Phishing has been around for decades, yet it remains one of the most effective and persistent cyber threats. Organisations have invested heavily in security awareness, email filtering, multi-factor authentication and advanced detection tools, but attackers continue to find ways through. The reason is simple: phishing does not just exploit technical vulnerabilities; it exploits human behaviour. A convincing message, a sense of urgency or a well-timed phone call can cause even a security-conscious employee to make the wrong decision.
So the question is no longer simply “How do we spot phishing?” It is “How do we prepare people and organisations to respond when convincing deception gets through?” That is where realistic, hands-on training can make a difference.
Phishing by the Numbers: A Threat That Refuses to Disappear
When it comes to phishing, the scale is difficult to ignore. Billions of phishing messages are estimated to be sent worldwide every day, while phishing consistently ranks among the most commonly reported forms of cybercrime. It is also a major initial access vector for attacks ranging from credential theft and business email compromise to ransomware and malware deployment. The latest data from the Anti-Phishing Working Group (APWG) shows that 971,181 phishing attacks were observed in Q1 2026, an increase of 13.8% compared with Q4 2025.
Verizon’s 2026 Data Breach Investigations Report, based on analysis of more than 22,000 security incidents and 12,000 confirmed breaches, found that phishing accounted for 15% of breaches overall. More significantly for organisations, Verizon reports that mobile social engineering attacks, including fake text messages and voice calls, achieved a 40% higher success rate than traditional email phishing, highlighting how attackers are increasingly moving beyond the inbox.
These figures tell an important story. Phishing is not disappearing as organisations strengthen their technical defences. Instead, attackers are adapting the channels, techniques and psychological triggers they use to reach their targets. The challenge, therefore, is not simply dealing with more phishing. It is preparing people to recognise and respond to increasingly convincing deception, wherever it appears.
Why Do Attackers Still Love Phishing?
From an attacker’s perspective, phishing remains attractive for a simple reason: it offers a highly scalable way to exploit trust. Rather than having to break through every technical defence, attackers can persuade a legitimate user to open the door for them. Here are the most common reasons behind phishing’s popularity:
It Exploits Human Psychology
Phishing works because it targets human behaviour, not just technical vulnerabilities. Urgency, authority, fear and familiarity can encourage people to act before they stop to verify a request.
Even security-conscious employees can make mistakes when an attack is convincing, contextual and well timed.
Attackers Only Need One Success
Phishing is highly scalable and relatively inexpensive. Attackers can target large numbers of people, while a single successful interaction may provide credentials, access, or the starting point for a larger attack. Defenders need to stop attacks consistently; attackers only need one success.
The financial consequences of that one success can be substantial. In 2024, European discount retailer Pepco Group reported that its Hungarian business had lost approximately €15 million following a phishing attack. The company said it was working with its banking partners and the police to recover the funds and subsequently launched a review of its financial controls and IT security. The incident is a powerful reminder that phishing does not need to compromise an entire organisation to cause serious damage. Sometimes, one convincing message and one successful decision are enough.
Phishing Is No Longer Just an Email Problem
Modern phishing extends across email, SMS, voice calls, social media, and collaboration platforms. Attackers can also combine channels, for example, following an email with a text message or phone call, making the overall deception more convincing.
Attackers Exploit Context and Trust
Attackers increasingly research their targets using publicly available information from company websites, social media and professional networks. Details about employees, projects, suppliers or events can then be used to create highly convincing, personalised messages.
AI: The Force Multiplier for Phishing
AI is making phishing faster, more scalable and harder to distinguish from legitimate communication. ENISA reports that large language models are increasingly being used to enhance phishing and automate social engineering, with AI-supported phishing reportedly accounting for more than 80% of observed social-engineering activity worldwide by early 2025.
For attackers, AI can automate tasks that previously required significant time and expertise, from generating convincing messages to adapting campaigns. It can also support more interactive forms of deception, including fraudulent chatbots and voice impersonation.
As a result, traditional warning signs are becoming less reliable. As AI continues to improve the quality and speed of deception, organisations need to prepare people not only to recognise threats, but to respond appropriately when a threat looks completely legitimate.
Why Traditional Phishing Awareness Training Falls Short
Security awareness training remains an important defence, but knowledge alone does not always translate into secure behaviour. Employees may understand the risks and still make mistakes when faced with a convincing message, time pressure, or competing priorities.
Traditional training methods, such as annual e-learning courses or occasional awareness campaigns, can improve understanding but rarely recreate the conditions of a real attack. A training module can explain what a suspicious message looks like; it cannot fully recreate the moment when an employee receives an apparently legitimate request and has seconds to decide what to do. This is why organisations increasingly need to move beyond awareness and focus on readiness: not only asking whether employees can recognise phishing, but whether they can make the right decisions when deception reaches them.
Cyber Range Training Changes the Outcome
Cyber range training gives organisations a controlled environment in which participants can experience realistic attacks, make decisions and see the consequences without real-world risk. Instead of simply identifying a suspicious message, participants can practise reporting it, investigating a potential compromise and responding as the situation develops.
For phishing, this creates an important connection between individual behaviour and the wider security response. A single user’s decision can become the starting point for an incident, while an effective response can limit its impact.
The value lies in practice and feedback. Participants can make mistakes safely, understand what went wrong and practise a better response, turning theoretical awareness into a capability they can apply under pressure. The goal is not to create people who never make mistakes. It is to build organisations that are better prepared when mistakes happen.
Phishing Will Evolve. Training Has to Evolve With It
Phishing is unlikely to disappear. Its low cost, scalability and ability to exploit human behaviour make it too effective for attackers to abandon. As AI and multi-channel attacks continue to evolve, organisations will face increasingly convincing forms of deception.
Technical controls and security awareness remain essential, but they cannot eliminate every successful interaction. The more realistic goal is to build an organisation that can recognise, respond to and contain phishing when it gets through.
This is where practical training makes a difference. Cyber range exercises allow organisations to move beyond theoretical awareness and test how people, processes and security teams respond to realistic attacks - including what happens after someone clicks. With CDeX, organisations can turn phishing from a topic discussed in training into a scenario that teams can experience, practise and learn from. You cannot predict when the next phishing attack will arrive. But you can prepare for what happens when it does.
Table of contents
