← All resources
Research

Why phishing awareness training doesn’t work

Most organizations rely on human awareness to stop phishing. The largest controlled study to date — and the rise of browser-in-the-browser attacks — show why that’s a losing bet.

Research · 6 min read · By SafeToOpen Research · January 2026

For two decades, the standard answer to phishing has been to train the human: annual modules, simulated phishing, “think before you click” posters. The assumption underneath all of it is that people are the firewall. The evidence increasingly says they aren’t — and the most effective modern attacks are built specifically to defeat the one habit training tries to instil.

The largest study to date barely moved the needle

In 2025, researchers at UC San Diego Health ran the largest controlled experiment yet on anti-phishing training: roughly 19,500 employees, ten campaigns, eight months, using a randomized design. [1] The results were bleak. There was no meaningful difference between employees who’d completed mandatory annual training and those who hadn’t. “Embedded” training — the just-in-time lesson shown the moment someone clicks — reduced the likelihood of clicking by about two percentage points. [2] And people got worse over time: about 10% clicked in the first month; by the eighth, more than half had clicked at least one lure.

~2%
The reduction in click-through delivered by embedded phishing training in a randomized trial of 19,500 employees. UC San Diego, 2025. [1]

The researchers’ own conclusion was blunt: as currently administered, none of the training approaches they tested were effective, and they recommended refocusing on technical countermeasures.

The gains that do appear tend to evaporate

Training vendors point to real reductions over a year of repeated practice, and that’s a fair counterpoint. [5] But independent reviews keep finding that improvements measured right after training fade within months — in one body of research, gains visible at four months had vanished by six. [3] As one researcher put it, our habits have more inertia than the nudges we receive. There’s a subtler risk too: training can breed overconfidence, which is the wrong instinct when the next lure is better than the last.

Even a trained workforce is fighting the clock

Verizon’s 2025 data put the median time from opening a phishing email to clicking at 21 seconds, and found roughly one in three who click go on to enter credentials. [4] A defense that depends on a tired human making the right call, in seconds, dozens of times a day, will eventually fail. The attacker only has to win once.

The technique that turns training against you: browser-in-the-browser

The single most repeated piece of phishing advice is “check the URL.” Browser-in-the-browser (BitB) attacks exist to make that advice worthless. Documented in 2022 by the researcher known as mr.d0x, a BitB attack draws a fake browser pop-up inside the real page using ordinary HTML, CSS and JavaScript. [5] When you click “Sign in with Google,” the attacker paints a pixel-perfect copy of that window — convincing title bar, padlock icon, and a legitimate-looking address bar showing the real domain. The address bar is just styled text. It can say anything.

The technique even defeats hovering to preview a link: a small script can show the genuine address on hover and ignore it on click. So the user does everything they were taught — checks the URL, sees the right domain, sees the padlock — and types their password straight to the attacker. This isn’t theoretical: BitB lures have stolen gaming accounts reportedly worth up to $300,000 and been folded into the toolkit of state-aligned groups. [6]

Catch the fake the eye can’t

A pixel-perfect BitB window beats every visual check. SafeToOpen analyses the page itself in real time — so the fake is caught even when it looks perfect.

How Browser Security works →

Awareness is a layer, not a control

Training isn’t worthless — a workforce that reports suspicious messages quickly genuinely helps. But human awareness can’t be the primary defense, because the human can always be fooled, the effect fades, and the best attacks are built to beat the exact checks we teach. The organizations getting this right shift weight to controls that don’t depend on a person being right in 21 seconds: phishing-resistant authentication, and detection that judges the page as it loads.

If you can’t train it away, measure it

Notice what the UC San Diego study actually is: a measurement. The only reason anyone knows that mandatory training barely moves the needle is that somebody ran the numbers instead of assuming. Most organizations do the opposite — they buy the training, tick the compliance box, and never find out what their people can really spot.

That gap is worth closing, and it is a different thing from training. Knowing that four in ten of your finance team can’t separate a real invoice from a fake one does not make them better at it. It tells you where your technical controls have to be strongest, what to put in front of your board, and whether anything you do next actually changes the number.

Our own free public quiz is a small illustration. Roughly nine in ten people who take it miss at least one question — and that is a self-selected audience who arrived at a page called “spot the fake” expecting to be tested, with no deadline and no busy inbox. The number inside a real working day is not going to be better.

Find out where you actually stand

Scam Check sends your people a short, timed, branded test built from real scam techniques — email, text, phone, QR and more — and scores it person by person. Nobody is tricked and nothing is disguised: people know they are being tested, and every answer is explained afterwards. The first campaign is free.

How Scam Check works →

Measurement is not a substitute for the controls. It is how you find out how much you are asking of them.

Frequently asked questions

The largest study to date found it barely reduces click rates, and the modest gains fade within months. It has value as a layer — but as the primary control, the evidence says no.

Because it competes with habit and workload. People click in rushed, routine moments — precisely the conditions training can't reach — and refreshers reset awareness only briefly.

Browser-in-the-browser attacks paint a fake address bar showing the legitimate URL — turning 'always check the address' against the person doing the checking. Trained users verify the fake and proceed confidently.

Because a test is a measurement, not a lesson. It tells you how exposed you are and where — which teams, which channels — so you can put technical controls where the risk actually sits, and check later whether anything changed. The UC San Diego researchers only know training failed because somebody measured. Scam Check does that measurement without tricking anyone: people know they are being tested, and every answer is explained.

Stop relying on a perfect eye

Nobody spots every fake, every time. Start by finding out how exposed you are — then let detection carry the seconds a person can’t. The first Scam Check campaign is free.

Sources

  1. UC San Diego, Cybersecurity Training Programs Don’t Prevent Employees from Falling for Phishing Scams (2025) \1
  2. HR Dive, Employees don’t learn anything from phishing training, research says (2025) \1
  3. Cybersecurity Dive, Why security awareness training doesn’t work (2025) \1
  4. Verizon, 2025 Data Breach Investigations Report, via Stingrai \1
  5. mr.d0x, Browser In The Browser (BITB) Attack (2022) \1
  6. NordLayer, What Is a Browser-in-the-Browser Attack? (real-world cases) \1

External statistics are attributed to their original publishers and were accurate at the time of writing. Figures from industry reports vary by methodology and period; we link to primary sources so you can verify them.

Could you spot the fake?

Put this into practice: 12 real-world scams and genuine messages, two minutes, no sign-up.

12 examples · 2 minutes
Warm-up question
Parcel Delivery
SMS · just now

Your package is on hold. A redelivery fee of $1.99 is required: parcel-redeliver.info/pay

Correct — it’s a scam.
It got you — this one’s a scam.
  • A fee to release a parcel — couriers don’t do this
  • The link isn’t the courier’s real domain
  • Urgency: pay now or lose the package

That was the warm-up. 12 more are waiting.