Phishing Statistics (2026): 40+ Data Points on Attack Volume, Financial Losses, and AI-Generated Threats

Phishing statistics 2026: attack volume, financial losses, AI-generated lures, and click rates from APWG, the FBI IC3, Verizon DBIR, IBM, KnowBe4, and Cloudflare.

Phishing was the single most common way attackers first broke into organizations in 2025, and each phishing-initiated breach cost an average of $4.8 million (IBM, Cost of a Data Breach 2025). The Anti-Phishing Working Group logged roughly 3.8 million phishing attacks across the year (APWG, Phishing Activity Trends 2025), while the FBI’s complaint center recorded 192,000 phishing and spoofing reports, more than any other crime type (FBI, IC3 2025 Internet Crime Report). Attacker tooling has also compressed: generative AI now cuts the time to write a convincing lure from about 16 hours to 5 minutes (IBM, Cost of a Data Breach 2025), and 82.6% of phishing emails already carry AI-generated content (KnowBe4 Threat Lab, 2025). This analysis consolidates data from IBM, the APWG, the FBI IC3, Verizon, KnowBe4, and 10 other primary sources to show where email and web phishing stand in 2026.

TL;DR

  • The APWG tracked roughly 3.8 million phishing attacks in 2025, up about 1% from 3.76 million in 2024 (APWG, Phishing Activity Trends 2025).
  • Phishing was the top initial-access vector, at an average breach cost of $4.8 million (IBM, Cost of a Data Breach 2025).
  • US phishing and spoofing losses rose about 208% year over year to $215.8 million (FBI, IC3 2025 Report).
  • Business email compromise drove $3.05 billion in US reported losses across 24,768 complaints (FBI, IC3 2025 Report).
  • The global average phish-prone percentage before training is 33.2% (KnowBe4, 2026 Phishing by Industry Report).
  • The median time to click a phishing link is 21 seconds; the median time to report one is 28 minutes (Verizon, DBIR 2025).
  • 82.6% of phishing emails now contain AI-generated content, up 53.5% year over year (KnowBe4 Threat Lab, 2025).
  • AI-generated phishing surged roughly 14x in December 2025, reaching 56% of detected attacks (Hoxhunt, Phishing Trends 2026).
  • Microsoft was the most impersonated brand in Q4 2025 at about 22% of attempts (Check Point Research, Q4 2025).
  • 62% of breaches involved the human element, up from 60% a year earlier (Verizon, DBIR 2026).
  • Cofense recorded one malicious email attack every 19 seconds in 2025, versus every 42 seconds in 2024 (Cofense, 2025).
  • Nearly 46% of analyzed emails failed DMARC authentication, leaving spoofing gaps (Cloudflare, 2026 Threat Report).

1. Phishing Attack Volume and Frequency

Raw volume held roughly flat year over year, but that masks a shift in cadence and concentration. The clearest sign of industrialization is speed: attackers now launch a malicious email every 19 seconds, more than double the pace of 2024 (Cofense, 2025). Quarterly totals swung hard in 2025, peaking in the spring before easing in the back half, yet the annual figure still edged past the prior year. Phishing also remains the most-reported crime type to US authorities by a wide margin, even as its share of confirmed breaches sits near 16%.

MetricValueSource
Phishing attacks tracked, 2025~3.8 million (up ~1% from 3.76M in 2024)APWG, Phishing Activity Trends 2025
Largest quarter, Q2 20251,130,393 attacks (up 13% from Q1)APWG, Phishing Activity Trends 2025
Q4 2025 volume853,244 attacks (down 4% from Q3)APWG, Phishing Activity Trends 2025
Malicious email attack cadence, 2025One every 19 seconds (vs every 42s in 2024)Cofense, 2025 Annual Report
Phishing/spoofing complaints (top-reported crime type)192,000FBI, IC3 2025 Report
Phishing as breach initial-access vector16%Verizon, DBIR 2026
Cyberattacks that begin with phishing (broad guidance)Over 90%CISA (rule-of-thumb figure)

Context note: treat the “over 90% of attacks start with phishing” figure as a broad awareness benchmark, not a precise breach statistic; confirmed-breach analyses put phishing’s share closer to 16% (Verizon, DBIR 2026). For the wider threat picture, see our cybersecurity statistics 2026 roundup.

2. The Financial Toll of Phishing

The cost story splits into two figures that both point up. A phishing-initiated data breach averaged $4.8 million in 2025, making phishing the costliest initial vector even though global average breach costs fell 9% (IBM, Cost of a Data Breach 2025). The United States remains an outlier on impact, where the average breach now exceeds $10 million. On the direct-fraud side, phishing and spoofing losses reported to the FBI jumped about 208% in a single year while complaint volume barely moved, meaning attackers are extracting far more per successful lure.

MetricValueSource
Average cost of a phishing-initiated breach, 2025$4.8 millionIBM, Cost of a Data Breach 2025
US average breach cost, 2025$10.22 millionIBM, Cost of a Data Breach 2025
Global average breach cost, 2025$4.44 million (down 9%)IBM, Cost of a Data Breach 2025
US phishing/spoofing reported losses, 2025$215.8 million (up ~208% YoY)FBI, IC3 2025 Report
US business email compromise losses, 2025$3.05 billion (24,768 complaints)FBI, IC3 2025 Report
US AI-enabled crime losses, 2025~$893 million (22,364 complaints)FBI, IC3 2025 Report

Outlier note: US phishing/spoofing losses rose from roughly $70 million in 2024 to $215.8 million in 2025 while complaint counts stayed near 192,000, so the increase reflects higher yield per attack, not more reports (FBI, IC3 2025 Report). See our data breach statistics 2026 roundup for the full cost breakdown.

3. The Human Element: Who Clicks and How Fast

Simulation data explains why phishing keeps working: roughly a third of untrained employees engage with a lure, and the ones who do act almost instantly. Before any training, the global average phish-prone percentage is 33.2%, and the median employee clicks a malicious link within 21 seconds of opening the email (KnowBe4, 2026 Phishing by Industry Report; Verizon, DBIR 2025). The gap between compromise and detection is the real exposure: users click in seconds but take nearly half an hour to report. Training closes the gap sharply, cutting susceptibility by about 79% over a year.

MetricValueSource
Global baseline phish-prone percentage33.2%KnowBe4, 2026 Phishing by Industry Report
Most vulnerable industry at baseline (Healthcare & Pharma)42.7%KnowBe4, 2026 Phishing by Industry Report
Large-enterprise baseline (10,000+ employees)39.5%KnowBe4, 2026 Phishing by Industry Report
Susceptibility reduction after 12 months of training~79%KnowBe4, 2026 Phishing by Industry Report
Breaches involving the human element62% (up from 60%)Verizon, DBIR 2026
Median time to click a phishing link21 secondsVerizon, DBIR 2025
Median time to report a phishing email28 minutesVerizon, DBIR 2025
Organizations hit by at least one successful phishing attack71%Proofpoint, State of the Phish 2024

Outlier note: KnowBe4’s 2026 benchmark analyzed 42 million phishing simulations across 14.8 million users at 64,000 organizations, and small firms under 250 employees started far lower at a 24.7% baseline (KnowBe4, 2026 Phishing by Industry Report).

4. AI Is Rewriting the Phishing Playbook

Generative AI removed the two tells defenders relied on for years: broken grammar and slow production. 82.6% of phishing emails now contain AI-generated content, and the time to draft a convincing lure fell from about 16 hours to 5 minutes (KnowBe4 Threat Lab, 2025; IBM, Cost of a Data Breach 2025). The shift accelerated late in 2025, when AI-written campaigns spiked to more than half of detected attacks in a single month. Attackers are also weaponizing AI inside the breach itself, most often for phishing and deepfake impersonation.

MetricValueSource
Phishing emails containing AI-generated content82.6% (up 53.5% YoY)KnowBe4 Threat Lab, 2025
AI-generated phishing surge, December 2025~14x (from under 5% to 56% of detected attacks)Hoxhunt, Phishing Trends 2026
Time to draft a convincing phishing email with GenAI5 minutes (from ~16 hours)IBM, Cost of a Data Breach 2025
Breaches involving attacker use of AI1 in 6IBM, Cost of a Data Breach 2025
Top malicious AI uses in breachesPhishing 37%, deepfake impersonation 35%IBM, Cost of a Data Breach 2025
MFA-bypass breaches using AiTM session-token theft80%Microsoft, Digital Defense Report 2025

Outlier note: voice-based AI fraud is escalating on a parallel track; our vishing statistics 2026 roundup covers voice-clone phone scams, which the FBI and Mandiant track separately from email phishing.

5. Beyond the Inbox: BEC, Quishing, and Smishing

Phishing is fragmenting across channels as email filters improve, and the money follows the format that dodges controls. Business email compromise remains the most financially destructive form: wire-transfer BEC attacks jumped 136% quarter over quarter in Q4 2025, with the average requested transfer peaking near $83,000 mid-year (APWG, Phishing Activity Trends 2025). Attackers deliberately calibrate amounts below approval thresholds, and they are moving into QR codes and text messages to bypass inbox scanning entirely.

MetricValueSource
BEC wire-transfer attacks, Q4 2025+136% quarter over quarterAPWG, Phishing Activity Trends 2025
Peak average BEC wire-transfer request, Q2 2025$83,099 (up 97% from Q1)APWG, Phishing Activity Trends 2025
Image-based / QR (quishing) phishing increase into 2025~400%APWG, Phishing Activity Trends 2025
Smishing and vishing share of breaches19%Verizon, DBIR 2025
US text-message scam losses, 2024$470 millionFTC, Consumer Sentinel Data
Malicious emails blocked from one AiTM kit (Tycoon 2FA), Oct 202513 million+Microsoft, Defender for Office 365
Ransomware intrusions beginning with phishing~18%Sophos, State of Ransomware 2025

Outlier note: because phishing is the on-ramp to ransomware and account takeover, its downstream cost is far larger than direct fraud alone; see our ransomware statistics 2026 and password security statistics 2026 roundups for the follow-on impact.

6. Brand Impersonation and the Authentication Gap

Attackers pick brands the way marketers pick keywords: whichever opens the most downstream access. Microsoft was the most impersonated brand in every quarter of 2025, appearing in about 22% of brand-phishing attempts, because a stolen Microsoft credential opens email, files, and single sign-on at once (Check Point Research, Q4 2025 Brand Phishing Report). The defensive gap is authentication: nearly half of analyzed email still fails DMARC, and most login traffic is now automated, letting spoofed messages and credential-stuffing bots ride through.

MetricValueSource
Most impersonated brand, Q4 2025Microsoft, ~22% of attemptsCheck Point Research, Q4 2025 Brand Phishing Report
Next most impersonated, Q4 2025Google 13%, Amazon 9%Check Point Research, Q4 2025 Brand Phishing Report
Quarters Microsoft ranked #1 impersonated brand in 2025All fourCheck Point Research, 2025
Emails failing DMARC authentication~46%Cloudflare, 2026 Threat Report
Logins using credentials already compromised elsewhere63%Cloudflare, 2026 Threat Report
Login attempts originating from bots94%Cloudflare, 2026 Threat Report
Phishing as top initial-access vector in IR engagements, Q1 2026Over one thirdCisco Talos, IR Trends Q1 2026

Outlier note: Cisco Talos reported phishing reemerged as the most-observed initial-access method in early 2026, reversing a period when stolen credentials led, which underscores how quickly the vector mix shifts quarter to quarter (Cisco Talos, IR Trends Q1 2026).

Summary: Phishing by the Numbers

MetricValueSource
Phishing attacks tracked, 2025~3.8 millionAPWG, Phishing Activity Trends 2025
Peak quarter, Q2 20251,130,393 attacksAPWG, Phishing Activity Trends 2025
Malicious email attack cadence, 2025One every 19 secondsCofense, 2025 Annual Report
Average phishing-initiated breach cost$4.8 millionIBM, Cost of a Data Breach 2025
Phishing share of breach initial access16%Verizon, DBIR 2026
Median time to click a phishing link21 secondsVerizon, DBIR 2025
US business email compromise losses, 2025$3.05 billionFBI, IC3 2025 Report
US phishing/spoofing losses, 2025$215.8 million (up ~208%)FBI, IC3 2025 Report
Global baseline phish-prone percentage33.2%KnowBe4, 2026 Phishing by Industry Report
Susceptibility drop after 1 year of training~79%KnowBe4, 2026 Phishing by Industry Report
Phishing emails with AI-generated content82.6%KnowBe4 Threat Lab, 2025
AI-generated phishing surge, Dec 2025~14xHoxhunt, Phishing Trends 2026
Most impersonated brand, Q4 2025Microsoft, ~22%Check Point Research, Q4 2025
Emails failing DMARC authentication~46%Cloudflare, 2026 Threat Report
Q4 2025 BEC wire-transfer attacks+136% QoQAPWG, Phishing Activity Trends 2025
MFA-bypass breaches via AiTM token theft80%Microsoft, Digital Defense Report 2025
Ransomware intrusions starting with phishing~18%Sophos, State of Ransomware 2025
Smishing/vishing share of breaches19%Verizon, DBIR 2025

Methodology and Sources

Data was gathered by aggregating figures from primary security reports, government complaint data, and vendor threat telemetry published in 2025 and the first half of 2026, prioritizing original datasets over secondary reporting and flagging any pre-2025 figure as most recent available.

Data watch: several cited sources publish on fixed cycles and will refresh soon. The APWG issues quarterly Phishing Activity Trends Reports, with the Q1 2026 edition expected mid-2026; IBM’s Cost of a Data Breach lands each July; Verizon’s DBIR arrives each spring; KnowBe4’s Phishing by Industry benchmark is annual; the FBI IC3 report publishes annually; and Check Point and Cloudflare update their brand-phishing and threat telemetry quarterly.

Last updated: July 16, 2026. We review and update this page quarterly as new data is published.

Try VoxBooster — 3-day free trial.

Real-time voice cloning, soundboard, and effects — wherever you already talk.

  • No credit card
  • ~30ms latency
  • Discord · Teams · OBS
Try free for 3 days