Why Phishing Training Fails to Stop Attacks
A study from UC San Diego Health ran nearly 20,000 employees through ten simulated phishing campaigns over eight months. Training made almost no difference. Employees who had recently completed mandatory cyber awareness courses failed phishing tests at virtually the same rate as those who had not. The measured improvement was just 1.7%. More than 75% of employees spent less than a minute on the training material.
Millions are spent on annual training. The phishing success rate stays the same.
The lesson is clear. Training alone does not protect enterprises from phishing.
AI Has Made Phishing Impossible to Spot
Generative AI has fundamentally changed what phishing looks like. A convincing spoofed login page that once required hours of design work can now be generated in under a minute. The fake site is visually indistinguishable from the real one. The URL uses look-alike characters that pass a quick glance. The phishing email reads as if it came from the organisation’s own IT department.
Security training is built on the assumption that phishing attacks have tells. Misspelled words, suspicious senders, unusual URLs. Those tells no longer exist at scale. AI removes them before the email is sent. Asking employees to detect what cannot be detected is not a training problem. It is an architecture problem.
Why a Phishing-Aware Employee Is Still Vulnerable
Even an employee who recognises a phishing attempt and refuses to click can still be exploited by a colleague who does not. One compromised credential is enough for an attacker to gain a foothold.
But the more significant problem is what happens after the click. Modern phishing kits operate as real-time relay proxies. When an employee enters credentials on a fake site, the attacker’s server forwards them to the real service. The real service responds with an MFA challenge. The fake site mirrors that challenge back to the employee. The employee completes it. The attacker captures the authenticated session.
A phishing-aware employee who follows every instruction in their awareness training can still be the entry point for a breach, as long as their MFA can be relayed. The training addressed the detection problem. The relay attack bypasses it entirely.
Legacy MFA Fails the Moment One Employee Clicks
SMS codes, push notifications and authenticator apps all fail against relay attacks. Each one relies on the user completing a challenge. None of them verify whether the site requesting that challenge is the legitimate one.
An attacker running a relay proxy does not need to break MFA. They just need the employee to complete it. The challenge is proxied through in real time. The response is forwarded immediately. The attacker holds a valid authenticated session.
This is not a theoretical vulnerability. Groups like Scattered Spider used exactly this method to breach Fortune 500 companies, defeating MFA without breaking any authentication controls.
What Actually Stops These Attacks
The training failure and the MFA relay problem share the same root cause. Both depend on a human making a correct judgment in a moment of uncertainty. Phishing-resistant authentication removes that dependency.
TokenCore devices require a live fingerprint match before any authentication is possible. Each credential is cryptographically bound to the domain it was created for. A relay proxy cannot complete a Token authentication because the domain does not match. There is nothing for an employee to approve, relay or hand over.
Even if an employee clicks every phishing link they receive, a TokenCore device gives an attacker nothing to work with.
FAQs
Does security awareness training actually stop phishing attacks?
Training improves awareness, but it doesn’t stop phishing. Research shows employees still fall for modern attacks even after repeated training. Attackers now use advanced phishing kits that capture MFA codes and relay push approvals in real time. Stopping these threats requires phishing-resistant, biometric, and proximity-based authentication instead of passwords, phones, or codes.
Why does legacy MFA fail against phishing and relay attacks?
Legacy MFA depends on shared secrets like OTPs, SMS codes, or push approvals that can all be intercepted or relayed. Attackers trick users into approving access on spoofed pages, which completes a valid login for the attacker. Phishing-resistant authentication, like Token’s identity assurance, binds each login to the legitimate domain and requires biometric presence, blocking relay attacks automatically.