Home » Phishing Statistics 2026: Key Data, Trends, and Emerging Threats

Phishing Statistics 2026: Key Data, Trends, and Emerging Threats

Over 3.8 million phishing attacks were recorded globally in 2025 – and the average breach triggered by a phishing email now costs organizations $4.88 million. For security teams, CISOs, IT administrators, and business leaders, these numbers are no longer background noise: phishing is the most reported cybercrime in the United States and the primary delivery mechanism for ransomware, credential theft, and business email compromise. This article compiles 50+ verified phishing statistics from authoritative sources including APWG, IBM, the FBI IC3, Verizon DBIR, KnowBe4, and Proofpoint, organized into a clear taxonomy to help organizations understand scale, cost, targets, and defenses in 2026.

Key Phishing Statistics for 2026

The following figures represent the most important data points across the full phishing landscape:

Global Phishing Volume Statistics

Phishing activity in 2025 stayed at historically elevated levels – the second-highest annual count on record. After peaking at 4.7 million attacks in 2022 and declining slightly in 2024, attack volume climbed again in 2025, driven by AI-assisted campaign generation and the proliferation of Phishing-as-a-Service (PhaaS) kits.

Quarterly Phishing Attack Volume 2024-2025

Phishing Costs and Financial Impact Statistics

The financial consequences of phishing extend well beyond the initial breach – they include forensic investigation, business disruption, notification costs, regulatory fines, and reputational damage. The numbers in 2025 reflect a threat with direct P&L implications.

Broad Phishing Breach Costs vs Targeted BEC Demands 2025
  • Wire transfer BEC attacks in Q4 2025 increased 136% compared to Q3 2025, driven largely by threat group “Scripted Sparrow,” which sends an estimated 6 million targeted emails monthly, per the APWG Q4 2025 Phishing Activity Trends Report (January 2026).
  • In 2024, the FBI IC3 received over 21,442 BEC complaints, with total reported losses of $2.77 billion, per data cited in Verizon’s 2025 DBIR analysis by Keepnet (May 2025).
  • Organizations extensively using AI and automation in breach prevention saved an average of $2.2 million per breach compared to those without such tools, according to IBM’s 2025 Cost of a Data Breach Report.

What Industries Are Most Targeted by Phishing?

No sector is immune, but phishing campaigns concentrate in industries with high transaction volumes, valuable credentials, and large user bases. The sector rankings shifted throughout 2025 as attackers adapted tactics.

Most Targeted Industries by Phishing Share Q2 2025
  • Manufacturing was the sector most often attacked with malicious QR codes in Q3 2025, with 74,054 detections, per the APWG Q3 2025 Phishing Activity Trends Report (December 2025).
  • Social engineering accounts for 16% of Educational Services breaches, and 77% of those social engineering breaches were caused by phishing, per Verizon’s 2025 DBIR (2025).
  • Phishing was the fifth most common action in manufacturing data breaches, accounting for nearly one-fifth (19%) of incidents, per Verizon’s 2025 DBIR cited by Secureframe (August 2025).
  • Finance, Retail, and Federal sectors were the three most consistently targeted by social media-based phishing threats throughout 2025, per ZeroFox data in APWG Q4 2025 (January 2026).
  • The financial services sector showed the highest phishing simulation reporting rate at 32.35%, while education had the lowest at 7.71%, per Proofpoint’s 2025 phishing test data (April 2025).

Brand Impersonation Statistics

Attackers consistently exploit the trust users have in well-known brands. The most impersonated brands change quarter to quarter, but technology companies and delivery services dominate.

Brand

Phishing Share (Avg)

QR Phishing Target Rank

Primary Industry

Microsoft

22% – 51.7%

High (#2)

Technology / SaaS

Google

9% – 13%

Moderate

Technology / SaaS

Amazon

3% – 9%

Moderate

eCommerce / Retail

Apple

6% – 12%

Low

Technology / Hardware

Facebook (Meta)

3% – 14.5%

Moderate

Social Media

DHL

1% – 2%

Very High (#1)

Logistics / Shipping

Walmart

(Leading Q3 ’25)

Moderate

eCommerce / Retail

PayPal

2% – 3%

Moderate

Financial Services

AI-Powered Phishing Statistics

The weaponization of generative AI has fundamentally changed phishing’s threat profile. AI enables attackers to produce high-volume, high-quality, personalized campaigns at a fraction of the previous cost and effort.

AI Phishing Effectiveness vs Human Attackers 2023-2025
  • AI-generated phishing emails achieve a click-through rate of 54%, matching performance of emails crafted by human experts and outperforming control groups by 350%, per a 2024 study cited by NordVPN’s 2026 Phishing Statistics (January 2026).
  • 86% of organizations have encountered at least one AI-related phishing or social engineering incident, per Bright Defense’s Phishing Statistics 2026 (February 2026).
  • A single threat intelligence database misses 15–30% of threats, highlighting why AI-assisted multi-source detection is now necessary, per analysis from CaptainDNS phishing trends analysis (February 2026).

QR Code Phishing (Quishing) Statistics

QR code phishing bypasses traditional email security filters because the malicious link is encoded in an image, not text. This technique surged throughout 2025.

QR Code Detections by Quarter

Business Email Compromise (BEC) Statistics

BEC sits at the intersection of phishing and fraud. Unlike broad phishing campaigns, BEC is precision-targeted – impersonating executives, vendors, or partners to authorize fraudulent transfers.

BEC Scam Type Distribution Q1 2025
  • Pretexting incidents have nearly doubled, now accounting for over 50% of all social engineering incidents, per Verizon’s 2025 DBIR analysis (May 2025). Pretexting is the social engineering layer that powers BEC.
  • The FBI’s 2025 IC3 report logged a 37% rise in AI-assisted BEC, including hundreds of deepfake-based scams involving cloned executive voices, per Deepstrike’s AI Cyber Attack Statistics 2025 (October 2025).
  • 74% of BEC attacks in Q3 2025 were launched from free webmail accounts, with Gmail used in 66% of those accounts, per the APWG Q3 2025 Phishing Activity Trends Report (December 2025).

Phishing Attack Types: Smishing, Vishing, and Spear Phishing Statistics

Phishing has expanded well beyond the email inbox. Attackers now operate across SMS, voice calls, and social platforms, exploiting the lower defenses of non-email channels.

Evolution of Phishing Channels 2023-2025

Phishing Awareness and Human Risk Statistics

Training and awareness programs produce measurable results – but the data reveals a persistent gap between knowing about phishing and resisting it in real situations.

  • 68% of employees admit to engaging in behaviors they know put their organization at risk, such as reusing passwords or ignoring security guidance, per Proofpoint’s 2024 State of the Phish Report cited by Tropico Security (December 2025).
  • The average reporting rate for users flagging simulated phishing messages across all organizations is 18.65%, with financial services highest at 32.35% and education lowest at 7.71%, per Proofpoint’s 2025 phishing simulation data (April 2025).
  • Annual phishing awareness training alone decreases click rates by only 1.7%, per a 2025 IEEE Security and Privacy study (Ho et al., 2025) – suggesting that one-time annual training has negligible impact without ongoing reinforcement.
Phishing Simulation Failure Rates by Industry 2024-2025

Phishing Defense and Security Technology Statistics

Technical controls including email authentication, AI-powered detection, and multi-factor authentication are producing results – but adoption gaps remain significant.

Defense Layer

Current Adoption Rate

Cost Impact (Per Incident)

Gap to Full Deployment

DMARC Enforcement

59% (Banking)

Significant reduction in spoofing risk

41% of banks still lack protection.

Phishing-Resistant MFA

14% (Global)

Prevents AiTM & session hijacking

86% still rely on legacy MFA (SMS/Push).

Zero-Trust Architecture

Varies by maturity

$1.76M savings per breach

38% higher costs for non-adopters.

Stay Secure with SSLInsights!

Subscribe to get the latest insights on SSL security, website protection tips, and exclusive updates.

✅ Expert SSL guides
✅ Security alerts & updates
✅ Exclusive offers