From the
http://www.sptoolkit.com/ website:
"Researchers sent simulated phishing messages to employees at more than 3,500 small and midsize enterprises (SMEs) and found that recipients at nearly 500 companies, or 15 percent, clicked on a link contained in the message."(my 2cents) Of the 85% who did not click the link, 80% called the helpdesk to ask whether the message was safe to open and/or whether they should click the link.
The Simple Phishing toolkit looks like an intriguing project.