Phishing attacks are continuing to catch employees despite workplace security training, with a survey suggesting that many organisations still do not require multifactor authentication across all their systems.
The poll of 1,890 technology and security professionals found that 82% had received security training, while 23% said their employers did not make multifactor authentication (MFA) compulsory for every application and service. Despite that gap, 88% described their organisation as secure.
“The gap was not the awareness; it was the adoption,” said Poupak Modirassari Enbom, Yubico’s chief market and growth officer.
The survey was conducted by Talker Research between 2 and 16 July across nine countries. Those questioned worked in technology or security roles at companies with at least 500 employees. Yubico, which sells hardware security keys, and identity management company Okta announced a partnership alongside the findings, released on 7 October.
More than half of respondents, 55%, said they had been directly targeted by personalised phishing attacks. A further 44% said their organisation had suffered at least one successful AI-driven phishing attack in the previous year.
Lorrie Faith Cranor, director of Carnegie Mellon University’s CyLab, said security awareness did not guarantee that an employee would recognise every malicious request. A message could exploit a genuine need, such as finding a job, resolving an immigration issue or helping a manager.
“But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard,” she said.
Personalised phishing attacks test workplace defences
In one example described in a November 2025 Reddit post, a new employee said they had bought $800-worth of Target gift cards after receiving an email apparently sent by their boss. The request was presented as a surprise for office assistants, but the employee realised it was a scam before sharing the redemption codes.
Cranor said the risk faced by an individual depended on how often they were targeted, their security habits, their ability to identify suspicious messages and whether the request appealed to them. Distraction could also lead someone with good practices to make a mistake.
Traditional warning signs are becoming less dependable. While spelling mistakes may still expose some scams, Cranor said many phishing messages were now written with perfect grammar and designed to resemble a company’s style and branding.
In the survey, respondents were shown two HR emails asking employees to approve an updated handbook. One had been written by a person and the other by AI. Only 36% correctly identified the human-written message, while 54% believed the AI-generated email had been written by a person.
Multifactor authentication can limit the damage
The report recommends making stronger authentication part of the onboarding process. Some 52% of respondents said they were given username-and-password credentials when they began their roles, although the figure did not establish whether they also used MFA.
Passkeys use cryptographic credentials linked to a legitimate website, meaning they should not authenticate a login attempt on an imitation site. However, they protect access to an account rather than stopping an employee from carrying out a fraudulent instruction, such as buying gift cards.
Cranor said MFA offered substantial protection, but warned that its effectiveness depended on the method used. Text-message codes could be compromised if an attacker persuaded a mobile phone provider to transfer a victim’s number, while an impostor posing as a help-desk worker could ask for a code generated by an authenticator app.
“So it is important to never give anyone these codes,” she said.
Training remains useful, Cranor said, but should go beyond simply raising awareness. It should teach practical skills, allow employees to practise them and reflect the threats associated with different roles.
Employers should also require staff to verify unusual requests through a separate channel, particularly when a message appears to come from a senior colleague. Cranor said organisations needed to assess whether their training actually changed behaviour, rather than measuring only how many people had completed a video or course.
“They celebrate the number of people who have been trained or have watched their videos, but they rarely do controlled experiments to see whether the training actually protects people,” she said.
