TL;DR: Security awareness training does little to change click or report rates against modern phishing, while browser-delivered attacks increasingly arrive through search ads, social media DMs, cloned AI service pages, and legitimate OAuth flows, according to Push Security and cited studies. The real control gap is at the point of execution: in the browser, where technical intervention can block compromise and educate users in context.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Why your training budget belongs in real-time browser security”.
By the numbers:
- A 2025 Purdue University study involving 12,511 employees found that anti-phishing training produced no significant effect on click rates or reporting rates.
- The Verizon DBIR 2025 found that employees trained within the last 30 days were 4x more likely to report phishing than those trained earlier.
- Push Security says 4 in 5 ClickFix payloads arrive via search engines, not email.
Key questions
Q: What breaks when phishing moves from email into the browser?
A: Training and email gateways lose much of their value when the lure is a search ad, cloned service page, or legitimate OAuth flow.
Q: Why do browser-based phishing attacks reduce the value of awareness training?
A: Because awareness programmes mostly teach people to recognise suspicious email patterns, while browser-based attacks increasingly use trusted domains, search results, and normal-looking service workflows.
Q: How should security teams defend against browser-in-the-browser phishing?
A: Focus on the full login journey, not just the URL.
Practitioner guidance
- Deploy browser-layer phishing blocking Use behavioural detection to stop fake login pages, cloned service pages, and malicious copy-and-paste events before credentials or tokens are entered.
- Instrument trusted-domain abuse Review how your stack handles search ads, social-media referrals, and legitimate domains that host malicious content, because reputation alone will miss that path.
- Recast awareness as supporting control Keep training for vocabulary and culture, but stop using completion as evidence that users can resist real-time browser attacks under pressure.
Bottom line: Modern phishing now exploits trusted browser contexts, which makes annual awareness training too slow and too abstract to stop the attack.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Browser trust has become the real phishing perimeter: awareness training was built for suspicious messages, not for attacks that execute inside search results, trusted domains, and consent flows. The control problem has moved from recognition to runtime intervention. Security leaders should treat the browser as the enforcement point where identity risk becomes real.
A question worth separating out:
Q: Should organisations keep investing in security awareness training for phishing?
A: Yes, but as a supporting control rather than the primary defence. Training helps with culture and vocabulary, but the article shows that real prevention needs runtime controls in the browser where the attack is executed and where identity data is actually exposed.
👉 Read our full editorial: Browser-based controls expose the limits of security awareness training