iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Phishing can affect employees’ confidence and stress levels, but the clearest direct evidence located is from a simulated campaign—not a study of lasting harm after real attacks. In a 2024 study at one large organization, employees who clicked a simulated phishing email reported significantly higher stress and lower confidence in their ability to spot phishing than employees who reported it. That finding is not a diagnosis, does not show how long the effects lasted, and should not make a click seem like proof of carelessness.
What employees may feel after a phishing incident
Phishing is social engineering: an attacker impersonates a person or organization the recipient may trust, trying to obtain sensitive information or network access. Messages can arrive by email, text, or telephone. A successful attempt may lead to a breach, data or service loss, identity fraud, malware, or ransomware. The uncertainty about what was exposed or what might happen next can reasonably be worrying, but the sources cited here do not measure the psychological impact of each of those outcomes on employees. CISA’s phishing infographic describes the threat and its possible consequences.
The most directly relevant evidence is Markus Schöps, Marco Gutfleisch, Eric Wolter, and M. Angela Sasse’s 2024 USENIX Security study, Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees’ Perception, Stress and Self-Efficacy. Researchers assessed 408 employees immediately after they clicked or reported a simulated phishing email and interviewed 21 employees. Those who clicked had significantly higher stress and significantly lower phishing self-efficacy than those who reported the message. Overall, participants generally viewed the simulation as positive and effective.
Here, self-efficacy means confidence in one’s ability to identify phishing. A lower score in that measure is not evidence of generalized incompetence or a permanent loss of confidence. The study concerns employees in one organization responding to a simulation; it does not establish clinical diagnoses, duration of effects, or the prevalence of lasting psychological injury among real-world victims. The authors call for further study of the relationship between simulated campaigns and perceived stress.
#1 Best Overall
Why a click is not simply a personal failing
Phishing messages are designed to exploit attention and workplace context. In a 2018 study, Emma J. Williams, Joanne Hinds, and Adam N. Joinson examined nine simulated spear-phishing emails sent to 62,000 employees over six weeks, alongside focus groups at a second organization. Authority cues were associated with a higher likelihood of clicking a suspicious link. The findings support considering message design and work conditions, rather than interpreting every click as a moral or character failing. The study is published in the International Journal of Human-Computer Studies.
A 2023 naturalistic simulation study by Nathan Beu and colleagues at a large organization found that fewer years of employment and lower employee satisfaction and loyalty predicted increasingly unsafe behavior in that simulation. These are predictors observed in that setting; they do not prove that shorter tenure or dissatisfaction causes victimization in every workplace. They do point to the value of accessible onboarding and security practices that fit the realities of employees’ work. The study appears in Computers & Security.
How managers should respond when someone clicks
The response after a click affects how quickly security teams can assess and contain a possible incident. CISA advises employees to report phishing to the appropriate security team and not forward the message to coworkers. Reporting helps responders determine whether an event is isolated and whether protections are needed to prevent wider impact.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallIn its 2025 guidance for state, local, tribal, and territorial governments, CISA says organizations should make it safe to report phishing even when an employee inadvertently downloaded malware or shared information. The guidance states: “A no-blame culture promotes quick action and reduces the chance of widespread damage.” That principle is useful beyond the audience addressed by the guidance. Read CISA’s Four Cybersecurity Essentials for SLTTs.
Applied to workplace incident handling, this means giving employees a simple reporting route, making clear that reporting is expected even after a mistake, responding privately and promptly, and telling the employee what containment steps are underway. These are practical applications of reporting guidance, not proven mental-health treatments. Avoid public shaming or turning an individual’s incident into a spectacle; the evidence supports attention to stress and confidence, but does not show that every simulation or incident harms every employee.
What phishing training can—and cannot—show
A 2019 field experiment involving more than 10,000 employees at a Dutch ministry compared information, simulated experience, and a combination of the two. Both information and simulated experience reduced the proportion of employees giving away a password, while combining them did not produce a larger impact in that study. This is evidence about password-disclosure behavior in that setting, not proof that a training format prevents distress or eliminates phishing risk. The findings are published in PLOS ONE.
For a workplace program, measure more than click rates: include whether staff report suspicious messages, whether reporting is easy even after a click, and whether employees understand the next steps. Use incident patterns to improve onboarding, message controls, and training around real working conditions. Share results constructively and privately, and consider checking employee stress and phishing self-efficacy when evaluating simulations. The studies cited do not establish a universally best training cadence or product.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What is not yet established
The evidence cited here supports a careful conclusion: in one 2024 simulated campaign, clickers reported more stress and less confidence in their ability to recognize phishing than reporters. It does not tell us how common clinical conditions are after real workplace attacks, whether effects persist, or how an individual employee will respond. Those outcomes should not be assumed or diagnosed from a click.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

