Consider the following scenario: A new employee, on their third day, receives an urgent email from “HR” requesting immediate login to complete onboarding documents. They click the provided link, unaware it leads to a phishing scam. This action instantly compromises your organization’s security.
Keepnet, a Human Risk Management Company, analyzed phishing risks among new hires in 237 randomly selected organizations out of 5,000 from various industries. This study, conducted from January 1 to December 31, assessed phishing susceptibility under strict ethical standards.
The 2025 New Hires Phishing Susceptibility Report by Keepnet indicates that new hires are 44% more prone to phishing and social engineering attacks than seasoned employees. This often-overlooked risk poses a significant financial threat to businesses.
The Hidden Cyber Risk of New Hires
It’s not that new employees are careless. In fact, they’re often enthusiastic and hardworking. But they’re also:
- Unfamiliar with internal systems and norms
- Overwhelmed with onboarding information
- Eager to follow instructions without questioning authority
- Still waiting for security training—or unaware of it
This makes them the perfect target for phishing campaigns. And cybercriminals know it.
In their first 90 days, 71% of new hires fail phishing simulations, compared to 49% of tenured staff. These are not just numbers—this is a pattern.
30% Phishing Risk Reduction After 90 Days: Organizations implementing adaptive phishing simulations and ongoing cybersecurity awareness training achieved an average 30% reduction in phishing risk for new hires after their first 90 days.
Real-World Examples of How New Hires Get Tricked
- CEO Impersonation Scam
A fake message from the CEO requests a wire transfer. A new hire, trying to act fast and help, transfers money without question. - Fake HR Login Portal
A new hire receives an email asking them to log in to complete onboarding. The link leads to a fake login page, stealing their credentials. - Vendor Invoice Fraud
Someone posing as a vendor requests urgent payment for an “unpaid invoice.” A junior finance staff member clicks without verifying.
These are not far-fetched. They happen every day. And without training, your new employees won’t know how to spot the danger.
The Cost of Inaction
Failing to address phishing risks during onboarding can expose individuals and organizations to significant security threats. It is important to implement proper measures early to prevent potential attacks and vulnerabilities.
- Data breaches and ransomware attacks
- Loss of customer trust
- Compliance violations and legal trouble
- Public relations disasters
- Downtime and financial loss
The good news? You can take control of this risk—before it turns into a crisis.
How to Secure New Hires
You can reduce phishing risk by up to 30% in the first 90 days through six key strategies:
1. Smart Segmentation
Automatically group new hires and high-risk users based on role, behavior, and risk level—no manual work required.
2. AI-Powered Security Awareness Training
Deliver hyper-personalized phishing simulations and cybersecurity awareness training tailored to each person’s job, region, and language, including an orientation course for new hires.
3. Real-Time Reporting & Response
Enable employees to report phishing with one click. Behind the scenes, Keepnet provides instant analysis and helps your IT team respond fast.
4. Gamified Learning
Employees earn points, badges, and rank on leaderboards. Gamification taps into motivation and boosts engagement.
5. Executive Dashboards
Link phishing data to business impact. Show real progress with metrics like fewer incidents, faster reporting, and improved behavior.
6. Security Behavior & Culture Program
Track phishing dwell time, training completion, and risky trends. Identify where more education is needed and intervene early .
Key Takeaways
Cybersecurity isn’t just about firewalls and antivirus software. It’s about people, and the moment they walk through the door.
Start training your new hires from Day One. Show them how to spot scams. Build a sense of responsibility. And protect your company from within.
Download the full report: https://keepnetlabs.com/reports/new-hires-phishing-susceptibility-report.






