By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: Knowbe4Published July 7, 2026

TL;DR: A 33.1% industry-wide phishing susceptibility rate and AI-generated attacks evading more traditional defences are highlighted in KnowBe4’s 2025 benchmarking report, based on 14.5 million users, 62,400 organisations and 67.7 million simulated phishing tests. The governance issue is no longer awareness alone, but whether human identity controls can keep pace with adaptive social engineering, with training reducing risk materially over time.


At a glance

What this is: A phishing benchmarking report showing that AI-assisted attacks are increasing human susceptibility and that ongoing security awareness training can materially reduce risk.

Why it matters: It matters because phishing remains a major identity entry point, and IAM, SOC, fraud, and security teams need controls that account for how people actually respond to adaptive social engineering.

By the numbers:

  • KnowBe4 analyzed data from 14.5 million users across 62,400 organizations and 67.7 million simulated phishing tests.
  • 33.1%, ndustry-wide baseline Phish-prone Percentage was 33.1%, meaning about one in three employees remained susceptible to phishing and social engineering attacks.
  • Security awareness training reduced phishing risk by over 40% in 90 days and by up to 86% within a year.
  • 82.6% of phishing emails now leverage AI-generated content, while attacks evading Microsoft’s native defenses and secure email gateways rose by 47%.

👉 Read KnowBe4's 2025 Phishing By Industry Benchmark Report


Context

Phishing is no longer just a communications problem. It is an identity access problem, because successful deception still creates the trusted action that attackers need. When AI helps attackers tailor message timing, tone, and context, the gap widens between static controls and the way people make decisions under pressure.

For identity and security teams, the practical question is not whether users should be trained, but how human identity risk is measured, managed, and re-tested over time. That intersects with IAM, fraud prevention, and SOC detection because phishing often becomes the first step in credential theft, account takeover, and broader compromise.


Key questions

Q: What breaks when phishing controls stop at user awareness alone?

A: Awareness without identity enforcement leaves the attacker free to reuse stolen credentials, hijack sessions, or pivot through recovery workflows. The control failure is that a successful lure becomes authenticated access, which can then be used for fraud, mailbox abuse, or lateral movement. Effective defence needs conditional access, session controls, and privilege restrictions, not training by itself.

Q: Why do AI-generated phishing attacks change human identity controls?

A: They reduce the value of message inspection as a control because attackers can now generate persuasive, context-aware lures at scale. Human identity programmes should shift toward phishing-resistant authentication, stronger verification for sensitive actions, and recovery processes that do not depend on user intuition alone.

Q: How do security teams know if security awareness training is actually working?

A: Look for reductions in susceptibility over time, improved reporting behaviour, and fewer successful phish-to-access events. A useful programme measures outcomes by cohort, role, and channel, then compares those results with authentication and incident data. If training does not change behaviour or reduce downstream compromise, it is not functioning as a control.

Q: Why do phishing campaigns often become IAM problems after the first click?

A: Because the attacker is usually trying to gain a trusted identity foothold, not just send spam. Once credentials, session approvals, or reset workflows are captured, the incident becomes an access problem involving account takeover, privileged workflows, and potentially non-human identity exposure. That is why phishing needs to be governed as part of IAM, not only email security.


Technical breakdown

Why AI-generated phishing changes the attack surface

AI-generated phishing reduces the cost of creating convincing lures and increases the speed at which attackers can test variants. That matters because modern phishing is not one message at a time. It is a scalable influence loop that uses personalisation, language variation, and evasive formatting to bypass both user intuition and some email security controls. The result is a higher probability that a recipient will click, reply, or disclose information, even when the message is not technically sophisticated. In governance terms, this shifts phishing from a spam-filter problem to a human identity assurance problem.

Practical implication: treat phishing resilience as an identity control that must be measured, not a one-time awareness exercise.

How phishing becomes an account takeover path

Phishing succeeds when it converts attention into credentials, session tokens, or approved actions. Once the attacker has a password, MFA prompt approval, or a reset workflow compromise, they can pivot into account takeover, inbox abuse, or lateral fraud. In many environments, that initial compromise is enough to reach SaaS apps, privileged workflows, or financial processes. The control weakness is not only user error. It is also overreliance on a single verification step, weak step-up authentication, and limited behavioural monitoring after authentication has occurred.

Practical implication: pair user training with stronger authentication, conditional access, and post-login anomaly detection.

Why security awareness training changes outcomes

Security awareness training works when it is continuous, role-relevant, and reinforced by simulations. The report’s figures show that risk reduction compounds over time, which indicates that sustained behaviour shaping can materially change phishing susceptibility. This is not because training eliminates human error. It is because repeated exposure improves pattern recognition, response speed, and reporting behaviour. For practitioners, the technical point is that training acts like a behavioural control plane for human identity, especially when integrated with reporting channels and feedback loops into SOC or mailbox triage.

Practical implication: measure training by susceptibility trend and reporting behaviour, not by completion rates alone.


Threat narrative

Attacker objective: The attacker wants a trusted human identity foothold that can be turned into credential theft, account takeover, and downstream fraud or data access.

  1. Entry begins with AI-generated phishing that uses personalised language and delivery tactics to bypass user suspicion and some email controls.
  2. Credential access follows when the victim clicks, enters credentials, approves a prompt, or exposes information that enables account compromise.
  3. Impact occurs when the attacker uses the trusted account for fraud, inbox abuse, data access, or wider internal compromise.

NHI Mgmt Group analysis

AI-powered phishing is now a human identity governance problem, not just a user-awareness problem. The report’s core signal is that attackers are industrialising deception with AI-generated content, which means static training alone cannot keep pace. IAM teams need to think about how people authenticate, verify, and report suspicious requests across email, chat, and workflow tools. The practitioner conclusion is simple: human identity assurance must be measured as a control, not assumed as behaviour.

Phish-prone percentage is the named concept teams should track as a governance metric. The report’s 33.1% baseline shows that susceptibility is still high enough to create systemic exposure, especially when access to SaaS and business systems is one click away. A useful control model is to treat phish-prone percentage as a risk indicator alongside MFA coverage and conditional access outcomes. The practitioner conclusion is that behaviour metrics belong in identity governance reporting, not just awareness dashboards.

Security awareness training only matters when it is coupled to identity controls. The report shows meaningful risk reduction after sustained training, but that improvement becomes operationally valuable only when paired with stronger authentication, reporting paths, and detection after login. Without that coupling, training reduces some exposure but leaves account takeover paths open. The practitioner conclusion is to align SAT with IAM, SOC, and fraud processes rather than leaving it as a standalone education programme.

AI-generated phishing is widening the gap between detection assumptions and human decision-making. Email security tools can filter volume, but they cannot fully model context, urgency, or trust cues across every business relationship. That creates a governance gap where the attacker’s success depends less on technical exploitation and more on behavioural predictability. The practitioner conclusion is to assume that human trust will be probed continuously and design controls around that reality.

OWASP NHI Top 10 is increasingly relevant because phishing often targets the human path into non-human access. When a human account is used to approve access, create tokens, or expose secrets, the incident can quickly spill into NHI compromise. That intersection matters because identity programmes often separate human and non-human governance too cleanly. The practitioner conclusion is to review where phishing can become a route into privileged workflows, secrets, and delegated access.

What this signals

The signal for practitioners is that phishing defence now sits across IAM, SOC, and fraud operations. If a programme still measures awareness by completion alone, it is missing the part that matters most: whether users report, resist, and recover before access is abused.

Human identity assurance gap: the widening difference between user training coverage and actual trust decisions in live workflows. Teams should treat this as a measurable governance issue, using controls and reporting paths that turn human suspicion into security telemetry.

The next maturity step is to connect behaviour change with access containment. That means combining phishing-resistant authentication, conditional access, and post-login monitoring with role-based simulations so the programme can show whether risk is falling in the places that matter most.


For practitioners

  • Measure phishing susceptibility as a live risk metric Track phish-prone percentage by business unit, role, and region, then tie it to identity controls such as MFA, conditional access, and reporting rates. Use trends to identify where users remain most exposed rather than relying on annual completion data.
  • Pair training with stronger authentication controls Use phishing-resistant MFA where possible, step-up checks for risky transactions, and session monitoring after authentication. Training should reduce the chance of compromise, but authentication should still limit what a successful phish can do.
  • Build reporting into the human identity control loop Make it easy for employees to report suspicious messages and feed those reports directly into SOC and mailbox triage workflows. The value of awareness grows when reports become detection signals instead of being treated as training feedback only.
  • Map phishing to downstream NHI exposure Review where compromised human accounts can approve OAuth grants, reveal secrets, or access service workflows. This is where a human phishing event turns into broader NHI risk, so the access paths need explicit review.

Key takeaways

  • AI-generated phishing turns human trust into a scalable access path, which makes identity governance part of the defence model.
  • A 33.1% baseline susceptibility rate and sustained risk reductions after training show that behaviour can improve, but only if the programme is measured properly.
  • The most effective response is not awareness alone, but a control set that combines training, authentication, reporting, and downstream access containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-1The article is about phishing awareness and user training outcomes.
NIST SP 800-53 Rev 5AT-2AT-2 addresses security awareness training, the report's main control theme.
NIST SP 800-63SP 800-63BPhishing often targets authenticator use and account takeover pathways.
OWASP Non-Human Identity Top 10NHI-02Human phishing can cascade into compromised delegated access and non-human identities.
GDPRArt.32Where phishing leads to personal-data exposure, security measures must support confidentiality and resilience.

Treat phishing resilience as part of confidentiality controls under Art.32 when personal data is at risk.


Key terms

  • Phish-prone percentage: Phish-prone percentage measures the share of users who click or otherwise respond incorrectly during simulated phishing tests. It is a behavioural metric that helps security teams baseline susceptibility, target training, and track whether awareness efforts are improving real-world judgment over time.
  • Security Awareness: A programme that teaches people how to recognise and respond to common security risks. In identity security, awareness is only useful when it changes behaviour around authentication, verification, reporting, and safe handling of access requests. Message repetition alone does not create measurable risk reduction.
  • Human Identity Assurance: Human identity assurance is the set of controls and signals used to verify that a person is who they claim to be and is behaving within expected boundaries. In phishing contexts, it extends beyond authentication to include decision-making, reporting behaviour, and resistance to deceptive requests.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.

What's in the full report

KnowBe4's full report covers the operational detail this post intentionally leaves for the source:

  • Industry-by-industry phishing benchmark tables that let you compare susceptibility across sectors and company sizes
  • Regional breakdowns showing where phishing risk is highest and how that varies by geography
  • Simulation results and methodology details behind the 14.5 million user benchmark dataset
  • Practical guidance on how to strengthen security awareness programmes over a 90-day and 12-month horizon

👉 KnowBe4's full report includes the sector-level benchmark data, regional comparisons, and training impact figures behind these findings.

Deepen your knowledge

NHI Mgmt Group’s NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, secrets management, and machine identity security. It helps practitioners connect identity controls to the broader security programme they operate every day.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org