HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Well‑Funded Companies Exhibit Highest Phishing Attachment Click Rates in 13.9 M Simulation Study

A benchmark of 13.9 million simulated phishing messages reveals that only 10 % of recipients report attempts, while the majority click malicious attachments. Well‑funded organizations show the highest click‑through rates, highlighting a human‑layer weakness that directly impacts SOC 2 security compliance.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Well‑Funded Companies Exhibit Highest Phishing Attachment Click Rates in 13.9 M Simulation Study

What Happened — A benchmark of 13.9 million simulated phishing messages found that only 10 % of recipients reported the attempt, while the remaining 90 % either clicked the malicious attachment or ignored it. Companies with the largest funding levels showed the highest click‑through rates, indicating that financial resources alone do not guarantee stronger human defenses.

Why It Matters for Compliance & Audit Readiness

  • The low reporting rate and high click‑through expose a gap in the “people” control that SOC 2’s Security principle expects to be continuously monitored and evidenced.
  • Without demonstrable, periodic security‑awareness testing, organizations struggle to provide audit‑ready proof that the human layer is effective against phishing.
  • Verisq’s Security Awareness Training capability supplies the continuous evidence and control‑mapping needed to satisfy SOC 2 access‑control and risk‑management criteria.

Who Is Affected — Financial services, technology/SaaS firms, defense contractors, and any organization that runs regular phishing simulations.

Recommended Actions

  • Align phishing‑simulation metrics (click‑rate, reporting‑rate) with SOC 2 control objectives and capture evidence in a centralized audit repository.
  • Augment technical controls (email filtering, MFA) with a structured, recurring security‑awareness program that includes measurable training completion and simulated‑phishing results.
  • Review and adjust reporting thresholds to avoid SOC overload while still catching early‑stage campaigns.

Source: Help Net Security – The best‑funded companies open the most phishing attachments

Technical Notes

  • Attack vector: Phishing emails with malicious attachments or credential‑harvesting links.
  • No specific CVEs; the threat leverages social‑engineering techniques (urgency, authority) and increasingly sophisticated Phishing‑as‑a‑Service kits that can bypass MFA.
  • Data types targeted: login credentials, corporate network access, and potential malware payloads.
📰 Original Source
https://www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →