A new study on phishing attacks reveals some very interesting findings, different from those of previous research. The 15-month study involved 14,733 people.

The study was conducted by researchers at ETH Zurich in collaboration with a company that did not inform participants about the phishing attack simulation program.
See also: Phishing emails distribute Agent Tesla malware via malicious PowerPoints
To conduct the study, the researchers sent fake phishing emails to participants' work emails and developed an email client button that allowed them to easily report suspicious emails.
The four objectives of the study were to determine the following:
- Which employees fall into phishers' traps most often
- How vulnerability evolves over time
- How effective training and warnings are
- If employees can do anything to help detect phishing

Gender does not play a role
The researchers also took into account some demographics. One finding that contradicts existing studiesis that gender is not associated with “susceptibility” to phishing. That is, both men and women are equally likely to fall victim to phishing.
However, the study found that age is a more determining factor. Younger and older people appear to be more prone to clicking on phishing links.
Furthermore, those who use specialized software continuously are more likely to fall into phishing traps, compared to those who do not need computers for their daily tasks.
Repeated clickers
The so-called “repeated clickers” represent a major risk for organizations in this study (as in previous ones), since these individuals often fall victim to phishing attacks. Furthermore, 23.91% of those who performed a dangerous action (activating macros, submitting credentials to login pages, etc.) did so more than once.
See also: Phishing attacks use QR codes to steal banking credentials
An interesting finding in the ETH study is that employees who are constantly exposed to phishing emails are ultimately scammed. According to the research, 32.1% of study participants clicked on at least one dangerous link or attachment.
This finding highlights the importance of having effective email security and anti-phishing filters, as constant exposure leads even the most resilient employees to take risky actions.

Training is not always effective
Warnings about suspicious emails were found to be effective, but effectiveness did not increase when there was more detail in those warnings. This is a new finding.
Another finding, which contradicts recommended security practices, is that voluntary training of employees to recognize phishing attacks through simulation programs is not effective.
Company employees who participated in the survey were able to use a 'Report Phishing' button in their email to report suspicious messages.
See also: Phishing attacks target US universities
The study found that 90% of employees reported six or fewer suspicious emails, but some remained very active throughout the experiment.
The reports were accurate at a rate of 68% for phishing and 79% when spam is also taken into account.
10% of users reported the suspicious emails within the first 5 minutes of receiving them, while 35% reported them half an hour after receipt.
Phishing is a complex topic involving many critical factors beyond the scope of this research, so these findings are not enough to judge whether the security practices already recommended (training, etc.) are effective or not.
However, taking into account the central role of phishing in the threat landscape, we must consider every new piece of data so that we can learn how to ultimately address it.
Source: Bleeping Computer
