1 in 10 Phishing E-mails Fool Users in Education

In a recent study, 10 percent of simulated phishing e-mails sent to users in education institutions were successful, causing the recipient to click on a fraudulent link. That's according to the 2018 State of the Phish report from Wombat Security Technologies, in which researchers measured the average click rates on phishing tests across various industries. Education had an average click rate of 10 percent; the industries that performed worst in the tests were telecommunications and retail, with 15 percent and 14 percent average click rates, respectively. 

The study, which looked at user awareness and behavior around phishing and other data security issues, gathered data from several sources:

  • Analysis of tens of millions of simulated phishing attacks sent through Wombat's Security Education Platform between Oct. 1, 2016, and Sept. 30, 2017;
  • Survey responses from 10,000-plus information security professionals in more than 16 industries; and
  • A third-party survey of about 3,000 technology users in the United States, United Kingdom and Germany.

Other findings include:

  • Across all industries, 76 percent of organizations experienced phishing attacks in 2017;
  • Nearly half of information security professionals believe the rate of attacks has increased compared to 2016;
  • 76 percent of organizations now measure their susceptibility to phishing, up from 66 percent in 2016;
  • 95 percent of organizations train their end users on how to identify and avoid phishing attacks; and
  • 61 percent of users in the U.S. could correctly define what phishing is, while just 46 percent knew what ransomware is.

The report also pointed to one area where awareness is particularly low among U.S., U.K. and German adults: "smishing," or SMS/text message phishing. Just 16 percent of survey participants could correctly define smishing, while 67 percent couldn't even venture a guess.

"Smishing (SMS/text message phishing) has generally been considered a regional, consumer-based threat as opposed to a global cybersecurity concern," the report noted. "However, media coverage of successful smishing attacks rose during 2017 — a trend that's sure to increase in 2018 given that awareness of this threat vector is low."

For the full report, visit the Wombat site (registration required).

About the Author

Rhea Kelly is editor in chief for Campus Technology, THE Journal, and Spaces4Learning. She can be reached at [email protected].

Featured

  • The First Steps of Establishing Your Cloud Security Strategy

    In this guide, we'll identify some first steps you can take to establish your cloud security strategy. We'll do so by discussing the cloud security impact of individual, concrete actions featured within the CIS Critical Security Controls® (CIS Controls®) and the CIS Benchmarks™.

  • Human Error Remains the Leading Cause of Cloud Data Breaches

    Human error is still one of the biggest threats to cloud security, despite all the technology bells and whistles and alerts and services out there, from multi-factor authentication, to social engineering training, to enterprise-wide integrated cybersecurity platforms, and more.

  • Abstract illustration of a human news reporter interviewing an AI with a microphone

    AI on AI in Education: A Dialogue

    Scholars are doing lots of asking and predicting about the risks and rewards of generative artificial intelligence in school, but has anyone asked the all-knowing chatbots?

  • Pattern of desks with interconnected circles, triangles, and lines

    Classroom Furniture Giveaway Seeks Dream Learning Space Design

    Educators have a chance to design their ideal K-12 learning space in a contest recently announced by classroom furniture manufacturer KI.