By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: Knowbe4Published January 8, 2026

TL;DR: South America starts with a 39.1% phishing-prone percentage, the highest in the world, according to Knowbe4 research, but that falls to 18.2% after 90 days of training and 4.5% after a year, while AI-generated phishing now accounts for 82.6% of emails. The finding is clear: awareness programmes remain one of the few controls that can materially reduce human-driven exposure at scale.


At a glance

What this is: This benchmark report maps phishing susceptibility by region, sector and workforce size, and its central finding is that sustained awareness training sharply reduces click risk over time.

Why it matters: It matters because phishing remains a primary identity entry point, and security teams need to understand how human behaviour, not just filters, changes the likelihood of compromise across IAM, NHI and broader security programmes.

By the numbers:

👉 Read KnowBe4's phishing benchmark report for South America and AI-driven attack trends


Context

Phishing is a governance problem as much as a detection problem. When a region starts with a high click-through rate, the real question is not whether mail filters are working, but whether identity assurance, user behaviour and reporting workflows are reducing the chance that a malicious message becomes a compromise. This article focuses on South America, where the benchmark data shows unusually high initial exposure.

For identity and security teams, the relevance is broader than email alone. Phishing is still one of the easiest ways to capture credentials, session tokens and delegated access, which then affects human identity, NHI governance and downstream access control. The article’s starting point is typical of a workforce-risk benchmark: it measures behaviour rather than exploit mechanics, which is exactly what practitioners need for programme planning.


Key questions

Q: How should security teams reduce phishing risk without relying only on awareness training?

A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions. Awareness helps users spot obvious lures, but it does not stop impersonation that looks routine. The stronger model is to detect trust abuse across mail, identity, and workflow layers before approval or credential use occurs.

Q: Why do phishing attacks still succeed in well-defended environments?

A: They succeed because many environments protect the mailbox but not the business process behind it. Attackers only need one trust decision to stick, then they can exploit people, delegated approvals, or automation that accepts the email as proof of intent.

Q: What do security teams get wrong about phishing awareness training?

A: They often treat training as a replacement for technical containment. Awareness can reduce clicks, but it does not stop every mistake, especially under pressure or when attackers use convincing workflow-based lures. Training should be measured by lower incident impact, faster reporting, and fewer successful follow-on actions.

Q: Why do phishing incidents become identity incidents so quickly?

A: Because modern phishing often aims at credentials, session tokens, or approval workflows rather than just inbox deception. Once an attacker gets a trusted identity foothold, the response problem shifts from email filtering to account protection, session control, and preventing further abuse across connected systems.


Technical breakdown

Phishing-prone percentage as a behavioural risk metric

Phish-prone percentage, or PPP, measures the share of users who click a simulated phishing link before training or intervention. It is not a vulnerability score in the technical sense. It is a behavioural exposure indicator that helps security teams compare regions, business units and sectors. A high PPP tells you that a message can cross the human trust boundary before technical controls ever fire. That matters because modern phishing often targets credentials, OAuth grants, MFA fatigue and session capture, not just passwords. Used well, PPP supports risk segmentation rather than one-size-fits-all awareness campaigns.

Practical implication: use PPP as a control-tuning signal for awareness, reporting and access review priorities, not as a vanity metric.

Why AI-generated phishing changes the defence model

AI-generated phishing raises the quality floor of malicious email. The result is fewer obvious grammar mistakes, more contextual language and faster content variation at scale. That weakens the old assumption that users can spot fraud through writing style alone. It also puts pressure on secure email gateways and native platform defences, because message quality and delivery volume are both increasing. In practical terms, AI does not replace social engineering. It industrialises it, making repeatable human deception easier and cheaper for attackers. Security awareness now has to train recognition, verification and reporting behaviours together.

Practical implication: pair awareness training with stronger reporting paths and user verification steps for high-risk requests.

The identity bridge: phishing often ends in credential and token abuse

The identity impact of phishing is more important than the initial click. Once a user enters credentials, approves a prompt or authorises a malicious app, attackers can move from message delivery to identity abuse. That can include account takeover, delegated mailbox access, OAuth token theft and later use of those identities to reach SaaS, cloud and NHI-managed systems. For that reason, phishing resilience is part of identity governance, not just employee training. Controls such as phishing-resistant authentication, conditional access and rapid revocation matter because they reduce the value of the initial compromise.

Practical implication: treat phishing outcomes as identity events and connect awareness reporting to authentication and token revocation workflows.


Threat narrative

Attacker objective: The attacker wants to turn a single user interaction into durable identity access that can be reused for takeover, fraud or lateral movement.

  1. Entry occurs when the attacker delivers a phishing message that uses social engineering or AI-generated content to increase the chance of user interaction.
  2. Credential access follows when the user clicks, submits credentials, approves a prompt or grants a malicious application access to an account.
  3. Impact occurs when the captured identity is used for account takeover, delegated access or downstream fraud and data exposure.

NHI Mgmt Group analysis

Phishing remains an identity problem disguised as a human factors problem. The attack surface is not just the inbox. It is the sequence of trust decisions that lets a message become credentials, a token or an authorised application. That is why phishing benchmarks matter to IAM and NHI teams, not only to awareness leads. The practitioner lesson is to connect user behaviour data to identity controls.

AI-driven phishing creates a verification trust gap. The more convincing the message becomes, the less useful superficial content cues are. Teams need to shift from “can the user spot the phish” to “can the organisation verify the request path before access changes or approvals happen”. That framing aligns with phishing-resistant authentication and stronger confirmation workflows. The practitioner conclusion is to harden the path, not just the recipient.

South America’s high initial PPP is a reminder that training must be adaptive, local and continuous. A single campaign cannot close a behavioural gap that starts near 40% and only drops meaningfully after sustained reinforcement. Regional language, sector context and job-role targeting all matter. Generic annual training is too blunt for a risk profile that changes with attacker sophistication. The practitioner conclusion is to measure reduction over time, not completion rates.

Non-human identity governance is part of the phishing response chain. Phishing increasingly targets the identities that sit behind SaaS, cloud and AI workflows, including service accounts and delegated tokens. When a user or admin authorises a malicious action, the compromised object is often an NHI, not just a mailbox. That means revocation, lifecycle control and token hygiene belong in phishing response plans. The practitioner conclusion is to treat phishing as an access-control event across human and machine identities.

What this signals

Phishing programmes are now identity governance programmes in practice. If a user click can lead to delegated access, mailbox takeover or app consent, then awareness metrics need to be read alongside MFA resistance, consent controls and revocation speed. The organisations that will improve fastest are the ones that connect user reporting to identity response, not just security education.

AI-generated phishing is pushing teams toward verification-first workflows. That means stronger confirmation for payment changes, access grants and high-risk approvals, plus phishing-resistant authentication for the users most likely to be targeted. The control objective is not perfect detection. It is making the malicious message unable to become durable access before containment can happen.


For practitioners

  • Implement continuous phishing-reduction campaigns Move from annual awareness sessions to monthly or continuous reinforcement, using regional examples, role-specific scenarios and repeat measurement of click and report rates. Track the change in phishing-prone percentage over time, not just course completion.
  • Connect phishing reports to identity response Route user-reported phishing events into identity and access workflows so that suspicious logins, OAuth grants and mailbox delegations can be reviewed or revoked quickly. This shortens the window between user detection and access containment.
  • Prioritise phishing-resistant authentication for high-risk users Require phishing-resistant MFA for privileged users, finance teams and administrators who can approve access, delegate mail or create app consent. This reduces the value of credential harvesting even when an attacker gets a successful click.
  • Review delegated application consent paths Audit where users can authorise applications, grant mailbox access or approve third-party integrations. Restrict consent for high-risk scopes and add approval for sensitive permissions so a phish cannot easily become durable access.

Key takeaways

  • Phishing is still a primary route from human error to identity compromise, which makes it a governance issue as much as a training issue.
  • The benchmark data shows sustained training can reduce susceptibility dramatically, but only when it is continuous and measured as behaviour change.
  • Security teams should tie awareness, authentication and revocation together so a successful click does not become lasting access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BPhishing-resistant authentication is relevant where phishing leads to account takeover.
NIST CSF 2.0PR.AA-1Phishing resilience depends on identity proofing and authentication controls.
NIST SP 800-53 Rev 5IA-2Authentication strength matters when phishing targets credential reuse and session capture.
GDPRArt.32Where phishing exposes personal data, security of processing obligations become relevant.

Use phishing outcomes to test whether access controls and incident response meet security-of-processing requirements.


Key terms

  • Phish-prone percentage: Phish-prone percentage measures the share of users who click or otherwise respond incorrectly during simulated phishing tests. It is a behavioural metric that helps security teams baseline susceptibility, target training, and track whether awareness efforts are improving real-world judgment over time.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
  • Security Awareness: A programme that teaches people how to recognise and respond to common security risks. In identity security, awareness is only useful when it changes behaviour around authentication, verification, reporting, and safe handling of access requests. Message repetition alone does not create measurable risk reduction.

What's in the full report

KnowBe4's full report covers the operational detail this post intentionally leaves for the source:

  • Regional benchmark tables for South America by sector and company size, useful for comparing your own phishing-prone percentage.
  • The full before-and-after training curve showing how risk changes at 90 days and after one year.
  • Breakdowns of the highest-risk sectors and how continuous training affects susceptibility.
  • The AI-phishing findings that explain why message quality is now harder to use as a detection signal.

👉 KnowBe4's full report includes the regional benchmark detail, sector comparisons and training impact data behind the findings.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management and machine identity security alongside core IAM concepts. It is suitable for practitioners who need to connect identity controls to real-world compromise paths across modern security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org