Original research · SMARTFENSE

Human Risk Report: Spain, Italy and Latin America

What people actually do when faced with simulated phishing and ransomware attacks. Primary data from the SMARTFENSE platform, aggregated and anonymized, across a base of 700+ organizations in the region.

4M+ simulated attack emails sent 13,000+ campaigns 9 countries with a broad sample 2018-2026
The study

What is the Human Risk Report?

The Human Risk Report is a recurring SMARTFENSE study that measures how people in real organizations respond to simulations of phishing, ransomware and other social-engineering vectors. It is built from aggregated, anonymized platform data — no surveys, no self-perception — and lets you compare human risk by country, by sector and over time.

Human risk is the probability that people's behavior leads to a security incident. It is measured through observed conduct (opens, clicks, data submission, reports) and managed with awareness, simulation and continuous remediation.

Global results · phishing

How many people fall for a simulated phishing attack?

For every 100 simulated phishing emails delivered in the region, 41.5 are opened, 7.8 end in a click and 2.3 in submitting data on a fake form. Only 1.3 are reported to the security team. Put another way: 1 in 13 people clicks and 1 in 43 hands over their data.

The report rate is the metric that sets a mature organization apart: a person who reports turns an attack into an early warning.

3M+ sends · 9,000+ valid campaigns · over the dataset of 700+ organizations (2018-2026).

Trend 2018-2026

Does sustained awareness work?

Yes, and the data shows it clearly. The aggregate click rate fell from 13.8% in 2020 to 7.1% in 2026, a cut of nearly half. Over the same period a reporting culture was born: from 0% in 2020 to 2.8% in 2026. Organizations that sustain their program year after year reduce risk and gain early warnings.

YearSendsOpen rateClickReport
202035,000+36.5%13.8%0.0%
2021110,000+31.1%11.2%0.5%
2022350,000+43.0%9.5%0.6%
2023540,000+41.1%7.6%1.1%
2024620,000+39.2%6.9%0.9%
2025800,000+40.3%7.4%1.2%
2026 (partial)570,000+47.7%7.1%2.8%

2026 includes data through June. The years 2018-2019 are omitted from the table due to a small sample (under 15,000 annual sends) although they are part of the global aggregate.

-49%
in click rate between 2020 and 2026. Risk exposure was cut in half with sustained programs.
SMARTFENSE dataset
47.7%
open rate in 2026, the highest in the series. Lures hook more than ever, in line with the rise of AI-assisted phishing.
SMARTFENSE dataset
2.8%
report rate in 2026, twice that of 2025. Defensive behavior grows while clicks are kept in check.
SMARTFENSE dataset

The 2026 reading is the most revealing of the series. Emails achieve the highest open rate on record (47.7%), consistent with ever better-written lures in the age of AI-assisted phishing, and yet clicks do not follow that rise and reporting doubles. Attacks get better; trained people get better too.

Regional comparison

How does human risk vary by country?

Nine countries exceed 10,000 simulated phishing sends in the dataset. Italy records the highest click rate (10.6%) and Chile the lowest (5.4%). Panama leads the reporting culture (7.5%), followed by Peru (6.8%), both well above the regional average.

CountrySendsOpen rateClickData submittedReport
Italy85,000+53.6%10.6%2.6%1.2%
Ecuador80,000+46.6%9.3%2.6%3.4%
Colombia70,000+34.2%9.2%3.3%0.6%
Peru220,000+50.5%9.0%3.2%6.8%
Argentina1.3M+49.1%8.2%2.8%0.7%
Spain310,000+34.7%8.0%2.3%1.2%
Mexico220,000+25.4%7.9%0.7%0.2%
Panama40,000+21.9%5.5%1.1%7.5%
Chile620,000+31.3%5.4%1.5%0.7%

Only countries with 10,000+ sends. Argentina holds the largest sample (1.3M+ sends). Percentages over each country's total sends.

Sector comparison

Which sectors show the most human risk?

Energy leads the click rate (12.3%) and Transportation records the lowest (4.8%). Insurance combines a high click rate (9.3%) with the best sector report rate (6.1%).

SectorSendsOpen rateClickReport
Energy60,000+44.1%12.3%5.2%
Education20,000+48.3%10.7%0.0%
ICT55,000+40.5%9.8%1.2%
Insurance160,000+43.2%9.3%6.1%
Food50,000+35.6%8.8%0.9%
Public administration110,000+32.3%8.1%1.5%
Services990,000+53.5%8.0%0.4%
Banking/Finance570,000+31.9%7.7%2.5%
Healthcare160,000+48.1%6.7%0.1%
Industrial620,000+32.7%5.5%0.5%
Retail40,000+27.4%5.4%4.0%
Transportation35,000+45.1%4.8%0.5%

Only sectors with at least 5 organizations with data (anti-reidentification publication criterion). Percentages over the sector's total sends.

Simulated ransomware

And against simulated ransomware?

Ransomware simulations measure the download and opening of attachments that, in a real attack, would encrypt the machines. With 1M+ sends across 350+ organizations, 45% of emails are opened, 5.6% end in downloading the file and 2.9% in opening it. Reporting reaches 1.5%, slightly better than for phishing.

1M+ sends · 3,400+ valid campaigns · 350+ organizations (2018-2026).

Beyond the simulation

How do people respond to training?

The dataset also records behavior toward educational content. The signal is consistent: when content reaches the inbox, a significant share of the organization completes it.

43.0%
complete the training modules they receive. Over 17,000+ campaigns and 2.8M+ sends across 430+ organizations.
Training · SMARTFENSE dataset
52.4%
open the awareness newsletters. It is the program's best-reaching content, with 6M+ sends.
Newsletters · SMARTFENSE dataset
60.5%
pass the knowledge tests they start. Over 9,000+ campaigns across 360+ organizations.
Tests · SMARTFENSE dataset
Transparency

Methodology

Source and scope

  • Primary data from the SMARTFENSE platform, no surveys
  • 700+ organizations analyzed
  • Valid phishing campaigns over the 2018-2026 period
  • Simulated phishing includes vector variants such as qrishing (QR-code phishing)
  • Excludes multitenant instances managed by partners

Data quality

  • Test campaigns and demos excluded
  • Funnel consistency filters (campaigns with incoherent metrics are discarded)
  • Software-generated activity (sandboxes, gateways) excluded from the count
  • One interaction per person and campaign (last attempt)

Privacy and publication

  • Anonymized aggregates, with no identifiable person or organization data
  • Only sectors with 5 or more organizations with data are published
  • Only countries with 10,000+ sends are published
  • 2026 includes data through June (partial year)
Clean figures, not inflated

The figures exclude interactions generated by security software (sandboxes, gateways, scanners, link checkers). SMARTFENSE detects and filters these interactions automatically. In tools without that filtering, clicks and downloads tend to be inflated.

Free download

Download the full report as a PDF

The same data you see on this page, packaged for your committee: presentable charts, extended methodology and an executive summary. We send it to your inbox right away.

Your organization against the benchmark

Compare your human risk with your sector

In a demo we show you how to measure your organization's human risk with the same methodology as this report, and how to reduce it with a sustained program.