Report by KnowBe4

Q1 2025 Phishing Report

9 FINDINGSPublished Apr 28, 2025
View Original Report →

Key Findings

Over 60% of top-clicked phishing emails were related to HR and IT.

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonationHRIT

People were more likely to click on links related to internal topics or impersonating known brands, accounting for 61.6% of clicks.

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonation

The top three QR codes scanned in simulations related to: A new drug and alcohol policy from HR (14.7%), A DocuSign for review and signing (13.7%), A Workday happy birthday message (12.7%).

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonationQR

In attachment-based campaigns, people were most likely to open certain file types: PDFs (53%), HTML files (28.5%), Word files (18.5%).

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonationPDFHTML

68.6% of clicked links involved domain spoofing.

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonationSpoofing

60.7% of the phishing simulations that were clicked mentioned an internal team.

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonation

Internal communications are a significant driver of phishing failures. Emails impersonating internal teams, particularly HR and IT, received the most failures in phishing simulations.

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingHRIT

49.7% of clicked phishing simulations mentioned HR.

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonationHR

In attachment-based campaigns, people were most likely to open certain file types: PDFs (53%), HTML files (28.5%), Word files (18.5%).

KnowBe4Q1 2025 Phishing Report·Apr 28, 2025
EmailPhishingImpersonationPDFHTML