Phishing was the single most common way attackers first broke into organizations in 2025, and each phishing-initiated breach cost an average of $4.8 million (IBM, Cost of a Data Breach 2025). The Anti-Phishing Working Group logged roughly 3.8 million phishing attacks across the year (APWG, Phishing Activity Trends 2025), while the FBI’s complaint center recorded 192,000 phishing and spoofing reports, more than any other crime type (FBI, IC3 2025 Internet Crime Report). Attacker tooling has also compressed: generative AI now cuts the time to write a convincing lure from about 16 hours to 5 minutes (IBM, Cost of a Data Breach 2025), and 82.6% of phishing emails already carry AI-generated content (KnowBe4 Threat Lab, 2025). This analysis consolidates data from IBM, the APWG, the FBI IC3, Verizon, KnowBe4, and 10 other primary sources to show where email and web phishing stand in 2026.
TL;DR
- The APWG tracked roughly 3.8 million phishing attacks in 2025, up about 1% from 3.76 million in 2024 (APWG, Phishing Activity Trends 2025).
- Phishing was the top initial-access vector, at an average breach cost of $4.8 million (IBM, Cost of a Data Breach 2025).
- US phishing and spoofing losses rose about 208% year over year to $215.8 million (FBI, IC3 2025 Report).
- Business email compromise drove $3.05 billion in US reported losses across 24,768 complaints (FBI, IC3 2025 Report).
- The global average phish-prone percentage before training is 33.2% (KnowBe4, 2026 Phishing by Industry Report).
- The median time to click a phishing link is 21 seconds; the median time to report one is 28 minutes (Verizon, DBIR 2025).
- 82.6% of phishing emails now contain AI-generated content, up 53.5% year over year (KnowBe4 Threat Lab, 2025).
- AI-generated phishing surged roughly 14x in December 2025, reaching 56% of detected attacks (Hoxhunt, Phishing Trends 2026).
- Microsoft was the most impersonated brand in Q4 2025 at about 22% of attempts (Check Point Research, Q4 2025).
- 62% of breaches involved the human element, up from 60% a year earlier (Verizon, DBIR 2026).
- Cofense recorded one malicious email attack every 19 seconds in 2025, versus every 42 seconds in 2024 (Cofense, 2025).
- Nearly 46% of analyzed emails failed DMARC authentication, leaving spoofing gaps (Cloudflare, 2026 Threat Report).
1. Phishing Attack Volume and Frequency
Raw volume held roughly flat year over year, but that masks a shift in cadence and concentration. The clearest sign of industrialization is speed: attackers now launch a malicious email every 19 seconds, more than double the pace of 2024 (Cofense, 2025). Quarterly totals swung hard in 2025, peaking in the spring before easing in the back half, yet the annual figure still edged past the prior year. Phishing also remains the most-reported crime type to US authorities by a wide margin, even as its share of confirmed breaches sits near 16%.
| Metric | Value | Source |
|---|---|---|
| Phishing attacks tracked, 2025 | ~3.8 million (up ~1% from 3.76M in 2024) | APWG, Phishing Activity Trends 2025 |
| Largest quarter, Q2 2025 | 1,130,393 attacks (up 13% from Q1) | APWG, Phishing Activity Trends 2025 |
| Q4 2025 volume | 853,244 attacks (down 4% from Q3) | APWG, Phishing Activity Trends 2025 |
| Malicious email attack cadence, 2025 | One every 19 seconds (vs every 42s in 2024) | Cofense, 2025 Annual Report |
| Phishing/spoofing complaints (top-reported crime type) | 192,000 | FBI, IC3 2025 Report |
| Phishing as breach initial-access vector | 16% | Verizon, DBIR 2026 |
| Cyberattacks that begin with phishing (broad guidance) | Over 90% | CISA (rule-of-thumb figure) |
Context note: treat the “over 90% of attacks start with phishing” figure as a broad awareness benchmark, not a precise breach statistic; confirmed-breach analyses put phishing’s share closer to 16% (Verizon, DBIR 2026). For the wider threat picture, see our cybersecurity statistics 2026 roundup.
2. The Financial Toll of Phishing
The cost story splits into two figures that both point up. A phishing-initiated data breach averaged $4.8 million in 2025, making phishing the costliest initial vector even though global average breach costs fell 9% (IBM, Cost of a Data Breach 2025). The United States remains an outlier on impact, where the average breach now exceeds $10 million. On the direct-fraud side, phishing and spoofing losses reported to the FBI jumped about 208% in a single year while complaint volume barely moved, meaning attackers are extracting far more per successful lure.
| Metric | Value | Source |
|---|---|---|
| Average cost of a phishing-initiated breach, 2025 | $4.8 million | IBM, Cost of a Data Breach 2025 |
| US average breach cost, 2025 | $10.22 million | IBM, Cost of a Data Breach 2025 |
| Global average breach cost, 2025 | $4.44 million (down 9%) | IBM, Cost of a Data Breach 2025 |
| US phishing/spoofing reported losses, 2025 | $215.8 million (up ~208% YoY) | FBI, IC3 2025 Report |
| US business email compromise losses, 2025 | $3.05 billion (24,768 complaints) | FBI, IC3 2025 Report |
| US AI-enabled crime losses, 2025 | ~$893 million (22,364 complaints) | FBI, IC3 2025 Report |
Outlier note: US phishing/spoofing losses rose from roughly $70 million in 2024 to $215.8 million in 2025 while complaint counts stayed near 192,000, so the increase reflects higher yield per attack, not more reports (FBI, IC3 2025 Report). See our data breach statistics 2026 roundup for the full cost breakdown.
3. The Human Element: Who Clicks and How Fast
Simulation data explains why phishing keeps working: roughly a third of untrained employees engage with a lure, and the ones who do act almost instantly. Before any training, the global average phish-prone percentage is 33.2%, and the median employee clicks a malicious link within 21 seconds of opening the email (KnowBe4, 2026 Phishing by Industry Report; Verizon, DBIR 2025). The gap between compromise and detection is the real exposure: users click in seconds but take nearly half an hour to report. Training closes the gap sharply, cutting susceptibility by about 79% over a year.
| Metric | Value | Source |
|---|---|---|
| Global baseline phish-prone percentage | 33.2% | KnowBe4, 2026 Phishing by Industry Report |
| Most vulnerable industry at baseline (Healthcare & Pharma) | 42.7% | KnowBe4, 2026 Phishing by Industry Report |
| Large-enterprise baseline (10,000+ employees) | 39.5% | KnowBe4, 2026 Phishing by Industry Report |
| Susceptibility reduction after 12 months of training | ~79% | KnowBe4, 2026 Phishing by Industry Report |
| Breaches involving the human element | 62% (up from 60%) | Verizon, DBIR 2026 |
| Median time to click a phishing link | 21 seconds | Verizon, DBIR 2025 |
| Median time to report a phishing email | 28 minutes | Verizon, DBIR 2025 |
| Organizations hit by at least one successful phishing attack | 71% | Proofpoint, State of the Phish 2024 |
Outlier note: KnowBe4’s 2026 benchmark analyzed 42 million phishing simulations across 14.8 million users at 64,000 organizations, and small firms under 250 employees started far lower at a 24.7% baseline (KnowBe4, 2026 Phishing by Industry Report).
4. AI Is Rewriting the Phishing Playbook
Generative AI removed the two tells defenders relied on for years: broken grammar and slow production. 82.6% of phishing emails now contain AI-generated content, and the time to draft a convincing lure fell from about 16 hours to 5 minutes (KnowBe4 Threat Lab, 2025; IBM, Cost of a Data Breach 2025). The shift accelerated late in 2025, when AI-written campaigns spiked to more than half of detected attacks in a single month. Attackers are also weaponizing AI inside the breach itself, most often for phishing and deepfake impersonation.
| Metric | Value | Source |
|---|---|---|
| Phishing emails containing AI-generated content | 82.6% (up 53.5% YoY) | KnowBe4 Threat Lab, 2025 |
| AI-generated phishing surge, December 2025 | ~14x (from under 5% to 56% of detected attacks) | Hoxhunt, Phishing Trends 2026 |
| Time to draft a convincing phishing email with GenAI | 5 minutes (from ~16 hours) | IBM, Cost of a Data Breach 2025 |
| Breaches involving attacker use of AI | 1 in 6 | IBM, Cost of a Data Breach 2025 |
| Top malicious AI uses in breaches | Phishing 37%, deepfake impersonation 35% | IBM, Cost of a Data Breach 2025 |
| MFA-bypass breaches using AiTM session-token theft | 80% | Microsoft, Digital Defense Report 2025 |
Outlier note: voice-based AI fraud is escalating on a parallel track; our vishing statistics 2026 roundup covers voice-clone phone scams, which the FBI and Mandiant track separately from email phishing.
5. Beyond the Inbox: BEC, Quishing, and Smishing
Phishing is fragmenting across channels as email filters improve, and the money follows the format that dodges controls. Business email compromise remains the most financially destructive form: wire-transfer BEC attacks jumped 136% quarter over quarter in Q4 2025, with the average requested transfer peaking near $83,000 mid-year (APWG, Phishing Activity Trends 2025). Attackers deliberately calibrate amounts below approval thresholds, and they are moving into QR codes and text messages to bypass inbox scanning entirely.
| Metric | Value | Source |
|---|---|---|
| BEC wire-transfer attacks, Q4 2025 | +136% quarter over quarter | APWG, Phishing Activity Trends 2025 |
| Peak average BEC wire-transfer request, Q2 2025 | $83,099 (up 97% from Q1) | APWG, Phishing Activity Trends 2025 |
| Image-based / QR (quishing) phishing increase into 2025 | ~400% | APWG, Phishing Activity Trends 2025 |
| Smishing and vishing share of breaches | 19% | Verizon, DBIR 2025 |
| US text-message scam losses, 2024 | $470 million | FTC, Consumer Sentinel Data |
| Malicious emails blocked from one AiTM kit (Tycoon 2FA), Oct 2025 | 13 million+ | Microsoft, Defender for Office 365 |
| Ransomware intrusions beginning with phishing | ~18% | Sophos, State of Ransomware 2025 |
Outlier note: because phishing is the on-ramp to ransomware and account takeover, its downstream cost is far larger than direct fraud alone; see our ransomware statistics 2026 and password security statistics 2026 roundups for the follow-on impact.
6. Brand Impersonation and the Authentication Gap
Attackers pick brands the way marketers pick keywords: whichever opens the most downstream access. Microsoft was the most impersonated brand in every quarter of 2025, appearing in about 22% of brand-phishing attempts, because a stolen Microsoft credential opens email, files, and single sign-on at once (Check Point Research, Q4 2025 Brand Phishing Report). The defensive gap is authentication: nearly half of analyzed email still fails DMARC, and most login traffic is now automated, letting spoofed messages and credential-stuffing bots ride through.
| Metric | Value | Source |
|---|---|---|
| Most impersonated brand, Q4 2025 | Microsoft, ~22% of attempts | Check Point Research, Q4 2025 Brand Phishing Report |
| Next most impersonated, Q4 2025 | Google 13%, Amazon 9% | Check Point Research, Q4 2025 Brand Phishing Report |
| Quarters Microsoft ranked #1 impersonated brand in 2025 | All four | Check Point Research, 2025 |
| Emails failing DMARC authentication | ~46% | Cloudflare, 2026 Threat Report |
| Logins using credentials already compromised elsewhere | 63% | Cloudflare, 2026 Threat Report |
| Login attempts originating from bots | 94% | Cloudflare, 2026 Threat Report |
| Phishing as top initial-access vector in IR engagements, Q1 2026 | Over one third | Cisco Talos, IR Trends Q1 2026 |
Outlier note: Cisco Talos reported phishing reemerged as the most-observed initial-access method in early 2026, reversing a period when stolen credentials led, which underscores how quickly the vector mix shifts quarter to quarter (Cisco Talos, IR Trends Q1 2026).
Summary: Phishing by the Numbers
| Metric | Value | Source |
|---|---|---|
| Phishing attacks tracked, 2025 | ~3.8 million | APWG, Phishing Activity Trends 2025 |
| Peak quarter, Q2 2025 | 1,130,393 attacks | APWG, Phishing Activity Trends 2025 |
| Malicious email attack cadence, 2025 | One every 19 seconds | Cofense, 2025 Annual Report |
| Average phishing-initiated breach cost | $4.8 million | IBM, Cost of a Data Breach 2025 |
| Phishing share of breach initial access | 16% | Verizon, DBIR 2026 |
| Median time to click a phishing link | 21 seconds | Verizon, DBIR 2025 |
| US business email compromise losses, 2025 | $3.05 billion | FBI, IC3 2025 Report |
| US phishing/spoofing losses, 2025 | $215.8 million (up ~208%) | FBI, IC3 2025 Report |
| Global baseline phish-prone percentage | 33.2% | KnowBe4, 2026 Phishing by Industry Report |
| Susceptibility drop after 1 year of training | ~79% | KnowBe4, 2026 Phishing by Industry Report |
| Phishing emails with AI-generated content | 82.6% | KnowBe4 Threat Lab, 2025 |
| AI-generated phishing surge, Dec 2025 | ~14x | Hoxhunt, Phishing Trends 2026 |
| Most impersonated brand, Q4 2025 | Microsoft, ~22% | Check Point Research, Q4 2025 |
| Emails failing DMARC authentication | ~46% | Cloudflare, 2026 Threat Report |
| Q4 2025 BEC wire-transfer attacks | +136% QoQ | APWG, Phishing Activity Trends 2025 |
| MFA-bypass breaches via AiTM token theft | 80% | Microsoft, Digital Defense Report 2025 |
| Ransomware intrusions starting with phishing | ~18% | Sophos, State of Ransomware 2025 |
| Smishing/vishing share of breaches | 19% | Verizon, DBIR 2025 |
Methodology and Sources
Data was gathered by aggregating figures from primary security reports, government complaint data, and vendor threat telemetry published in 2025 and the first half of 2026, prioritizing original datasets over secondary reporting and flagging any pre-2025 figure as most recent available.
- Anti-Phishing Working Group (APWG), Phishing Activity Trends Reports, Q1-Q4 2025 - apwg.org/trendsreports
- Federal Bureau of Investigation, IC3 2025 Internet Crime Report - ic3.gov
- Verizon, Data Breach Investigations Report (DBIR) 2025 and 2026 - verizon.com/business/resources/reports/dbir
- IBM, Cost of a Data Breach Report 2025 - ibm.com/reports/data-breach
- KnowBe4, 2026 Phishing by Industry Benchmarking Report and Threat Lab, 2025 - knowbe4.com
- Hoxhunt, Phishing Trends Report 2026 - hoxhunt.com/guide/phishing-trends-report
- Cofense, 2025 Annual State of Email Security report - cofense.com
- Cloudflare, 2026 Threat Report - blog.cloudflare.com/2026-threat-report
- Check Point Research, Q4 2025 Brand Phishing Report - blog.checkpoint.com
- Cisco Talos, IR Trends Q1 2026 - blog.talosintelligence.com
- Microsoft, Digital Defense Report 2025 and Defender for Office 365 telemetry
- Sophos, State of Ransomware 2025
- Proofpoint, State of the Phish 2024
- Federal Trade Commission (FTC), Consumer Sentinel Network data
- Cybersecurity and Infrastructure Security Agency (CISA) guidance
Data watch: several cited sources publish on fixed cycles and will refresh soon. The APWG issues quarterly Phishing Activity Trends Reports, with the Q1 2026 edition expected mid-2026; IBM’s Cost of a Data Breach lands each July; Verizon’s DBIR arrives each spring; KnowBe4’s Phishing by Industry benchmark is annual; the FBI IC3 report publishes annually; and Check Point and Cloudflare update their brand-phishing and threat telemetry quarterly.
Last updated: July 16, 2026. We review and update this page quarterly as new data is published.