Skip to content
← Intel Brief
Enterprise · Red team

Phishing still wins. Here's the data.

The inbox still beats the firewall. What holds up in phishing simulations and what is theatre when you measure click, report, and dwell.

Phishing campaign data visualised across email and security signals
AN3 · Offensive Research · · 8 min read

The inbox still beats the firewall.

Not because employees are careless. Because phishing is a product: role-specific pretexts, cloned internal tools, OAuth consent flows, and MFA fatigue prompts that look like the real stack. Perimeter controls do not see most of that path until a session already exists.

This note is for security leads who run annual "phishing training," get a click rate, and call it done. The useful signal is not the click rate alone. It is what happens after the click, and whether anyone reports before the attacker finishes.

What we measure when we simulate

A useful campaign is not a gotcha email with a cartoon. It is a controlled test of:

  • Delivery — did the message reach the inbox the way an adversary would?
  • Interaction — click, reply, credential submit, OAuth consent, MFA approve
  • Reporting — how fast did someone flag it, and did that open a real response path?
  • Dwell — time from first interaction to containment of the resulting session or account

If you only report "12% clicked," you are measuring curiosity. You are not measuring human-layer risk.

Patterns that keep showing up

### 1. Role-specific pretexts outperform generic IT support

Finance gets vendor payment changes. Engineering gets CI / GitHub / cloud console alerts. Executives get board or legal framing. Generic "IT password reset" still works on some populations. Targeted pretexts work on more, and they produce cleaner sessions because the victim expects that workflow.

### 2. Fake internal tools beat external links

A link to a lookalike SSO page for a tool people already use (HR, expense, VPN, password vault, ticketing) outperforms a random "document share" domain. People have been trained to fear unknown links. They have not been trained to distrust a familiar logo on a slightly wrong hostname.

### 3. Reporting culture beats another awareness video

Teams that can report without shame, and that see a response when they report, cut dwell time hard. Teams that treat a click as a personal failure hide it. Attackers prefer the second culture.

The control is not "more training modules." It is a short path from report to revoke-session / reset / ticket, plus leadership that treats reports as wins.

### 4. MFA helps until it is pushed or consented away

MFA fatigue, push bombing, and malicious OAuth apps turn "we have MFA" into a speed bump. Simulations that stop at password harvest understate modern kits. Include consent phishing and MFA prompts if that is how your real IdP works.

What actually moves the needle

From field exercises, the changes that stick are operational, not cinematic:

  • Pretext library matched to real roles — not one corporate template for everyone
  • Instrumentation — know who interacted, from where, and whether a session was created
  • Report button that works — one click, ticket opens, SOC sees it
  • Fast containment playbooks — revoke sessions, kill refresh tokens, force step-up, disable the OAuth grant
  • No public shaming — private coaching for repeat high-risk roles; public praise for fast reports
  • Executive and VIP tracks — different pretexts, higher monitoring, not a free pass

Awareness content still has a place. It does not replace a measured kill chain from email to session.

What to stop doing

  • Annual one-shot campaigns with no follow-up on reporters or clickers
  • Leaderboards that punish clicks in open channels
  • Simulations that never touch OAuth, SSO, or mobile MFA
  • Counting "training completion" as a security metric

Those produce slides. They do not produce shorter dwell.

Closing note

Phishing wins when the organization optimizes for blame and completion rates instead of detection and containment.

Treat human-layer defense like any other control: define the attack path, measure the breakpoints, and fix the ones that leave sessions alive. The inbox will keep being the front door. The question is how long the visitor gets to stay.


AN3 Intel · field notes on human-layer defense.