Participants
120
Opened message
82%
Clicked link
31%
Reported suspicious
19%
Submitted sensitive info
8%
Risk level
High
Department Breakdown
Opened / Clicked / Submitted, by team
Timeline
T+0h
Simulation launched to 120 Finance + AP staff
T+1h
First message opened (28%)
T+4h
First credential submission detected
T+12h
First user-reported phish via security inbox
T+48h
Simulation closed, debrief scheduled
Lessons learned
- AP team most exposed — 41% click rate and 12% credential submission
- Sender spoof technique bypassed default email gateway rules
- Out-of-band callback verification not used in any failed case
- Only 19% reported the simulated phish — below 30% target
Recommended follow-up training
Executive Deepfake & Fraud Defense
Finance / AP
AI Phishing & Deepfake Awareness
All Employees
AI Incident Reporting
All Employees