Skip to main content

Why employee activity on phishing emails in Riot doesn't look right ?

Understanding why the activity details in a Simulation email seem strange.

You may notice unusual activity on your Simulation campaigns: clicks or opens that look suspicious, abnormally high rates, or actions that don't match your employees' real behaviour. Or an employee may tell you they were caught when, on their side, they never clicked a link in a phishing email or entered their credentials.

Here is an example of suspicious behaviour:

Here we see unusual behaviour: several clicks on the link in the email, along with several opens of that email. Another suspicious sign is the employee's location, showing several different countries on the same day.

👉 The main cause: security bots and scanners

Many organisations use advanced security tools that automatically scan incoming emails to detect threats. These scanners:

  • open emails to analyse them;

  • click links to check where they lead;

  • download attachments to inspect them;

  • perform other automated actions.

In all likelihood, one of your own internal security tools is skewing the activity Riot displays on your Simulation campaign emails.

1️⃣ How this affects recorded activity

👉 Inflated open rates

Scanners open emails automatically. This artificially raises your open rate, because Riot records those actions as genuine employee opens.

👉 Inauthentic clicks

If your simulation contains links, scanners click them during their analysis. Those clicks are recorded in your statistics, creating false positives attributed to your employees.

👉 Skewed vulnerability rates

If your simulation is a phishing attempt with a credential form, scanners may interact with it. This distorts your real vulnerability rate, making your team look more "vulnerable" than it actually is.

👉 The gap between sending and the first interactions

Scanners act very quickly, often within the first few seconds after the email arrives. You will see near-instant clicks or opens, which is quite different from real employee behaviour.

2️⃣ How to identify the problem

👉 Look for suspicious activity patterns

  • Immediate clicks or opens, right after sending

  • Identical or repetitive interaction patterns (every employee reacting the same way)

  • Actions coming from unusual IP addresses, or outside your working hours

  • Excessively high open rates compared with your usual benchmarks

  • Activity that is too uniform (little variation between employees)

3️⃣ Solutions and good practice on your security tools

👉 Look at the detail rather than the aggregates

Instead of relying only on overall rates, look at the detailed logs for each employee. Watch for suspicious patterns or behaviour typical of a scanner.

👉 Filter out scanner interactions

If you can identify the IP addresses or domains of your security scanners, you can exclude them from your campaigns to get a truer picture of your employees' actual activity.

Did this answer your question?