ADVERTISEMENT

Half of workers still can’t spot a phishing scam, even when they think they can

New research shows most executives and staff think they can spot a phishing scam. Most of them are wrong.

Phishing, trap

Image by Cybernews.

Paulina Okunytė
Paulina Okunytė Senior Journalist
June 8, 2025 Updated: June 6, 2025 3 min read

Key phishing research numbers

  • 53% of all respondents failed to detect the phishing emails they were shown.
  • Executives were better at detecting legitimate emails from business messaging applications like Slack and password management applications like Dashlane: 58% on average, vs an average of 36% of non-executive employees.
  • 90% of executives said they are confident they could spot an AI scam, yet 66% struggled to detect it when put to the test.
  • Only 38% could identify the two legitimate emails in the test batch.
  • 47% missed red flags in a fake Google alert email
  • 57% fell for a bogus Google Sheets invitation.
  • 48% couldn’t see the issue with a scam Dropbox message, despite the sender using a fake URL.
  • Overall, most people were fooled by AI-generated scams: 64% of non-executive employees and 66% of C-Suite executives could not identify an AI-generated scam.

Methodology

Phishing scam Dropbox
A phishing scam impersonating Dropbox. Source: Dojo

AI scams are getting smarter. Humans are not keeping up

Phishing scam Google Alert
Phishing scam impersonating Google Alerts. Source: Dojo
ADVERTISEMENT
“Our research discovered that, on average, 56% of the UK workers surveyed could not detect the real emails from the phishing scams, with just half correctly defining the term ‘phishing’,”
said Naveed Islam, Chief Information Security Officer at Dojo.
Phishing scam Google Docs
Phishing scam impersonating Google Docs. Source: Dojo

Executives also fall for phishing emails

Phishing scam CEO email
Phishing scam impersonating an email from the CEO. Source: Dojo
vilius Gintaras Radauskas Ernestas Naprys Paulina Okunyte
Don’t miss our latest stories on Google News.
Add us as your Preferred Source on Google.

Human factor is key to overall cybersecurity

What can businesses actually do?

  • Train smarter: Go beyond annual security videos. Use realistic phishing simulations and teach employees to read email headers, not just spot bad spelling.
  • Stay humble about AI: Everyone thinks they can spot a deepfake, until they can’t. Assume every inbox is a threat vector.
  • Lock down email protocols: Use domain-based authentication (DMARC, SPF, DKIM) and ensure internal comms tools can’t be spoofed.
  • Protect the frontline: Admins, receptionists, and payment handlers see the most scam attempts. Give them the most support.
ADVERTISEMENT