Security1 publisher3 min readPublished
Simulated phishing clicks rose for six months of training before they fell
Pistachio's read of 354,962 simulations at 648 organizations puts clicking and credential submission at their worst around month six, when the testing is heaviest and half of it is rated hard. Quarterly click reporting lands there.
The Watch · Security desk

What happened
- Pistachio's Phishing Behaviour Report 2026 covers 648 organizations and 123,692 users with a complete 12-month record between June 1, 2025 and May 31, 2026.
- Across 354,962 simulations, click and credential-submission rates rose through the first six months of a program before declining at later stages, and reporting moved the same way.
- The report-to-click ratio rose from 1.3 at three months to 1.8 at 12 months, so messages were reported almost twice as often as they were clicked at the final stage.
- Hard simulations made up 44% to 52% of sends across the 16 named departments, so no department received a systematically easier or harder mix of tests.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A quarterly click rate cannot separate a program that has added harder and more frequent tests from a workforce that is getting worse, so it cannot carry the funding argument it is usually cited in.
- decision A program reviewed at month six is being judged at the worst point on this curve, and the choice in front of whoever reads that report is whether to cut it there.
- exposure Health and Logistics report the least of any named department, so their users leave the security team blind to a live campaign already sitting in other inboxes.
- contradiction The stage-by-stage groups are not the same users, so the method behind the headline curve cannot attribute either the rise or the fall to training.
The six-month peak sits where the testing is heaviest. Users at that stage received an average of 3.5 simulations per person, against 2.6 at three months and 2.8 at 12 months [4]. That is about 35% more mail per person than the three-month group got [16]. Half of it was difficult: 50.4% of six-month simulations were classified Hard [5]. After that stage the mix held at roughly 50% Hard while clicking and credential submission fell [6]. The fall is therefore measured against a steady difficulty mix. Over the stretch where clicks were rising, frequency was still climbing toward the six-month figure [4].
The stages compare overlapping but non-identical groups of organizations and users that had reached the three-, six-, nine- and 12-month marks of their programs [3]. Pistachio says the temporary increase in clicks can reflect more demanding and frequent testing that exposes vulnerabilities easier exercises may miss, instead of indicating that employees are becoming less resilient [21]. Neither the rise nor the fall is a measurement of one workforce improving.
"A low click rate can create a false sense of security. Clicking a phishing link is just one moment in a much longer chain of employee behaviour, and on its own it says little about whether someone, or the organisation as a whole, is actually getting more resilient," said Joe Jones, CEO of Pistachio [9]. Pistachio sells the simulations, and its report's central finding is that resilience reads best as a combination of clicking, credential submission and reporting behavior [20]. One mechanism it names is checkable without trusting the vendor: reused, familiar templates push click rates down because employees learn to recognize the exercises, without necessarily being better prepared for unfamiliar attacks [10].
Credential leaks fell about 1.5 times as fast as clicks between month six and month 12 [17]. Reporting also declined in that window [7]. Reports per click improved about 11% across those two stages [18], and that improvement comes from clicks falling faster than reports did. The larger ratio figure quoted at the 12-month stage is measured from three months, a longer stretch than the decline percentages cover [8].
The departmental figures count users, not messages. They are annual user-level measures: the share of users who clicked or submitted credentials at least once during the analysis year [13]. On that basis Construction's credential leak rate is about 40% of its click rate [19], the highest pair of departmental figures in the dataset [12]. Health clicked comparatively little and reported least of any named department, at 13.17% [14]. Logistics reported at 17.11%, below average, with an above-average click rate [15]. Pistachio notes that a reported message gives the security team the chance to investigate and remove similar mail from other inboxes [22].
What to watch
- Whether Pistachio publishes the Hard-simulation share at the three-month stage; without it the six-month rise stays tangled with test difficulty.
- Whether a true cohort, the same users tracked across 12 months, reproduces the six-month peak.
- Whether the report releases absolute click and credential-submission rates at each stage alongside the percentage changes.