Smishing Attack

All Employees · launched Sep 18, 2025

Participants
120
Opened message
82%
Clicked link
31%
Reported suspicious
19%
Submitted sensitive info
8%
Risk level
High

Department Breakdown

Opened / Clicked / Submitted, by team

Timeline

T+0h
Simulation launched to 120 Finance + AP staff
T+1h
First message opened (28%)
T+4h
First credential submission detected
T+12h
First user-reported phish via security inbox
T+48h
Simulation closed, debrief scheduled

Lessons learned

  • AP team most exposed — 41% click rate and 12% credential submission
  • Sender spoof technique bypassed default email gateway rules
  • Out-of-band callback verification not used in any failed case
  • Only 19% reported the simulated phish — below 30% target

Recommended follow-up training

Executive Deepfake & Fraud Defense
Finance / AP
AI Phishing & Deepfake Awareness
All Employees
AI Incident Reporting
All Employees