Executive Overview
In the modern theater of enterprise cybersecurity, organizations have poured unprecedented financial and operational capital into hardening their digital perimeters. Advanced email security gateways, endpoint detection and response (EDR) platforms, zero-trust architectures, and granular identity controls now form the bedrock of corporate defense strategies. Yet, despite these multi-layered technological investments, the most vulnerable link in the corporate security chain remains remarkably unchanged: the human user.
This sobering reality is thrust back into the spotlight by the release of the 2025 Phishing Simulation Benchmark Report, published by cybersecurity leader Fortra. Analyzing a massive dataset comprising over 14 million simulated phishing recipients across more than 7,500 distinct campaigns, the report paints a clear, unvarnished picture of how employees respond to social engineering tactics. The findings reveal that while technological defenses have evolved exponentially, cybercriminals have successfully scaled and refined their operational models, continuously exploiting the human element to bypass traditional defenses.
The report’s core metrics—a 5.42% click rate and a 1.99% credential submission rate—underscore a persistent and dangerous vulnerability. Even more concerning is the finding that only 10.5% of targeted employees actively reported simulated phishing emails. These statistics reinforce a paradigm shift that security leaders have long debated: identity security is now the ultimate battleground, and compromised credentials serve as master keys to corporate networks.
As enterprises accelerate their migration toward cloud-centric ecosystems, the necessity of moving beyond reactive filtering becomes absolute. Fortra’s comprehensive analysis argues that securing the enterprise no longer relies solely on technological blockades. Instead, organizations must cultivate an active, resilient security culture that treats employees not as liabilities waiting to fail, but as an empowered, frontline layer of defense.
Detailed Chronology: The Evolution of the Phishing Ecosystem and the 2025 Benchmark
To fully grasp the gravity of Fortra’s latest findings, it is essential to trace the historical evolution of social engineering and the modern threat landscape. Phishing has long ceased to be the domain of the amateur hacker sending poorly translated, obvious scams. Over the past decade, the phishing ecosystem has matured into a sophisticated, industrialized criminal enterprise characterized by automated delivery platforms, artificial intelligence-driven content generation, and rapid adaptation strategies.

From Mass Blasts to Precision Targeting
In the early days of cyberspace, phishing attacks were largely indiscriminate. Attackers cast wide nets using generic email templates, relying on sheer volume to snare unsuspecting victims. Security teams responded by developing keyword filters, reputation-based email blocklists, and signature-based antivirus solutions, which successfully marginalized these rudimentary attempts.
However, cybercriminals quickly pivoted. Recognizing that traditional spam filters could easily intercept automated, untargeted emails, threat actors began investing in reconnaissance. Spear-phishing and Business Email Compromise (BEC) emerged as preferred tactics, leveraging open-source intelligence (OSINT) and compromised social media profiles to craft hyper-personalized lures.
By the early 2020s, the commoditization of cybercrime via Phishing-as-a-Service (PaaS) platforms democratized access to advanced attack infrastructure. Ransomware gangs and state-sponsored groups alike began incorporating automated phishing kits capable of bypassing standard Multifactor Authentication (MFA) protocols through Adversary-in-the-Middle (AiTM) frameworks.
The 2025 Benchmark: Methodology and Scale
It is against this backdrop of escalating sophistication that Fortra conducted its comprehensive research for the 2025 Phishing Simulation Benchmark Report. By analyzing data derived from over 14 million simulated phishing recipients spread across more than 7,500 independent corporate campaigns, Fortra captured a statistically significant cross-section of global workforce behavior.
The methodology behind the benchmark was designed to measure real-world employee susceptibility under controlled, anonymized conditions. Rather than evaluating isolated incidents, the report aggregated broad behavioral trends to answer a fundamental question: How well do modern employees recognize and respond to deceptive communications designed to mimic contemporary business workflows?

The insights yielded by this massive dataset provide a vital baseline for security leaders. By mapping employee interactions against evolving threat vectors, the report illustrates the exact friction points where technological defenses fail and human intervention becomes necessary. The historical trajectory of phishing proves that threat actors will always seek the path of least resistance—and as long as human psychology remains exploitable, the human vector will remain a primary target.
Supporting Context & Metrics: Unpacking the Numbers Behind the Data
The quantitative findings of the Fortra report offer an uncompromising look at human behavior within the corporate environment. While percentage rates may appear deceptively small at first glance, scaling them across enterprise-wide headcounts reveals a staggering exposure surface.
Analyzing the Core Metrics
- 5.42% Click Rate: Across the millions of simulated emails analyzed, more than 5 out of every 100 recipients interacted directly with malicious or suspicious links. In an enterprise organization with 50,000 employees, a 5.42% click rate translates to over 2,700 individuals willingly engaging with a potential threat vector in a single campaign.
- 1.99% Password Submission Rate: Even more alarming than the click rate is the credential surrender rate. Nearly 2% of all targeted users went a step further, entering their corporate credentials into fraudulent landing pages. In an era where a single set of compromised credentials can grant unfettered access to cloud storage, internal networks, and sensitive databases, a 1.99% compromise rate represents an existential risk.
- 10.5% Reporting Rate: Perhaps the most telling metric regarding corporate security culture is the low rate of proactive reporting. Only 10.5% of users took the initiative to report the simulated phishing attempts to their security operations centers (SOC). This means that nearly 90% of targeted employees either ignored the threat or fell victim to it, leaving security teams largely blind to active social engineering campaigns operating within their environments.
+-------------------------------------------------------------+
| FORTRA 2025 BENCHMARK KEY METRICS |
+------------------------------+------------------------------+
| Metric | Observed Rate |
+------------------------------+------------------------------+
| Simulated Phishing Recipients| 14 Million+ |
| Analyzed Campaigns | 7,500+ |
| Click Rate | 5.42% |
| Password Submission Rate | 1.99% |
| Phishing Reporting Rate | 10.50% |
+------------------------------+------------------------------+
The Cloud Migration and the Identity Perimeter
To understand why these metrics carry such high stakes, one must examine the shifting architectural landscape of modern enterprises. For decades, the corporate network was defined by a hard perimeter protected by firewalls, virtual private networks (VPNs), and internal access controls.
Today, digital transformation has dismantled that perimeter. Organizations have migrated vast troves of sensitive data and mission-critical applications to multi-cloud environments (AWS, Microsoft Azure, Google Cloud Platform) and Software-as-a-Service (SaaS) platforms like Microsoft 365 and Salesforce.
In this decentralized ecosystem, the traditional network perimeter has been replaced by the identity perimeter. Employees no longer need to be physically inside a corporate office or logged into a secure VPN to access enterprise resources; they authenticate their identity from remote locations using diverse devices. Consequently, threat actors have shifted their focus away from traditional malware exploits and software vulnerabilities, which are increasingly blocked by modern endpoint detection tools. Instead, they target the credentials that govern access to these cloud environments.

When an attacker successfully acquires a user’s credentials through a targeted phishing campaign, they do not need to hack their way through firewalls or deploy complex exploits. They simply log in using legitimate credentials, effectively impersonating an authorized user. This makes identity security controls—such as robust Multifactor Authentication (MFA), conditional access policies, and continuous behavior monitoring—absolute prerequisites for modern defense. However, as Fortra’s research emphasizes, technology alone cannot completely mitigate the risk.
Official Statements and Industry Analysis
The implications of the 2025 benchmark extend far beyond statistical data points; they point to a fundamental philosophy shift in how cybersecurity professionals must view their workforce.
In its executive commentary accompanying the report, Fortra highlighted the relentless adaptability of the modern threat landscape:
"The modern phishing ecosystem is no longer defined by isolated scams, but by rapidly evolving criminal platforms that continuously adapt to defensive improvements."
This observation underscores the asymmetrical nature of cyber warfare. While corporate security teams must build defensive architectures that protect against every conceivable attack vector, cybercriminals need to find only a single weak point—often an exhausted, distracted, or inadequately trained employee—to breach the enterprise.

Industry analysts and security practitioners examining the report have echoed Fortra’s conclusions, emphasizing that traditional security awareness training (SAT)—often reduced to an annual compliance checkbox—is failing to deliver meaningful behavioral change. For years, organizations treated training as an administrative chore: employees would sit through a generic video presentation once a year, take a multiple-choice quiz, and return to their daily routines unchanged.
Security experts argue that this compliance-driven model is fundamentally mismatched with the speed and sophistication of modern social engineering. Modern threat actors leverage psychological triggers—such as urgency, fear, authority, and curiosity—to manipulate human cognition before rational thought can intervene. Combating these sophisticated tactics requires continuous, context-aware training regimens that simulate real-world threats and provide immediate, constructive feedback.
Furthermore, industry leaders stress that employees must be reframed. Rather than viewing the workforce as the weakest link in the security chain, organizations must intentionally cultivate an environment where employees feel empowered and valued as active defenders. When a corporate culture encourages open reporting without fear of punitive action, the entire organization benefits from collective vigilance.
Future Outlook: Building a Resilient Security Culture
As enterprises look toward the remainder of the decade and beyond, the path forward requires a fundamental harmonization of advanced technology and human-centric security strategies. The findings of the 2025 Phishing Simulation Benchmark Report make it unmistakably clear that neither technological automation nor human awareness alone can successfully neutralize modern phishing threats. A symbiotic approach is required.
1. Moving Beyond Compliance-Driven Training
Organizations must transition from periodic, check-the-box awareness training to continuous, adaptive learning programs. This involves deploying frequent, randomized phishing simulations that reflect current threat trends—such as generative AI-crafted lures, sophisticated MFA bypass techniques, and multi-channel attacks spanning email, SMS (smishing), and collaboration platforms like Microsoft Teams or Slack. Training should not be punitive; instead, it should serve as a positive reinforcement mechanism that educates users in real-time when they interact with simulated threats.

2. Reducing Friction in Incident Reporting
With only 10.5% of users reporting simulated threats in Fortra’s study, organizations must examine why reporting remains so difficult. Often, the reporting mechanism is cumbersome, requiring employees to forward suspicious emails as attachments or navigate complex ticketing systems. Enterprises must implement streamlined "Phish Alarm" buttons directly within email clients and collaboration tools, enabling one-click reporting. Furthermore, security operations teams must acknowledge and reward reporting behavior, transforming reporters into valued intelligence assets.
3. Strengthening Identity and Access Management (IAM)
Given that credential harvesting remains a primary objective for phishing campaigns, technical controls must assume that user credentials will occasionally be compromised. Organizations should accelerate the adoption of phishing-resistant MFA standards, such as FIDO2-compliant security keys and passkeys, which cannot be bypassed by traditional AiTM phishing kits. Coupled with strict conditional access policies—which evaluate device health, user location, and behavioral anomalies in real-time—enterprises can contain the blast radius even if a user falls victim to a sophisticated lure.
4. Cultivating a Just Culture of Shared Responsibility
Ultimately, technology and processes are only as effective as the culture that supports them. Building a robust security culture requires executive sponsorship, transparent communication, and psychological safety. Employees must feel confident that if they make a mistake—such as clicking a suspicious link or submitting credentials—they can report the incident immediately without fear of immediate reprimand. Early detection is the single most effective weapon against catastrophic data breaches; fostering a culture of trust ensures that security teams are alerted before minor oversights escalate into full-scale enterprise crises.
Conclusion
Fortra’s 2025 Phishing Simulation Benchmark Report serves as both a warning siren and a strategic roadmap. The data proves that attackers will continue to exploit human psychology to bypass technological barriers. By acknowledging that employees are an integral part of the security perimeter, organizations can bridge the gap between technology and human behavior—transforming their workforce from the most vulnerable attack vector into their most resilient line of defense.
