1 in 10 Phishing E-mails Fool Users in Education

In a recent study, 10 percent of simulated phishing e-mails sent to users in education institutions were successful, causing the recipient to click on a fraudulent link. That's according to the 2018 State of the Phish report from Wombat Security Technologies, in which researchers measured the average click rates on phishing tests across various industries. Education had an average click rate of 10 percent; the industries that performed worst in the tests were telecommunications and retail, with 15 percent and 14 percent average click rates, respectively. 

The study, which looked at user awareness and behavior around phishing and other data security issues, gathered data from several sources:

  • Analysis of tens of millions of simulated phishing attacks sent through Wombat's Security Education Platform between Oct. 1, 2016, and Sept. 30, 2017;
  • Survey responses from 10,000-plus information security professionals in more than 16 industries; and
  • A third-party survey of about 3,000 technology users in the United States, United Kingdom and Germany.

Other findings include:

  • Across all industries, 76 percent of organizations experienced phishing attacks in 2017;
  • Nearly half of information security professionals believe the rate of attacks has increased compared to 2016;
  • 76 percent of organizations now measure their susceptibility to phishing, up from 66 percent in 2016;
  • 95 percent of organizations train their end users on how to identify and avoid phishing attacks; and
  • 61 percent of users in the U.S. could correctly define what phishing is, while just 46 percent knew what ransomware is.

The report also pointed to one area where awareness is particularly low among U.S., U.K. and German adults: "smishing," or SMS/text message phishing. Just 16 percent of survey participants could correctly define smishing, while 67 percent couldn't even venture a guess.

"Smishing (SMS/text message phishing) has generally been considered a regional, consumer-based threat as opposed to a global cybersecurity concern," the report noted. "However, media coverage of successful smishing attacks rose during 2017 — a trend that's sure to increase in 2018 given that awareness of this threat vector is low."

For the full report, visit the Wombat site (registration required).

About the Author

Rhea Kelly is editor in chief for Campus Technology, THE Journal, and Spaces4Learning. She can be reached at [email protected].

Featured

  •  laptop on a clean desk with digital padlock icon on the screen

    Data Privacy a Top Concern as Orgs Scale Up AI Agents

    As organizations race to integrate AI agents into their cloud operations and workflows, they face a crucial reality: while enthusiasm is high, major adoption barriers remain, according to a new Cloudera report. Chief among them is the challenge of safeguarding sensitive data.

  • chart with ascending bars and two silhouetted figures observing it, set against a light background with blue and purple tones

    Report: Enterprises Are Embracing Agentic AI

    According to a new report from SnapLogic, 50% of enterprises are already deploying AI agents, and another 32% plan to do so within the next 12 months..

  • stacks of glowing digital documents with circuit patterns and data streams

    Mistral AI Intros Advanced AI-Powered OCR

    French AI startup Mistral AI has announced Mistral OCR, an advanced optical character recognition (OCR) API designed to convert printed and scanned documents into digital files with "unprecedented accuracy."

  • student using a tablet with math symbols dissolving into a glowing AI

    Survey: Students Say AI Use Can Reduce Math Anxiety

    In a recent survey, 56% of high school students said that the use of artificial intelligence can go a long way toward reducing math anxiety.