That being said, I don't like these reports, because any time I get a phishing email I immediately load it up in a protected VM to see what it does, so it would count me as a victim. Since the page you go to isn't a real looking login page, you can't differentiate between those who fall for it and those who just clicked to see what it was.
You need to actually set up the fake page and see who puts in valid credentials to get a true report.