70% of new hires click on phishing links within the first 3 months of employment – here’s how to stay safe
- Most phishing incidents happen before new employees even understand how internal systems work, report claims
- Security awareness should begin on day one, before the first email is even opened
- Hackers target uncertainty, and onboarding is full of it for eager, confused new hires
The first few months of employment are now one of the riskiest periods for enterprise cybersecurity, new research has claimed,
Keepnet’s 2025 New Hires Phishing Susceptibility Report found nearly three-quarters (71%) of new hires fall for phishing or social engineering attacks within their first 90 days on the job.
Often overlooked in onboarding workflows, this shortcoming suggests many organizations are not doing enough to prepare new staff for the reality of modern cyber threats.
Inexperience, urgency, and confusion drive early mistakes
The report, based on data from 237 companies, reveals new employees are 44% more likely to be deceived by phishing attempts than their longer-tenured colleagues.
Most incidents stem from a combination of inexperience, lack of familiarity with internal processes, and a desire to comply with instructions.
Common attack types include CEO impersonation, fraudulent HR portals, fake invoice requests, and technical support scams, many of which exploit this period of onboarding confusion.
The study also found phishing emails impersonating executives led to a 45% higher success rate among new hires compared to tenured staff.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
This gap demonstrates how even basic social engineering tactics can be disproportionately effective against employees who are still navigating organizational systems and norms.
Without dedicated and structured training, these early errors can create long-lasting security risks.
To tackle this issue, Keepnet recommends that organizations adopt a layered defense strategy tailored specifically for onboarding periods.
Organizations that adopted adaptive simulations and behavior-based training programs saw phishing risk drop by 30% after onboarding.
Traditional tools like the best endpoint protection, best FWAAS, and best FWAAS solution remain essential, but they are not enough on their own.
“Phishing attacks don’t wait for your employees to feel ready. Our research shows that organizations must invest in onboarding-specific cybersecurity awareness training. We’re proud to offer adaptive, scalable solutions that protect businesses from day one,” said Ozan Uçar, CEO, Keepnet.
You might also like
Most phishing incidents happen before new employees even understand how internal systems work, report claims Security awareness should begin on day one, before the first email is even opened Hackers target uncertainty, and onboarding is full of it for eager, confused new hires The first few months of employment are…
Recent Posts
- Tesla teases Cybercab with a built-in Starlink V5 antenna
- The wireless headset that gets hot-swappable batteries right
- Halliday’s New Smart Glasses Skip the Camera
- Geekom AX8 Max vs Geekom A9 Max: Which mini PC deal should you buy from $619?
- 5 questions to ask before choosing a robot lawn mower, according to a lawnbot exec
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023