optional HR initiative; it is an indispensable pillar of enterprise survival.
