High-Risk Users
SL-11Who is actually being targeted. Repeat encounters matter more than single ones, and a user flagged here who is also flagged by Access Assurance is the pattern that precedes credential misuse escalating into broad data access.
Detections grouped by campaign. Several users hitting the same infrastructure within a short window is a targeted campaign rather than opportunistic traffic, and it changes the response.
18 users
What to do with this list
Treat it as a targeting report, not a performance review. People who encounter more phishing are usually the ones whose role makes them worth targeting — finance, HR, privileged administrators. The proportionate responses are step-up authentication for correlated users, and a training campaign built from their own blocked encounters rather than from generic material.