While phising your staff might be questionable,if it can increase awareness of this kind of cyber attack, then it's worth the embarrassment.
Here's the link to the Symantec report:
https://www.symantec.com/security-center/threat-report?inid=symc-home-page_ghp_to_security-center_threat-response