The average phishing click rate for untrained employees is 33.2%, measured across 67.7 million simulated phishing tests (KnowBe4 Phishing by Industry Benchmarking Report, 2026 edition). After a year of regular training and simulation, the same organisations average under 5%. On real attacks the average click rate is 3.4% (Proofpoint State of the Phish), and the median click happens 21 seconds after the email is opened (Verizon DBIR 2025). This page collects the benchmark numbers you need to judge your own results, with every source linked.
What is the average phishing click rate?
It depends on training maturity, and the spread is dramatic. Vendors name the metric differently: KnowBe4 calls it the Phish-prone Percentage (PPP), Proofpoint calls it failure rate, most platforms including PhishGrid just call it click rate. All of them measure the share of recipients who click a link, open an attachment, or submit credentials in a simulated phishing test.
| Population | Click rate | Source |
|---|---|---|
| Untrained employees (baseline test), global | 33.2% | KnowBe4 2026 |
| Untrained employees, 2025 edition | 33.1% | KnowBe4 2025 |
| Same organisations after 90 days of training | roughly 40% lower than baseline | KnowBe4 2025 |
| Same organisations after 12 months | under 5% | KnowBe4 2025/2026 |
| Real (non-simulated) phishing emails | 3.4% | Proofpoint State of the Phish |
| Trained users vs the hardest lure type | 7.4% | Hoxhunt 2026 |
The KnowBe4 dataset is the largest published benchmark: 67,718,305 simulations across 14.5 million users in 62,460 organisations over three years. Treat 33% as what an unprepared workforce does, not what yours must do. The gap between 33% and 5% is the measurable effect of a working programme.
Phishing click rate benchmarks by industry
Baseline (untrained) click rates vary by sector. Healthcare tops the table: high mail volume, shift work, and shared workstations leave little time to inspect senders.
| Industry | Baseline click rate (untrained) | Source |
|---|---|---|
| All industries, global average | 33.1% | KnowBe4 2025 |
| Healthcare and Pharmaceuticals | 41.9% | KnowBe4 2025 |
| Banking (1,000 to 9,999 employees) | 39.5% | KnowBe4 2025 |
| Insurance | 39.2% | KnowBe4 2025 |
| Financial Services (1,000 to 9,999 employees) | 38.4% | KnowBe4 2025 |
| Retail and Wholesale | 36.5% | KnowBe4 2025 |
| All industries, Europe average | 32.5% | KnowBe4 Europe 2025 |
What is a good phishing click rate?
A click rate of 3 to 5% on realistic simulations is the widely accepted target for a mature programme (KnowBe4 Phishing by Industry Benchmarking Report). Below that, difficulty is usually the variable to raise, not the number to celebrate: an easy test that nobody clicks proves nothing. Two better questions than “is my click rate low?”: is it falling quarter over quarter at constant difficulty, and is the report rate rising?
Report rate is the metric that predicts real outcomes. Proofpoint State of the Phish tracks a resilience ratio, reports divided by clicks: financial services leads at 8.23 reports per click, education trails at 1.27. Hoxhunt 2026 Phishing Trends Report data shows behaviour-change programmes produce a 6x improvement in reporting within 6 months and an 87% reduction in malicious clicks. And speed decides whether a report helps: the median click happens 21 seconds after open, the median report 28 minutes (Verizon DBIR 2025).
Which phishing emails get clicked the most?
Spoofed internal HR and IT announcements are the most clicked simulation theme, with a 7.4% failure rate even among trained users (Hoxhunt 2026 Phishing Trends Report).
AI-generated phishing jumped from about 4% to 56% of attacks reported to Hoxhunt’s network during December 2025, and holds near half of reported attacks in 2026 (Hoxhunt 2026 Phishing Trends Report).
80 to 95% of breaches begin with a phishing attack (Comcast Business, cited in Hoxhunt 2026 Phishing Trends Report), and a phishing-initiated breach costs an average of USD 4.88 million (IBM Cost of a Data Breach).
What phishing simulations actually test: inside a template library
Benchmarks only mean something if the tests behind them resemble real attacks. As a reference point, here is the composition of PhishGrid’s own simulation template library, 797 templates as of August 2026:
58% beginner, 38% intermediate, 3% advanced difficulty. That shape is deliberate: baselines and early rounds need believable but catchable lures, and only mature programmes need the near-perfect ones.
About 57% carry a link lure, still the dominant mechanic in real attacks, and roughly 1 in 10 spoof a sending domain to test whether people check the actual address.
The rest test attachments, credential forms, and reply-based lures, plus voice (vishing) and QR scenarios for channels email filters never see.
If you run simulations on another platform, audit its mix the same way. A library that is all easy lures flatters your click rate and hides your risk.
How to benchmark your own organisation
1. Run a blind baseline. One realistic test, no warning, no training first. Compare the result to the industry table above, not to the 3 to 5% target.
2. Fix the difficulty, vary the theme. Quarterly tests at constant difficulty make your trend line honest. Rotate themes so people can’t pattern-match the test.
3. Track three numbers. Click rate, report rate, and median time to report. The last two decide real-world outcomes.
4. Train the clickers immediately. The teachable moment is worth more than the annual course. KnowBe4’s data shows roughly 40% risk reduction within 90 days of starting.
You can run this entire loop free: our phishing email template library covers every difficulty tier in the mix above, the free phishing tools include the simulator and reporting analytics, and our guides to security awareness training and phishing awareness emails cover the follow-through.
Methodology and sources
Industry benchmarks on this page come from the largest published datasets: KnowBe4 Phishing by Industry Benchmarking Report (2025 and 2026 editions; 67.7M simulations, 14.5M users, 62,460 organisations), Verizon DBIR (2025), Proofpoint State of the Phish, Hoxhunt 2026 Phishing Trends Report (50M+ data points from 4M users), IBM Cost of a Data Breach, and Fortra 2025 Phishing Simulation Benchmark (14M recipients). PhishGrid library composition is computed from our template metadata as of August 2026 and describes test content, not customer results. We update this page when new report editions publish. Last update: August 2026.
FAQs
What percentage of employees click on phishing emails?
About 33% of untrained employees click in a baseline simulation (KnowBe4, 67.7M tests). On real attacks the average is 3.4% (Proofpoint). Organisations that train consistently for a year get simulation click rates under 5%.
What is a good phishing simulation click rate?
Under 5% on realistic, difficulty-consistent tests, with 3 to 5% the accepted target for mature programmes. A falling click rate at constant difficulty plus a rising report rate is the real sign of health. A near-zero rate on easy tests means the tests are too easy.
Does security awareness training actually reduce clicks?
Yes, and the effect is fast. KnowBe4 measured roughly 40% risk reduction within 90 days and up to 86% within a year across 62,460 organisations. Hoxhunt measured an 87% reduction in malicious clicks and a 6x improvement in reporting within 6 months for behaviour-change programmes.
Is click rate the right metric for phishing risk?
It’s necessary but not sufficient. Report rate and time to report predict real outcomes better, because a fast report lets your team kill a campaign before more people click. Proofpoint’s resilience ratio, reports per click, is a good single number: financial services averages 8.23, education 1.27.