Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Repeat Phishing
Cyber Security

Repeat Phishing

← Back to Glossary
By NHI Mgmt Group Updated September 2, 2026 Domain: Cyber Security

Repeat phishing is a pattern where an employee repeatedly clicks suspicious messages, submits credentials, or otherwise interacts with deceptive content after earlier warnings. The behavior becomes more serious when the person has privileged access, handles sensitive data, or is being targeted by an active campaign. Context determines whether it is a coaching issue or a compromise signal.

Expanded Definition

Repeat phishing describes a recurring interaction pattern, not a single lapse. In security operations, it usually means the same individual continues to click, enter credentials, approve prompts, or respond to deceptive messages after prior warnings, simulations, or incident response coaching. The key distinction is that the risk is cumulative: repeated exposure can reflect weak awareness, poor message hygiene, fatigue, or an active compromise path that has not yet been contained.

Definitions vary across vendors and training platforms, but the term is most useful when it helps analysts separate isolated user error from an ongoing threat indicator. In a mature programme, repeat phishing is assessed alongside mailbox telemetry, authentication logs, endpoint signals, and help desk reports to determine whether the behavior is education-related or evidence of account targeting. The most common misapplication is treating every repeated click as a discipline issue, which occurs when teams ignore the possibility of credential harvesting or session hijacking.

Examples and Use Cases

Implementing repeat-phishing monitoring rigorously often introduces privacy, labour-relations, and process overhead, requiring organisations to weigh faster detection against the cost of careful escalation and user handling.

  • A finance employee clicks a fake invoice link twice in one quarter, prompting security to review whether mailbox rules or forwarded messages were changed.
  • An executive assistant submits credentials after a callback phishing email, then repeats the behavior during a later campaign, making the pattern more important than the individual incidents.
  • A help desk analyst receives multiple lures tied to password reset themes; the team correlates the events with sign-in anomalies rather than relying only on awareness training outcomes.
  • A privileged user repeatedly approves MFA prompts from unexpected locations, which may indicate push fatigue or an attacker testing access persistence.
  • Security teams compare user-reported incidents with broader controls from the NIST Cybersecurity Framework 2.0 to decide whether detection, response, or awareness controls need tightening.

Why It Matters for Security Teams

Repeat phishing matters because recurrence changes the risk model. A single click can be an awareness failure, but repeated engagement can reveal an identity-focused attack path, weak email filtering, unmanaged credentials, or a user who is exposed to high-volume targeting. For teams responsible for privileged access, cloud consoles, or sensitive data, the issue can quickly move from training to containment. That is especially true where an employee’s account can be used to reach non-human identities, shared admin tools, or downstream automation.

Security and governance teams need a consistent way to decide when repeat behavior should trigger coaching, when it should trigger a case review, and when it should be treated as a compromise signal. This is where logging, access reviews, and escalation criteria become essential rather than optional. Organisations often recognise the operational cost only after a second or third successful lure, at which point repeat phishing becomes an incident management problem, not just an awareness metric.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this term.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.ATCSF awareness and training outcomes frame repeated phishing as a people-risk signal.

Use training outcomes and reporting patterns to decide whether repeated clicks need coaching or escalation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 2, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org