Get the latest tech news

Phishing training doesn't stop your employees from clicking scam links - here's why


A UC San Diego study found phishing training programs are basically useless, with employees just as likely to click scam emails whether or not they took training.

The study, conducted by UC San Diego Health and Censys researchers, found that phishing-related cybersecurity training programs had no effect on whether or not employees were duped by phishing emails. By crafting messages that inspire fear or urgency, cybercriminals hope that their victims will not take a step back and think rationally, but will, rather, panic-click a button or hand over sensitive information that can be used in identity theft, to conduct fraudulent transactions, or for use in broader cybercrime. "Taken together, our results suggest that anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value in reducing phishing risks," the researchers said.

Get the Android app

Or read this on ZDNet

Read more on:

Photo of employees

employees

Photo of phishing training

phishing training

Photo of scam links

scam links

Related news:

News photo

Many employees are using AI to create 'workslop'

News photo

US labor board drops allegation that Apple's CEO violated employees' rights

News photo

Many employees are using AI to create 'workslop,' Stanford study says