Most clicked phishing email subjects by category 2026

The most clicked phishing email subjects by category in 2025-2026: HR and payroll notices, IT help desk replies and shared-document alerts top the simulation data.

The most clicked phishing email subjects in 2025 and 2026 simulation data share one trait: they look like they came from inside your company. Payroll and HR notices, IT help desk replies and shared-document notifications top the lists - and KnowBe4's Q4 2025 data shows internal workplace topics appeared in 100% of the ten most-clicked subject lines.

TL;DR

Why this matters

Phishing simulations generate two kinds of data. Campaign volume - how many emails went out - tells you nothing. Clicks by category tell you which stories your people believe. That is the difference between a monthly phishing report nobody reads and a human risk report that changes what you train next.

The category data also changes how you read a click rate. A 6% campaign click rate split evenly across categories is noise. The same 6% concentrated in payroll and invoice subjects is a signal: your finance process has a trust gap that attackers know how to use.

What the 2025 data says

KnowBe4 publishes quarterly roundups of the most-clicked subject lines from millions of simulated phishing tests. The Q4 2025 report (data from October to December 2025) found:

The Q3 2025 report (July to September 2025) shows the same pattern with the subjects spelled out. The most-clicked subject line was "Google: Document shared with you", and the top ten also included MS Teams messages ("Strategic Planning", "Manager Trying to Reach You"), IT help desk replies ("IT Help Desk Info", "IT: Internet Report", "Possible typo") and a run of HR subjects: dress code, reimbursements, performance review, training past due and vacation.

The 2026 Phishing by Industry Benchmarking Report puts a baseline under all of it: without training, 33.2% of employees globally are likely to click a malicious email or comply with a fraudulent request - roughly one in three.

The subjects by category

Grouped from the published quarterly data:

CategoryExample subjects that rankedWhy it works
IT / help desk"IT Help Desk Info", "IT: Internet Report", "Possible typo", password reset noticesPeople are conditioned to obey IT and to act fast on anything that sounds like a fault
Document sharing"Google: Document shared with you"The most-clicked subject in Q3 2025 - cloud notifications arrive constantly, so one more feels normal
Internal messaging"MS Teams: Strategic Planning", "MS Teams: Manager Trying to Reach You"A manager's name in a subject line short-circuits scrutiny
HR / payrollHR: Dress Code, HR: Reimbursements, HR: Performance Review, HR: Training Past Due, HR: VacationHR messages are routine, personal and lightly policed - nobody suspects the leave policy email
Branded consumerMicrosoft was the most-impersonated brand at 25.2% of branded landing pages in Q3 2025Password-reset muscle memory does the attacker's work

The common thread is not urgency or greed - it is familiarity. The subjects that win look like the emails people already receive every day, from systems and departments they already trust.

How to use this in your programme

  1. Tag every simulation by category - IT, HR, finance, document sharing, internal messaging - not just by template name.
  2. Rank your own categories by click rate each quarter and compare against the published trends. Where your click concentration differs from the market data, your data wins.
  3. Match training to the top categories, not to a generic annual curriculum. If reimbursements and help desk replies are what your people click, that is what your next training module should cover.
  4. Re-run the winning categories as follow-up simulations after training, so you can show the click rate moving rather than asserting it did.
  5. Watch the personalisation factor. If your platform cannot merge company names, manager names and internal system names into templates, your simulations under-test the exact weakness the real attacks exploit.

The honest limitations

Simulation data measures clicks on simulated lures, not on real attacks. The published reports also skew toward KnowBe4's customer base - large, English-speaking and mostly US-headquartered - so an Australian workforce with different HR rhythms and a different vendor mix may shift the category rankings. Treat the published lists as a hypothesis your own campaign data should confirm, not as a substitute for it.

And the base rate matters: with 33.2% of untrained employees phish-prone, the first campaigns of any programme produce grim numbers by design. That is the point - the baseline is what makes the improvement measurable.

What to do next

Run a category-tagged campaign set against these five groups, then read the results as a ranking rather than a single percentage. If you want the mechanics, phishing simulations cover how automated campaigns, auto-remediation and coaching turns a click into a training moment - and human risk reporting shows how the results roll up into a score you can defend in a client meeting.

FAQ

What is the most clicked phishing email subject? In KnowBe4's Q3 2025 data it was "Google: Document shared with you"; in Q4 2025, the top two both contained the recipient's own company name. The pattern across both quarters is personalisation plus an internal, routine-looking topic.

Are HR emails really the most dangerous phishing category? They are the most clicked in aggregate - HR topics were referenced in 46% of the Q4 2025 top ten and half of a 2023 top-ten list. Dangerous depends on what the click leads to: credential theft, payment redirection or malware.

How often should we simulate the top categories? Monthly at minimum, rotating across the categories your own data ranks highest. A category that stopped getting clicked after training deserves a re-test one to two months later to confirm the change held.

Does clicking a simulated phishing email mean an employee is a risk? It is a data point, not a verdict. Repeat clicks in the same category identify a specific training gap; one click on a well-crafted personalised lure is close to the population baseline and is better treated as a coaching moment than a disciplinary event.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.