The Digital Whale

Privacy and security

Scams, phishing and what stops them

The two best randomised trials of phishing training found effects at or near zero, while reported US fraud losses reached record levels in 2025.

Two things are well established. Reported fraud losses are at record levels and are a fraction of the true total, because most victims never report. And the intervention almost every organisation buys — security awareness training with simulated phishing — has been tested in two large randomised trials and found to do close to nothing. An eight-month study of 19,500 employees found no significant relationship between annual training and phishing susceptibility; a Swiss trial of 4,554 employees found embedded training produced no significant fall in repeat clicking. What predicted clicking was the lure. That is the strongest evidence on the question, and it is uncomfortable for an industry that sells training. For a concrete commercial example of the monitoring category discussed here, see this overview.

Reported losses are records and also a small fraction of the total

The two US datasets, FTC consumer reports and FBI IC3 complaints, both hit new highs for 2025.

2026

US consumers reported $15.9 billion in fraud losses to the FTC in 2025, a record.

Direction: Increase. Strength of evidence: Strong.

Federal Trade Commission, testimony to the Joint Economic Committee, 2026About 3 million consumer fraud reports, US, 2025

Caveat Reported losses only, and the FTC's own June 2026 release rounds the same figure to $16 billion, so quote one version and note the rounding.

2026

The FBI's IC3 recorded $20.877 billion in reported losses for 2025, led by investment fraud at $8.648 billion, of which $7.2 billion was crypto-related.

Direction: Increase. Strength of evidence: Strong.

FBI Internet Crime Complaint Center, 2025 Internet Crime Report, 20261,008,597 complaints, US-skewed, 2025

Caveat Self-reported complaints with no verification of loss amounts, skewed toward US victims and crimes people know to report to the FBI.

The reporting rate changes how this should be read. Research cited by the FTC finds only 4.8% of mass-market fraud victims complained to a government body or the Better Business Bureau (FTC, 2026) — an order-of-magnitude indicator, not a precise rate. The agency's own correction is far larger.

2026

The FTC estimates the true cost of US consumer fraud in 2024 could be as high as $195.9 billion, over fifteen times the reported figure.

Direction: Increase. Strength of evidence: Mixed.

Federal Trade Commission, testimony to the Joint Economic Committee, 2026Modelled national extrapolation from survey-based reporting rates

Caveat An extrapolation, not a measurement — treat it as the scale of the gap rather than a total.

Imposter scams were the most-reported category for the fifth year running, with over a million reports and $3.5 billion in losses in 2025, while investment scams caused the largest losses at over $7.9 billion (FTC, 2026). Losses skew old: IC3 complainants aged 60 and over reported $7.748 billion in 2025, over a third of the total, though age is optional on those complaints (FBI, 2026).

The FTC's 2026 Data Spotlight records $2.1 billion lost to scams originating on social media in 2025, about eight times the $261 million reported in 2020, with Facebook the most-cited platform; attribution is victim-reported and some of the rise reflects better data capture. That fits what is known about who sees and shares false content online.

Two randomised trials found training close to useless

Security awareness training is a large industry whose published effectiveness figures come almost entirely from its own vendors. Two independent randomised trials exist, both run in real organisations, and both found effects near zero.

2025

Annual mandatory security training had no statistically significant relationship with phishing susceptibility, and embedded "teachable moment" training reduced click rates by only about 2 percentage points.

Direction: No detectable effect. Strength of evidence: Strong.

Ho, Mirian, Luo, Savage, Voelker et al., IEEE Symposium on Security and Privacy, 202519,500 employees, eight months, ten randomised phishing campaigns

Caveat A single organisation, UC San Diego Health, and the 2-point effect was not distinguishable from noise.

2024

Embedded training produced no statistically significant reduction in repeat clicking, 33.1% against 37.0% for the control, and deterrent notices without training performed comparably.

Direction: No detectable effect. Strength of evidence: Strong.

Lain, Jost, Matetic, Kostiainen, Capkun et al., ACM CCS, 20244,554 employees at a company of about 60,000, three simulated emails over six weeks

Caveat Six-week window, one company and possible contamination between colleagues; the fall in credential submission, 21.2% against 23.6%, was significant, so the effect is not literally zero.

These results come from different countries, sectors and research groups, and they converge: the training format the market standardised on does not measurably change who clicks. A plain warning notice in the Swiss trial worked about as well as the training product, suggesting any benefit comes from reminding people they are watched rather than from teaching them.

The commercial figures that contradict this are before-and-after simulation metrics from vendors' own customer platforms, with no control group. Claims of an 80% or 90% cut in click rates measure performance on the vendor's simulations, not real compromise.

What people click depends on the lure, not on the person

The UC San Diego study's most useful result is not about training.

2025

A fake vacation-policy email drew a 30.8% click rate against 1.82% for an Outlook password notice, and cumulative click rates across all ten campaigns rose from about 10% in month one to over 50% by month eight.

Direction: Increase. Strength of evidence: Strong.

UC San Diego / Ho et al., IEEE S&P 2025, 2025Ten simulated phishing campaigns across 19,500 employees

Caveat The 50% figure is cumulative across ten campaigns, not a per-email rate — calling it "half of employees click phishing emails" is a common error.

A seventeen-fold difference driven by subject matter dwarfs anything training achieved in the same population, and given enough attempts most people click something. That points defence towards technical controls and authentication that survives a stolen password rather than individual judgement.

Phishing is the most reported crime and not the most costly

Phishing and spoofing was the most-reported crime type to IC3 in 2025 with 191,561 complaints, ahead of extortion at 89,129 (FBI, 2026) — but complaint counts measure reporting propensity, not harm. In the UK's official statistics, phishing was the most prevalent attack type organisations identified, at 38% of businesses and 25% of charities in 2025 (DSIT, 2026): one of the few prevalence figures here from a probability sample rather than a vendor's own telemetry.

The short version

  • US consumers reported $15.9 billion in fraud losses to the FTC in 2025; the FBI's separate IC3 data recorded $20.877 billion, and the two overlap.
  • Only about one in twenty mass-market fraud victims reports to a government body or the Better Business Bureau, according to survey work cited by the FTC in 2026.
  • An eight-month randomised study of 19,500 employees found annual training had no significant effect on phishing susceptibility (Ho and colleagues, IEEE S&P 2025).
  • A Swiss randomised trial found embedded training did not significantly reduce repeat clicking, and a bare deterrent notice performed comparably (Lain and colleagues, ACM CCS 2024).
  • Each training trial ran in one organisation, so the finding is strong for those settings and untested elsewhere.