You still treat a falling click rate like a win. The quarterly simulation looks cleaner. Someone builds a slide about “awareness improving.” Then you get a study of 2.47 million simulated attacks that says the number you’ve been managing is a weak proxy for actual loss. The researchers want credential leaks and reporting in the scoreboard. The click is a noisy side effect.

That would be an academic argument in a quieter week. It landed beside a threat actor that generated about a million personalized fraud emails in three days, and a marketing-platform breach that put crypto customers in the path of mail that looked operational. If your cybersecurity program still grades people on whether they opened a fake invoice, you’re scoring a habit attackers have already priced in.

You Optimized a Metric Attackers Already Ignore

Most awareness programs still run like a driver’s test. You send a lure, you count who bites, you assign a module, you graph the trend. The graph is comforting because it moves. Leadership likes motion. Vendors like a number they can put on a renewal deck.

SecurityWeek’s coverage of the research is blunt about why that comfort is fake. A click is a messy moment. People tap because they’re between meetings, because the preview pane on a phone is tiny, because the subject line matches a shipment they really are waiting on. Plenty of those clicks never become a password. Plenty of real password dumps never show up as a click in your simulator, because the live message didn’t look like your template. Credential submission is the loss event. Reporting is the defensive behavior you actually want. Click-through is a CSV with a story attached.

SecurityWeek report on phishing simulation research covering millions of test attacks
Large-scale simulation data is pushing teams to score credential leaks and reports, not just who clicked the lure.

You already know this pattern in the rest of the stack. A firewall that drops noise while the session that matters still lands does not get credit for being “green.” Threat detection that lights up on a tracking pixel, then goes quiet when a login posts to a lookalike SSO page, has the same bug as the awareness dashboard. You’re instrumenting the wrong step and calling the dashboard cyber security.

This is a bad look for programs that still sell click-rate reduction as risk reduction. Busy people will keep clicking. Determined people will keep submitting. Your job is to make the submit expensive for the attacker, and the report cheap for the user.

A Million Lures and a Stolen List Beat Your Simulator

For years the hallway briefing went like this: bulk spam is sloppy, spear phish is rare, training plus a filter covers the middle. That briefing is expired. Dark Reading’s reporting on a campaign that produced roughly one million personalized fraud emails in three days is the operational punchline. Drafting no longer forces a trade between volume and credibility. Both ship in the same job.

The message can mention a ticket, a region, a product the recipient actually uses, and still leave the queue by the hundreds of thousands. Your users will not be saved by a missing comma. There may not be a comma left to miss. Email threat-protection will still catch a slice. It will miss a slice that looks like every other SaaS notice in the inbox. When the lure is personalized and the list is accurate, some people will click. A smaller set will submit. Your simulated phish, written without last week’s real invoice thread, does not predict that second group.

Mailbox overflowing with messages, illustrating high-volume personalized fraud email campaigns
Once personalization scales, the inbox is full of mail that looks like work. Click rates on canned simulations stop telling you much.

Stolen lists make that problem worse. Malwarebytes reports that a breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to follow-on phishing, with a wider set of brands still in question. A marketing platform holds verified addresses, names, product lines, sometimes last-touch context. Steal that, and you skip the cold open. The lure can replay a brand’s cadence because it came from the same operational pipe the brand paid for.

Cryptocurrency investor at a laptop, representing customers targeted after a marketing-vendor email breach
After the Brevo incident, the risky mail looked like a product update, not a stranger with a gift card.

SPF and DKIM on your corporate domain don’t save a finance user who gets a “billing update” from a wallet or portfolio tool they really do use. Defense in depth here means you assume some mail will look right. You assume a subset of people will interact. You design so interaction doesn’t equal a live session.

Cybersecurity Controls Have to Fire on Submit, Not Click

If the research is right, incident response should start when credentials leave, or when someone hits report. That sounds like a policy footnote. It’s a detection and security hardening change. Hover-training is a relic you keep buying because it graphs well. Containment is the work.

Treat the password form as the incident

Build the next two weeks around events you can prove, not around shame. Keep the steps tool-agnostic so they survive whatever mail stack you already have.

  1. Retune simulations and live handling so credential entry and reporting are first-class. A click with no submit is a coaching note. A submit is a password reset, a session revoke, and a ticket. A report is a win you record in the same dashboard you used to reserve for clicks.
  2. Hunt stuffing and password-spray after any suspected campaign, not only after a “successful” click in your LMS. Stolen marketing lists feed reuse and brute-force against SSO, VPN, and mail. Watch auth failures, new MFA devices, and inbox rules in the same window.
  3. Cut the paths a harvested password can still use. Disable legacy auth, shrink standing app passwords, require phishing-resistant MFA on admin and finance, and shorten webmail and IdP session lifetime so a posted secret dies faster.
  4. Inventory who can email your people as a trusted brand. Marketing vendors, CRMs, support desks, payroll, crypto processors. Those contact files are pre-built targeting databases. Demand breach notification you can actually use, collect fewer fields, and expire dead contacts.
  5. Move threat-protection beyond static lure matching. Personalization will keep beating last month’s indicators. Score first-time sending domains, lookalike SSO, and unexpected vendors, then put human review on high-value roles instead of another annual module.

You still need a mail filter, a trained human, and a network edge that doesn’t blindly trust “the user clicked, so it must be fine.” The stack works when those layers agree on containing the account. Click counts can stay on a secondary chart. They just shouldn’t run the program.

Frequently Asked Questions

Should we shut down simulated phishing?
Keep sending tests if they teach reporting and catch real submits. Kill the program if the only output is a click-rate trend used for shame or vendor renewal. A simulation that never measures credentials or reports is expensive fiction.
How fast should we move on a submitted password versus a click?
Treat a submit as an identity incident: reset, revoke sessions, check MFA changes, and hunt reuse the same day. A click with no input can wait for coaching unless the URL already dropped a payload. Speed belongs on the secret, not on the curiosity tap.
Does a marketing-vendor breach change our mail authentication work?
DMARC on your own domain still matters, and it will not stop a third party from mailing your staff from a brand they actually use. Reduce what those vendors store, monitor for lookalike billing mail, and put finance on an out-of-band check for any payment change that arrives by email.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.