Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Phishing risk in South America: are awareness controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: South America starts with a 39.1% phishing-prone percentage, the highest in the world, according to Knowbe4 research, but that falls to 18.2% after 90 days of training and 4.5% after a year, while AI-generated phishing now accounts for 82.6% of emails. The finding is clear: awareness programmes remain one of the few controls that can materially reduce human-driven exposure at scale.

NHIMG editorial — based on content published by KnowBe4: Relatório de benchmark de phishing por setor de 2025 para a América do Sul and related phishing trend analysis

By the numbers:

Questions worth separating out

Q: How should security teams reduce phishing risk without relying only on awareness training?

A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions.

Q: Why do phishing attacks still succeed in well-defended environments?

A: They succeed because many environments protect the mailbox but not the business process behind it.

Q: What do security teams get wrong about phishing awareness training?

A: They often treat training as a replacement for technical containment.

Practitioner guidance

  • Implement continuous phishing-reduction campaigns Move from annual awareness sessions to monthly or continuous reinforcement, using regional examples, role-specific scenarios and repeat measurement of click and report rates.
  • Connect phishing reports to identity response Route user-reported phishing events into identity and access workflows so that suspicious logins, OAuth grants and mailbox delegations can be reviewed or revoked quickly.
  • Prioritise phishing-resistant authentication for high-risk users Require phishing-resistant MFA for privileged users, finance teams and administrators who can approve access, delegate mail or create app consent.

What's in the full report

KnowBe4's full report covers the operational detail this post intentionally leaves for the source:

  • Regional benchmark tables for South America by sector and company size, useful for comparing your own phishing-prone percentage.
  • The full before-and-after training curve showing how risk changes at 90 days and after one year.
  • Breakdowns of the highest-risk sectors and how continuous training affects susceptibility.
  • The AI-phishing findings that explain why message quality is now harder to use as a detection signal.

👉 Read KnowBe4's phishing benchmark report for South America and AI-driven attack trends →

Phishing risk in South America: are awareness controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Phishing remains an identity problem disguised as a human factors problem. The attack surface is not just the inbox. It is the sequence of trust decisions that lets a message become credentials, a token or an authorised application. That is why phishing benchmarks matter to IAM and NHI teams, not only to awareness leads. The practitioner lesson is to connect user behaviour data to identity controls.

A question worth separating out:

Q: Why do phishing incidents become identity incidents so quickly?

A: Because modern phishing often aims at credentials, session tokens, or approval workflows rather than just inbox deception. Once an attacker gets a trusted identity foothold, the response problem shifts from email filtering to account protection, session control, and preventing further abuse across connected systems.

👉 Read our full editorial: Phishing benchmarks show awareness training sharply reduces risk



   
ReplyQuote
Share: