Human Risk

Your Click Rate Cannot See A Deepfake Coming

A low click rate on your phishing simulations does not mean your organisation is safe. It measures one narrow behaviour, while deepfake calls and cloned voices now move money without a single click ever happening.

Your Click Rate Cannot See A Deepfake Coming

Your phishing click rate hides your true exposure because it measures one narrow behaviour, whether a person clicked one simulated link on one day, while the attacks doing the most damage now skip email links entirely: deepfake video calls and cloned voices. In the programmes I have run, click rate keeps falling while loss exposure keeps climbing.

Takeaways

  • Fortra’s 2025 benchmark of more than 14 million simulated phishing recipients found an average click rate of 5.4 percent, while close to 90 percent of genuine phishing emails employees receive go unreported.
  • Verizon’s 2024 Data Breach Investigations Report found that 68 percent of breaches involved a non-malicious human element such as error or social engineering.
  • Arup lost roughly $25 million in January 2024 after an employee in its Hong Kong office authorised transfers during a video call where every other participant was an AI-generated deepfake.
  • The FBI’s Internet Crime Complaint Center recorded $2.77 billion in business email compromise losses across 21,442 complaints in 2024.
  • Track report rate and time-to-report alongside click rate, since a workforce that flags suspicious messages quickly limits damage even when someone eventually clicks.
Human element share 68% of 2024 breaches
Avg click rate 5.4% (Fortra, 2025)
Phishing unreported about 90% (Fortra, 2025)
2024 BEC losses $2.77B (FBI IC3)

What does click rate measure?

Click rate measures exactly one behaviour: whether a person pressed a link inside a simulated phishing email your platform sent that day. It says nothing about whether they reported the email, hesitated first, forwarded it to a colleague, or would have verified a request over the phone before wiring money. Fortra’s 2025 benchmark of more than 14 million simulated phishing recipients across over 7,500 campaigns found an average click rate of 5.4 percent as of 2025, low enough that most security teams present it as a win. The same report found that close to 90 percent of genuine phishing emails employees receive go unreported, a gap the click rate number never shows a board.

Why boards still want it

Boards still ask for click rate because every phishing simulation platform generates it automatically, and a number that trends downward reads as progress on a single slide. In the programmes I have run, click rate falls almost every quarter simply because employees learn to recognise the same three or four simulation templates, not because they have gotten sharper at spotting novel attacks. That decline can sit next to a workforce that still cannot tell a cloned executive voice from the genuine one. Verizon’s 2024 Data Breach Investigations Report found that 68 percent of breaches involved a non-malicious human element, a person making an error or falling for social engineering, and Security Magazine’s coverage noted that share barely moved from the year before despite widespread awareness spending. SANS Institute’s analysis of the same report argues that completion metrics like click rate were never designed to capture that kind of exposure. Verizon’s 2024 DBIR is the clearest evidence that a falling click rate and a stable breach rate can coexist.

Five risk indicators ranked by cost

These are the five indicators I would put in front of a board instead of click rate, ranked by how much unaddressed risk each one carries based on the pattern I see running these programmes, worst first:

  1. Non-report rate. Fortra’s 2025 data puts unreported genuine phishing at close to 90 percent, which means most active campaigns run inside a mailbox for days before anyone tells security.
  2. Unverified payment change requests. The FBI’s Internet Crime Complaint Center recorded $2.77 billion in business email compromise losses across 21,442 complaints in 2024, and IC3’s 2024 report shows this single category still outruns almost every other cybercrime by dollar loss.
  3. Voice and video verification gaps. Employees with authority to move money need a callback protocol that does not rely on recognising a voice or a face, because both can now be cloned convincingly.
  4. MFA push acceptance under pressure. A workforce trained to approve a second or third push notification without checking will defeat multi-factor authentication regardless of how well it spots email links.
  5. Repeat-clicker concentration. A small group of repeat clickers, often the same ten or fifteen people every quarter, carries a disproportionate share of an organisation’s simulated and genuine exposure, and generic training rarely reaches them.

How did Arup’s deepfake win?

Arup’s deepfake attack won because it never touched a phishing simulation category at all: no email link, just a video call where every participant except the victim was AI-generated. In January 2024, an employee in Arup’s Hong Kong office joined a call with people who looked and sounded like the firm’s UK-based CFO and several familiar colleagues, all fabricated from public video and audio the company had published itself. CNN reported the employee authorised 15 transfers totalling roughly $25 million after the call resolved doubts a first, text-based request had raised. Dezeen’s report quoted Arup’s chief information officer, Rob Greig, confirming no network or data had been compromised and describing the incident as technology-enhanced social engineering. No phishing simulation trains for a fabricated meeting.

Is report rate the better number?

Report rate is a better number than click rate because it measures a behaviour an organisation needs at scale, someone recognising a suspicious message and telling security before it spreads. KnowBe4’s 2025 phishing benchmarking report found a global baseline phish-prone percentage of 33.1 percent before training, falling to 4.1 percent after twelve months of simulation and training. That report is a vendor publication built on KnowBe4’s own platform data, and KnowBe4 has separately claimed its training reduces global click rates by 86 percent, a vendor claim worth testing against your own numbers before accepting it. Neither publication reports a comparable improvement in report rate, which is the number I would ask for first.

What does AI vishing change?

AI vishing changes training because voice cloning removes the one cue people have relied on for decades to catch phone-based fraud: recognising whether a voice sounds like the person it claims to be. Since April 2025, the FBI has warned that malicious actors are impersonating senior US officials using AI-generated voice messages and text to build rapport before requesting money or access. The FBI’s alert recommends verifying any such contact through a separately known phone number rather than one supplied in the message itself, and CNBC covered the same warning for a broader audience beyond government targets. Most security awareness programmes I have seen still run zero simulations against phone or video channels, because the platforms built for email phishing were never designed to test them.

What should you tell the board?

Tell the board the report rate and how many days it takes on average between a genuine phishing email arriving and someone flagging it, since that gap determines whether security can act before damage happens. Add the percentage of finance and executive-assistant roles with a documented, tested out-of-band verification protocol for payment or credential changes, since IC3’s public service announcement puts cumulative reported BEC losses since 2013 at over $55 billion. Include repeat-clicker counts by role, not by individual name, and what remediation each group received. A click rate on its own only tells a board that training happened, nothing about whether the organisation would survive a call like the one that cost Arup $25 million.

Prompts you can use

Paste these straight in. Change the parts in square brackets and nothing else.

Design a human risk dashboard
You are a security awareness and human risk advisor helping me replace a phishing-click-rate-only report with a fuller dashboard for my leadership team. Here is my context: [describe organisation size, industry, current metrics tracked, and current phishing platform]. Propose a dashboard with 4 to 6 metrics beyond click rate, including report rate and time-to-report, that I can realistically pull from my existing tools within the next quarter. For each metric, explain why it beats click rate as a risk indicator, how to calculate it from data I already have, and one realistic target range based on published industry benchmarks, naming the source. Do not invent statistics; if you are unsure of a benchmark, say so and tell me where to find one. Ask me clarifying questions about my current tooling before you propose the dashboard.

Fill in your organisation’s size, industry and current phishing platform before using this, and verify any benchmark numbers the model gives you against the primary report rather than treating them as final.

Draft an out-of-band verification protocol
You are a security process designer helping me draft a payment and credential change verification protocol that would resist a deepfake video call or a cloned voice call, not just a phishing email. My context: [describe your finance team size, who currently has authority to approve wire transfers or credential resets, and any existing verification steps]. Draft a short, practical protocol covering what triggers the verification step, who the callback must go to and how that number is sourced independently of the request itself, what happens if the requester cannot complete the callback, and how exceptions get logged. Keep it to something a finance team can follow under time pressure. Ask me who currently has transfer authority before you draft it, since the protocol needs to name specific roles, not generic titles.

This produces a starting policy only; have legal, finance and security review it before rollout, and adapt the callback and escalation steps to your actual approval chain.

Build a repeat clicker plan
You are a security awareness programme manager helping me design a remediation plan for repeat clickers, the small group of employees who click simulated phishing links quarter after quarter. My context: [describe roughly how many repeat clickers you have, their roles or departments if known, and what generic training they have already received]. Propose a remediation approach that is proportionate, not punitive, including how many additional touchpoints to add, what format works better than another generic e-learning module, and how to measure whether the plan worked within two quarters. Flag anything in your proposal that could raise employee relations or privacy concerns, and ask me clarifying questions about my organisation's culture and any HR constraints before finalising it.

Loop in HR before implementing anything from this plan, and use it to guide behaviour change, not to single out individuals in front of leadership.

Questions people actually ask

What is a good phishing click rate?

Fortra’s 2025 benchmark of over 14 million simulated recipients found an average click rate of 5.4 percent, and KnowBe4’s 2025 data shows trained organisations reaching 4.1 percent. But a low number only proves people stopped clicking known simulation templates. It says nothing about report rate or deepfake resistance.

Why do employees not report phishing emails?

Fortra’s 2025 benchmark report found close to 90 percent of genuine phishing emails employees receive go unreported. In the programmes I have run, the usual causes are an unclear reporting button and no visible follow-up telling the person what happened after they reported.

Can security awareness training stop deepfake scams?

Standard email-based training does not, because deepfake attacks like the one that cost Arup $25 million in January 2024 arrive through a video call, not a link. Stopping them requires a separate, tested out-of-band verification protocol for anyone with authority to move money or credentials, which most awareness programmes still lack.

What is human risk management?

Human risk management is the practice of measuring and reducing the behaviours that lead to security incidents, such as unreported phishing and MFA fatigue, rather than only tracking training completion or simulated click rates. It treats people as a risk category with its own metrics, not a training checkbox.

How much money do businesses lose to business email compromise?

The FBI’s Internet Crime Complaint Center recorded $2.77 billion in business email compromise losses across 21,442 complaints in 2024. IC3 has also stated that cumulative reported BEC losses since 2013 exceed $55 billion, making it one of the most financially damaging categories of cybercrime it tracks.

Sources

  1. Fortra’s 2025 benchmarkfortra.com
  2. Security Magazine’s coveragesecuritymagazine.com
  3. SANS Institute’s analysissans.org
  4. Verizon’s 2024 DBIRverizon.com
  5. IC3’s 2024 reportic3.gov
  6. CNN reportedcnn.com
  7. Dezeen’s reportdezeen.com
  8. KnowBe4’s 2025 phishing benchmarking reportcontent.shi.com
  9. KnowBe4 has separately claimedsecure.businesswire.com
  10. The FBI’s alertfbi.gov
  11. CNBC coveredcnbc.com
  12. IC3’s public service announcementic3.gov

What happens next

Watch whether the major training vendors’ 2026 benchmark reports start publishing report rate and time-to-report as standard metrics alongside click rate, since that change is already underway in the platforms I track. Expect more incidents like Arup’s as video and voice cloning tools get cheaper, which will push out-of-band verification protocols from a finance-team policy into a standard line item in security awareness programmes.

Share this
About the author
Vinayak Kapoor
Vinayak Kapoor

Vinayak started at seventeen on a call centre floor and climbed every rung himself over fifteen years: millions of customer conversations for some of the world's largest brands, self-taught design, video and web work, a profitable e-commerce brand of his own, and now human cyber risk, where he has built customer success journeys for national critical infrastructure and leads business growth at HumanFirewall. Nobody groomed him. He learned every skill alone, including the AI he now builds with daily as founder of Quarry, MaaSify and HuMatrix. He writes here so your career gets the guide his never had.

Read next
Come find me

The daily thinking
lives on the feeds.

Long form here. The working notes, the arguments and the things that did not fit go out most days.

← All writing