Your first few weeks at work probably look something like this: figuring out who’s who on Slack, which floor has the best snacks, and navigating the hundreds of emails piling up in the inbox. Then one catches your eye. It says “Congratulations!” You click, and a new message appears: “You failed the test,” along with an attached invitation to security training.
Ladies and gentlemen, welcome to the decidedly forgettable experience of falling for a phishing scam—or in this case, the simulation of one. The lesson is to be more careful next time. But what happens when the next message looks like it came from the boss, lands during a busy afternoon, and asks for something that sounds perfectly reasonable?
A new survey from Yubico and Okta highlights why employers need an answer beyond another training session. Of 1,890 technology and security professionals, 82% had received employer security training. Still, 23% said their organizations did not require multifactor authentication (MFA)—a login step beyond a password—across all applications and services. Despite this, 88% described their enterprise as secure. For employers, the question is what stands between a convincing scam and a compromised account when a worker misses the warning signs.
“The gap was not the awareness; it was the adoption,” Poupak Modirassari Enbom, Yubico’s chief market and growth officer, told Fortune.
Talker Research conducted the survey July 2–16 across nine countries, polling professionals in technology and security roles at companies with at least 500 employees. The results, released Oct. 7, reflect that population, rather than workers generally. Yubico, which sells hardware security keys, and Okta, which provides identity management services, announced a partnership alongside the survey.
Knowing the rules does not mean someone will catch every suspicious request, said Lorrie Faith Cranor, director of Carnegie Mellon University’s CyLab, and a co-founder of Wombat Security Technologies, a security awareness training company later acquired by Proofpoint. A scam can work because it addresses a real need like finding a job, resolving an immigration concern, or pleasing the boss.
“But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard,” Cranor told Fortune.
Hey, the boss needs a favor
In a November 2025 Reddit post, one person described buying $800 in Target gift cards on their second day at a new job after receiving an email impersonating their boss. The supposed assignment was to surprise office assistants.
“I’m very new to the company, so I’m still not entirely sure how things go there,” the poster wrote. They said they recognized the scam before sharing the cards’ redemption codes.
Cranor said a person’s risk depends on how often they are targeted, their security habits, their ability to recognize suspicious messages, and whether the lure really interests them. Even someone with good habits can simply be distracted, she added.
Over half (55%) of respondents in the survey also reported being directly targeted by personalized phishing attacks. Another 44% said their organization had experienced at least one successful AI-driven phishing attack in the previous year.
Some familiar warning signs are becoming less useful.
“Sure, there are still some simple phishing messages that you might spot by looking at typos, but a lot of phishing messages are written by AI agents with perfect grammar and spelling and they mimic corporate style and branding,” Cranor said.
The survey put that to the test. Respondents were shown two versions of an HR email asking staff to sign off on an updated handbook, one written by a person and one by AI. Only 36% correctly identified the human-written message, while 54% thought AI wrote it.
Protection for the moment someone slips
The report recommends building stronger authentication into onboarding. Some 52% of respondents said they received username-and-password credentials when starting their roles, though that does not establish whether they also used multifactor authentication. Passkeys use cryptographic credentials tied to a legitimate site, so they won’t authenticate a login on an imitation website. But that protection covers account access—it won’t stop someone from buying gift cards at a scammer’s request.
Cranor said MFA provides substantial protection, but its forms differ. Text-message codes can be vulnerable when an attacker persuades a mobile carrier to transfer a victim’s number to the attacker’s phone. Even an authenticator app can be undermined by deception. A scammer posing as a help-desk employee might ask someone to read out a code, then use it to access the account, she said.
“So it is important to never give anyone these codes,” Cranor said.
And yes, training does still matter. Cranor said it can raise awareness that anyone is a potential victim.
“This is a good start, but to be most effective, it also needs to teach concrete skills and give people practice in using them,” she said. She added that training should also address the threats relevant to different jobs.
Employers should also make checking a request part of the job. If a message appears to come from the boss but something feels off, Cranor said, workers should verify it through another channel before responding.
But employers also need to know whether their training works. Cranor said many efforts to educate employees and the public about scams have not been rigorously evaluated.
“They celebrate the number of people who have been trained or have watched their videos, but they rarely do controlled experiments to see whether the training actually protects people,” she said.
