Cybersecurity Insights & Tips Blog | Nimblr Security

Why Does Phishing Still Work in 2026?

Written by Nimblr Security Awareness | Sep 11, 2026

Phishing has been around for decades. So why are people still clicking?

During 2025, Nimblr analyzed 1,714 phishing simulations sent around 11 million times across 10 European countries. They generated approximately 420,000 recorded clicks.

The results point to something important: the problem isn't simply that employees don't know what phishing looks like.

Modern phishing works because it often looks like an ordinary part of the working day.

What phishing emails get the most clicks?

Across the 10 European countries in our analysis, one theme appeared consistently: HR.

HR-themed phishing simulations appeared among the five most-clicked scenarios in every country.

Holiday schedules. Employee surveys. Requests to update personal information. Messages asking employees to confirm leave.

IT-themed messages were another recurring category, including fake system notifications, calendar reminders, e-signature requests and encrypted-message notifications.

These messages work precisely because they don't look extraordinary.

They look like work.

A phishing simulation that got 33% to click

One simulation stood out: a Summer Holiday HR simulation.

In Denmark, 33% of recipients clicked. The same lure reached 26% in Lithuania and also appeared among the most-clicked simulations in several other countries.

But this wasn't simply an effective scenario invented for training.

We had seen the attack in the wild.

From real phishing attacks to realistic simulations

Nimblr operates a honeypot network that captures phishing emails from active criminal campaigns.

Across Europe, our honeypots began receiving emails claiming to come from HR and asking recipients to review summer holiday schedules or confirm leave dates.

We study these attacks and recreate them as safe phishing simulations, giving employees an opportunity to encounter the tactic before facing the real thing.

This matters because phishing isn't always easy to identify from spelling mistakes, strange formatting or an obviously suspicious sender.

Attackers mimic familiar business processes.

And some attacks go considerably further than simply stealing a password.

Can phishing bypass MFA?

Some phishing attacks use a technique known as adversary-in-the-middle (AiTM).

Instead of simply collecting a username and password, the phishing page sits between the victim and the legitimate login service.

The victim enters their credentials and completes the normal MFA process. The attacker can then capture the session token created after successful authentication and use it to access the account.

That doesn't mean MFA doesn't work. MFA prevents many attacks and remains an important security control.

But it isn't a complete defense against this type of phishing attack.

Why do people fall for phishing?

The answer has less to do with intelligence or technical knowledge than we might think.

Phishing exploits normal human behavior.

Urgency - Messages that demand immediate action encourage fast decision-making. When we're focused on resolving an urgent problem, we're less likely to stop and inspect the details.

Authority - We're accustomed to responding to HR, IT and management. A request appearing to come from one of these functions already carries a degree of trust.

Familiarity - "Confirm your holiday dates" sounds like a perfectly normal workplace task. That's precisely the point.

Distraction - Email is often checked between meetings, while doing something else or on a mobile phone where sender and link information can be harder to inspect.

These conditions favor quick, automatic decisions over careful analysis.

As Martin Karlqvist, Behavioral Specialist at Nimblr, puts it: "It just looks like Tuesday."

Security awareness needs to change behavior

Knowing what phishing is isn't the same as being prepared when a convincing message arrives.

Effective security awareness needs to go beyond transferring knowledge. People need continuous, realistic opportunities to practice and immediate opportunities to learn from their decisions.

But training is only part of it.

Security culture matters.

Organizations getting the most from security awareness don't treat phishing simulations as tests employees either pass or fail.

They discuss the results. Managers participate. Leadership gets involved. Employees are encouraged to report suspicious activity. Experiences and mistakes become opportunities for the organization to learn.

One Nimblr customer brought their first months of results into a company-wide event. Their CEO explained why the organization was running the program and even shared two simulations that had personally fooled him.

Instead of putting the focus on who had clicked, the organization made security awareness something everyone could discuss and learn from together.

Building a stronger security culture

Security awareness works best when it becomes part of how an organization operates rather than something the security team runs quietly in the background.

That means creating an environment where security is talked about.

Where leadership participates.

Where managers continue the conversation with their teams.

Where employees feel comfortable reporting suspicious activity and sharing experiences.

And where simulation results are used to learn and improve, rather than to identify who got something wrong.

Over time, the focus shifts away from individual mistakes and towards how the organization recognizes, discusses and responds to threats together.

That's what #StrongerTogether means to us.

Security isn't the responsibility of one person, one department or one security team. Building a strong security culture is a collective effort.

Why continuous practice matters

Culture alone isn't enough. People also need opportunities to practice.

A single annual training session can't recreate all the situations people encounter throughout a working year.

Phishing changes. The context changes. The lures change.

Continuous simulations expose employees to different scenarios, levels of difficulty and tactics over time. When learning happens directly after an interaction, the experience is connected to the situation that triggered it.

The aim isn't to create perfect employees who never click.

It's to build an organization that keeps learning, keeps talking and gets better at responding to security threats together.

Learn more: Why Phishing Still Works

Want to dig deeper into the data?

Join Nimblr on September 24 at 14:30 CEST for our live webinar, Why Phishing Still Works.

We'll explore findings from 11 million phishing simulations, look at attacks captured through our honeypot network, examine the behavioral psychology behind successful phishing and share what we're learning from organizations working to build stronger security behavior and culture.

Register: https://nimblrsecurity.com/webinar/why-phishing-still-works

Because when it comes to security, we're #StrongerTogether.