The state of the human firewall, in numbers.
The annual SimuPhish report. 2.1M employees. 38 countries. 75+ languages. The data we wish someone had given us when we started.
1,275%
Growth in attacks targeting employees since 2022
82s
Median time to click on a modern AI lure
47%
Average report rate inside SimuPhish customer base
75+
Languages our drills shipped in this year
Top findings
Four numbers that changed the playbook.
Voice deepfakes are now the second most common payload.
Up from sixth in 2024. The rise tracks the cost curve of consumer grade voice cloning tools.
Vendor invoice swap dominates finance team incidents.
78% of finance led incidents in 2025 traced back to a vendor identity swap, not a credential leak.
Arabic, Hindi, and Tagalog drills moved the needle most.
Localized content lifted report rates by 31 points on average across three of our biggest customers.
HDR Score has become a board level KPI.
92% of customers we surveyed now report HDR Score in their quarterly board pack. Up from 0% in 2023.
By region
Click rate vs report rate, 2025.
North America
Click
8.2%
Report
44%
EMEA
Click
6.7%
Report
52%
MENA
Click
9.4%
Report
38%
APAC
Click
7.1%
Report
49%
LATAM
Click
10.6%
Report
33%
