Scantitan Researches

Phishing Statistics 2026: Global Attacks, Losses, AI & Trends

PUBLISHED
September 16, 2026
Researcher
Obaida Al-Sulaiman
Reviewed by
Security Research Team
Phishing Statistics 2026
Table of Contents
Phishing statistics can look contradictory because the largest datasets are not measuring the same thing. APWG counts reported phishing sites and campaigns. Microsoft counts threats detected across email telemetry. The FBI counts complaints submitted by victims. Verizon measures incidents and confirmed breaches. Mandiant measures investigated intrusions, while security-awareness vendors measure simulated-phishing behavior.The latest evidence therefore does not support one universal number for “how many phishing attacks happen worldwide.” Instead, the strongest 2025–2026 data shows different parts of the threat moving in different directions, from reported phishing sites and email detections to Business Email Compromise, AI-assisted social engineering, smishing, vishing, credential theft, and mobile phishing.

How to read this researchAPWG phishing attacks, Microsoft email detections, FBI complaints, Verizon breaches, Mandiant investigations, and KnowBe4 simulations are different measurements. They should not be added together or treated as competing estimates of one worldwide phishing total.

Executive Benchmark: Phishing Statistics 2025–2026

The table below summarizes the strongest current phishing benchmarks from primary and first-party research. Figures are prioritized by recency and source quality, with the measurement period shown separately from the report publication year.

Metric Latest verified figure Trend Data timeframe Source
Reported phishing attacks/sites 1,069,681 ▲ 10.1% QoQ Apr–Jun 2026
APWG, Q2 2026 Phishing Activity Trends Report
Q1 2026 phishing attacks 971,181 Jan–Mar 2026
APWG
Highest month in Q2 425,808 attacks in June ▲ Highest monthly total since April 2023 June 2026
APWG
Email-based phishing detections ~8.3 billion n/a Jan–Mar 2026
Microsoft Threat Intelligence, Q1 2026 Email Threat Landscape
FBI phishing/spoofing complaints 191,561 ▼ 0.95% YoY Calendar 2025
FBI IC3, 2025 Annual Report
FBI BEC complaints 24,768 ▲ 15.5% YoY Calendar 2025
FBI IC3, 2025 Annual Report
FBI BEC losses $3.0466 billion Calendar 2025
FBI IC3, 2025 Annual Report
Average BEC loss per FBI complaint ~$123,005 Derived Calendar 2025
Calculated from FBI IC3 complaint and loss totals
Breaches involving phishing About 15% Nov 2023–Oct 2024
Verizon, 2025 Data Breach Investigations Report
Phishing as Mandiant initial infection vector 14% 2024 investigations
Google Cloud / Mandiant, M-Trends 2025
Stolen credentials as Mandiant initial infection vector 16% ▲ Second-most-common vector 2024 investigations
Google Cloud / Mandiant, M-Trends 2025
AI-related IC3 complaints 22,364 n/a Calendar 2025
FBI IC3, 2025 Annual Report
AI-related IC3 losses $893.35 million n/a Calendar 2025
FBI IC3, 2025 Annual Report
Baseline simulated-phishing susceptibility 33.2% → 33.1% in 2025 2026 benchmark
KnowBe4, 2026 Phishing by Industry Benchmarking Report
Simulated susceptibility after one year of training 4.2% ▼ 87% from baseline 12 months after training
KnowBe4, 2026 Phishing by Industry Benchmarking Report
Vishing +20% QoQ Q2 vs Q1 2026
APWG / Crane Authentication, Q2 2026
Smishing +40% QoQ Q2 vs Q1 2026
APWG / Crane Authentication, Q2 2026
Encrypted-channel phishing 95.2% 2026 report dataset
Zscaler ThreatLabz, 2026 Phishing and Initial Access Report
Mobile phishing susceptibility 40% higher click rate on mobile ▲ Mobile risk Nov 2024–Oct 2025
Verizon, 2026 Data Breach Investigations Report
Most impersonated brand Microsoft, 23% ▲ From 22% in Q1 Q2 2026
Check Point Research, Q2 2026 Brand Phishing Report

Trend key: ▲ increase  ·  ▼ decrease  ·  → broadly unchanged  ·  n/a = no directly comparable previous-period figure verified.

The important finding is not simply that phishing is “going up.” APWG recorded a 10.1% quarter-over-quarter increase in reported phishing attacks in Q2 2026, while Zscaler reported an approximately 20% year-over-year decline in phishing volume within its own telemetry. Cofense, meanwhile, observed malicious emails arriving more frequently in its environment, averaging one every 19 seconds during 2025 compared with one every 42 seconds in 2024. These results are not necessarily contradictory because the organizations measure different parts of the phishing ecosystem: reported phishing sites, cloud traffic, and malicious emails reaching monitored inboxes.

For the wider breach, ransomware, vulnerability, cost, AI, and attack-volume context, see ScanTitan’s Cybersecurity Statistics 2026 research.

Methodology: What Counts as a Phishing Statistic?

This report prioritizes primary 2025 and 2026 data from APWG, FBI IC3, Microsoft, Verizon, Google/Mandiant, IBM, KnowBe4, Cofense, Zscaler, Check Point, national cyber agencies, and official fraud-reporting bodies.

Older statistics are included only when they answer a question that newer primary data does not, and they are labeled with the actual period measured rather than the publication year.

Source type What it measures What it does not measure
APWG Reported phishing sites, campaigns, brands, BEC and related threat observations All phishing emails sent worldwide
Microsoft Phishing threats visible in Microsoft’s email-security telemetry A census of every email sent globally
FBI IC3 Complaints voluntarily reported to the FBI Every phishing victim or every attempted attack
Verizon DBIR Security incidents and confirmed breaches from participating datasets Global phishing email volume
Mandiant Initial access observed in Mandiant incident-response investigations All organizations or all attempted attacks
KnowBe4 Simulated-phishing behavior and vendor threat telemetry A universal real-world phishing success rate
Zscaler / Cofense / Check Point Threats visible inside each vendor’s customer and sensor ecosystem A universal global attack rate
National reporting agencies Complaints, reports, takedowns, surveyed incidents, or financial losses within a jurisdiction A directly comparable global dataset

Why methodology mattersAPWG’s 1.07 million Q2 attacks are not comparable with Microsoft’s 8.3 billion Q1 phishing detections. APWG is primarily counting unique reported phishing sites, while Microsoft is counting email-based threat detections across a massive telemetry environment.

Phishing Statistics Worldwide: How Large Is the Problem?

There is no authoritative worldwide counter of every phishing message, site, text, call, and social-media lure. The best global view comes from combining several measurements without pretending that they represent the same denominator.

APWG Recorded 1.07 Million Phishing Attacks in Q2 2026

The Anti-Phishing Working Group recorded 1,069,681 phishing attacks in Q2 2026, a 10.1% increase from Q1.

Period APWG phishing attacks Change
Q1 2025 1,003,924
Q2 2025 1,130,393 +13% QoQ
Q1 2026 971,181 About 3.3% below Q1 2025
Q2 2026 1,069,681 +10.1% QoQ; about 5.4% below Q2 2025

June was the sharpest month of the latest quarter. APWG recorded 425,808 attacks in June 2026, compared with 317,940 in May and 325,934 in April. June was APWG’s highest monthly total since April 2023.

APWG reported phishing attacks in April, May and June 2026, totaling 1,069,681 attacks in Q2

APWG also observed 83,951 unique phishing email campaigns in Q2 2026, compared with 35,583 in Q1. The number of brands observed increased from 467 in April to 512 in May and 552 in June, with 941 unique brands seen across the quarter.

APWG defines its main attack count around unique phishing sites derived from reported phishing URLs. A single phishing site can be promoted through many emails and URLs, so these values should not be described as email counts.

Microsoft Detected About 8.3 Billion Email-Based Phishing Threats in Q1 2026

Microsoft Threat Intelligence detected approximately 8.3 billion email-based phishing threats between January and March 2026.

Monthly volume declined slightly during the quarter, from approximately 2.9 billion in January to 2.6 billion in March. Microsoft also found that 78% of email threats were link-based, while QR-code phishing became the fastest-growing attack vector during the quarter and more than doubled.

This number is much larger than APWG’s because Microsoft is measuring email detections, not unique phishing websites.

Cofense Saw One Malicious Email Every 19 Seconds in 2025

Cofense’s Phishing Defense Center reported an average of one malicious email every 19 seconds throughout 2025. In 2024, its reported rate had been one every 42 seconds.

This is a useful operational trend inside the Cofense ecosystem, but it should not be converted into an estimate of all malicious email worldwide.

Not Every Dataset Shows Phishing Volume Increasing

Zscaler ThreatLabz reported that phishing activity in its telemetry declined by roughly 20% year over year, even as campaigns became more targeted and sophisticated.

The apparent disagreement with APWG and Cofense is useful rather than problematic. It indicates why “phishing increased X% globally” is usually too broad a claim. Different sensors see different parts of the ecosystem.

Phishing Statistics 2025: What Changed Going Into 2026?

The 2025 data provides the baseline needed to understand 2026. The clearest pattern is not uniform growth in every phishing metric, but a shift toward identity theft, BEC, multi-channel social engineering, legitimate-platform abuse, and AI-assisted personalization.

2025 indicator Figure What it means
FBI phishing/spoofing complaints 191,561 Victim complaints submitted to IC3
BEC complaints 24,768 15.5% above 2024
BEC losses $3.0466B Reported FBI losses
KnowBe4 phishing email change +17.3% Vendor telemetry over the measured six-month comparison period
Phishing bypassing Microsoft / SEG defenses +47% KnowBe4 telemetry
AI observed in phishing emails 82.6% KnowBe4’s March 2025 threat-research dataset
Cofense malicious-email frequency One every 19 seconds Observed in Cofense’s 2025 environment
Mandiant email phishing initial vector 14% 2024 investigations published in M-Trends 2025
Mandiant stolen credentials 16% Exceeded email phishing in the same incident-response sample

The distinction between phishing and stolen credentials is increasingly important. Credential-phishing campaigns can create credentials that attackers use later, so an incident may ultimately be categorized as stolen-credential access even though phishing occurred earlier in the criminal supply chain.

FBI Phishing Statistics: Complaints and Financial Losses

The FBI Internet Crime Complaint Center is the strongest public source for U.S. complaint and reported-loss data, but its numbers represent incidents voluntarily reported to IC3 rather than every cybercrime event in the country.

In 2025, IC3 received 1,008,597 total complaints across all cybercrime categories and recorded $20.877 billion in reported losses. Total losses increased 26% from 2024.

Do not call $20.877 billion “phishing losses”The figure covers all IC3 cybercrime complaint categories. Phishing/spoofing was one of the most frequently reported categories, but the total loss figure includes investment fraud, tech-support scams, BEC, romance fraud, government impersonation, and other crimes.

191,561 Phishing and Spoofing Complaints Were Reported in 2025

The FBI recorded 191,561 phishing/spoofing complaints in 2025, compared with 193,407 in 2024, a decrease of approximately 0.95%.

IC3’s phishing/spoofing category is broader than email. It includes unsolicited email, text messages, and telephone communications that impersonate legitimate organizations in an attempt to obtain personal, financial, or login information.

BEC Losses Exceeded $3 Billion in 2025

BEC metric Figure
2023 complaints 21,489
2024 complaints 21,442
2025 complaints 24,768
2025 YoY complaint growth 15.5%
2025 reported losses $3,046,598,558
Average reported loss per complaint Approximately $123,005

FBI Business Email Compromise complaints increased from 21,489 in 2023 to 24,768 in 2025

The approximately $123,005 figure is calculated by dividing total FBI-reported BEC losses by the number of complaints. It should not be described as an average fraudulent wire request because complaints can involve different BEC methods and outcomes.

APWG’s newer Q2 2026 telemetry indicates that BEC pressure continued to grow. Wire-transfer BEC attacks increased 88% quarter over quarter, while the average amount attackers attempted to steal rose 45% to $61,732.

For ransomware incidents where malicious email and phishing appear as root causes, see ScanTitan’s Ransomware Statistics 2026 research.

What Percentage of Data Breaches Involve Phishing?

There is no single current percentage that applies to every breach dataset.

Phishing is the entry route; an unpatched web application is often what the attacker reaches next. ScanTitan’s website scanner covers that second half.

Verizon’s public 2025 DBIR material placed phishing at approximately 15% of breaches. The report analyzed more than 22,000 incidents and more than 12,000 confirmed breaches with an observation period from November 2023 through October 2024.

By the 2026 DBIR, Verizon reported a major shift in initial access: software vulnerability exploitation reached 31% of breaches and became the leading entry method in its latest dataset.

Mandiant’s incident-response population shows a similar reason not to describe phishing as universally dominant. In M-Trends 2025, the initial infection vectors were:

Initial infection vector Share of Mandiant investigations
Exploitation 33%
Stolen credentials 16%
Email phishing 14%

These figures are why modern phishing statistics should treat phishing as a major initial-access and credential-acquisition mechanism without automatically calling it the leading cause of every cyberattack.

AI Phishing Statistics 2026

Artificial intelligence is one of the most heavily exaggerated parts of phishing reporting, so vendor-specific observations need particularly careful attribution.

KnowBe4 Observed AI in 85.76% of Phishing Attacks in Its Latest Dataset

KnowBe4’s 2026 Phishing Threat Trends Report Volume Seven says 85.76% of attacks in its recent dataset were using artificial intelligence in some form. The report gives comparable figures of 84% in 2025 and 79.9% in 2024.

KnowBe4 also reported that 60.13% of phishing attempts contained a malicious hyperlink.

These are KnowBe4 telemetry statistics. They should be written as “KnowBe4 observed” rather than “85.76% of all phishing worldwide uses AI.”

An earlier March 2025 KnowBe4 dataset found AI characteristics in 82.6% of analyzed phishing emails, illustrating that percentages can vary even within the same vendor as methodology and reporting periods change.

FBI Recorded $893 Million in AI-Related Cybercrime Losses

The FBI’s 2025 data provides a different type of AI evidence: victim complaints rather than email telemetry.

FBI AI-related measure 2025 figure
AI-related complaints 22,364
AI-related reported losses $893.35 million
AI-related phishing/spoofing complaints 803
AI-related BEC complaints 135
AI-assisted BEC losses More than $30 million

The broader IBM 2026 Cost of a Data Breach study found AI-driven attacks increased 56% year over year. IBM’s result is not phishing-specific, however, and should be treated as evidence of wider AI-enabled attack growth rather than converted into a phishing growth rate.

Smishing, Vishing and QR Phishing Statistics

Phishing increasingly extends beyond the email inbox.

Attack type Latest verified signal Source
Smishing +40% from Q1 to Q2 2026 APWG
Vishing +20% from Q1 to Q2 2026 APWG
Vishing during 2025 KnowBe4 separately reported a 449% surge KnowBe4 telemetry; different methodology
QR-code phishing More than doubled during Q1 2026 in Microsoft’s environment Microsoft Threat Intelligence
Mobile interaction 40% higher click rates Verizon 2026 DBIR

The APWG and KnowBe4 vishing percentages should not be treated as competing estimates because they cover different periods and telemetry. The defensible conclusion is that independent sources both observed substantial growth in voice-based phishing.

There is not yet a robust primary-source percentage showing what share of all global phishing is QR phishing. Claims such as “X% of phishing is quishing” should therefore be treated cautiously unless the denominator and telemetry source are stated.

Which Industries Are Targeted Most by Phishing?

APWG’s Q2 2026 site telemetry placed SaaS and webmail far ahead of other categories.

Industry Share of Q2 2026 phishing-site activity
SaaS / webmail 29.1%
Payment 13.2%
Financial institutions 11.4%
Logistics / shipping 9.6%
Social media 8.5%
Cryptocurrency 7.2%
E-commerce / retail 5.2%
Telecommunications 4.2%
Other 11.6%

Industries targeted by phishing in Q2 2026, led by SaaS and webmail at 29.1 percent

The figures can move rapidly. SaaS/webmail increased from about 20% in Q1 to 29.1% in Q2, while telecom fell sharply from its Q1 share. This is why an industry-targeting statistic without a quarter or year attached to it quickly becomes misleading.

Brand Phishing Statistics: Microsoft Remains the Top Impersonated Brand

Check Point Research found that Microsoft accounted for 23% of observed brand-phishing attempts in Q2 2026, up from 22% in Q1.

LinkedIn, Google, Apple, and Amazon completed the top five. Together, those five brands accounted for more than half of Check Point’s tracked brand-phishing attempts during the quarter.

ChatGPT also entered Check Point’s top ten for the first time in Q2 2026, showing how attackers adapt impersonation lures around widely recognized technologies and services.

What brand statistics measureA 23% Microsoft share means Microsoft represented 23% of brand-phishing attempts in Check Point’s dataset. It does not mean 23% of every phishing attack worldwide impersonates Microsoft.

Employee Phishing Statistics and Training Effectiveness

Simulation data is useful for measuring human susceptibility, but it should never be presented as the success rate of criminal phishing campaigns.

KnowBe4’s 2026 benchmarking research analyzed approximately 42 million phishing simulations across 14.8 million users at 64,000 organizations.

Training stage Global Phish-prone Percentage
Before training 33.2%
After approximately 90 days 20.1%
After one year 4.2%

KnowBe4 simulated phishing susceptibility declined from 33.2 percent before training to 4.2 percent after one year

A 33.2% baseline does not mean 33.2% of real phishing attacks succeed. It measures behavior in KnowBe4’s simulated-phishing program before training.

Healthcare Had the Highest Baseline Susceptibility

Industry 2026 baseline PPP
Healthcare & Pharmaceuticals 42.7%
Insurance 38.1%
Retail & Wholesale 36.0%

The same three industries were the highest-risk categories in KnowBe4’s benchmarking for a second consecutive year.

Larger Organizations Showed Higher Baseline Simulation Risk

Organizations with fewer than 250 employees recorded a baseline Phish-prone Percentage of 24.7%, while organizations with more than 10,000 employees began at 39.5%.

Large healthcare organizations reached a baseline of 54% in KnowBe4’s dataset.

Again, these are simulation benchmarks—not the percentage of real cyberattacks that successfully compromise companies of each size, Phishing susceptibility is only one part of healthcare cyber risk. Our healthcare breach statistics research compares phishing with vulnerability exploitation, credential abuse, ransomware, unauthorized disclosure, and HHS OCR breach-reporting data without treating those measurements as interchangeable.

For wider SMB breach and threat data, see ScanTitan’s Small Business Cybersecurity Statistics.

Mobile Phishing Statistics

Mobile devices are becoming a more important social-engineering surface.

Verizon’s 2026 DBIR reports 40% higher click rates on mobile devices. APWG separately recorded a 40% quarter-over-quarter increase in smishing in Q2 2026.

Together, the datasets provide evidence from two different directions: attackers are increasing activity through mobile messaging channels, while users interacting through mobile devices show higher engagement with phishing lures in Verizon’s data.

Phishing Statistics by Country

Country-level statistics are particularly difficult to compare because national agencies use different reporting systems. Some count scam reports, some count cyber incidents, some count victim complaints, and others publish financial-loss data.

United States

FBI IC3 reporting for 2025 recorded:

  • 1,008,597 complaints across all IC3 cybercrime categories.
  • $20.877 billion in total reported losses.
  • 191,561 phishing/spoofing complaints.
  • 24,768 BEC complaints.
  • $3.0466 billion in BEC losses.
  • 22,364 AI-related complaints.
  • $893.35 million in AI-related losses.

Phishing Statistics Canada

The Canadian Anti-Fraud Centre received more than 112,000 fraud reports involving more than C$704 million in reported losses across all fraud categories in 2025.

Within that dataset, traditional phishing generated:

  • 2,869 phishing reports.
  • 467 recorded victims.

The CAFC classifies this phishing category primarily as solicitation for personal information and does not attach direct financial losses to it.

Spear phishing is reported separately and produced a much larger financial impact:

  • 813 spear-phishing reports in 2025.
  • 571 victims.
  • C$67.9 million in reported losses.

By the first three months of 2026, Canadians had already reported nearly C$31 million in spear-phishing-related losses, according to the CAFC.

Phishing Statistics UK

The UK’s National Cyber Security Centre operates the Suspicious Email Reporting Service rather than publishing one national “phishing attack total.”

As of June 2026, the NCSC reported:

  • More than 56.9 million scam reports since the reporting service began.
  • 252,000 scams removed.
  • Removals across approximately 448,000 URLs.

The NCSC’s 2025 Annual Review also reported more than 10.9 million Suspicious Email Reporting Service submissions during the year.

Its Takedown Service disrupted more than 26,000 phishing campaigns targeting UK government departments. Of confirmed phishing attacks targeting those departments, 79% were resolved within 24 hours and 50% within one hour.

UK denominator warning56.9 million reports are not 56.9 million unique phishing attacks. Users can report repeated messages, and the NCSC reporting system covers scams more broadly.

Phishing Statistics Australia

Australia’s National Anti-Scam Centre reported A$2.18 billion in combined scam losses during 2025 across Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange, and ASIC.

Phishing was the fourth-largest scam type by reported loss, at A$97.6 million in 2025, compared with A$84.5 million in 2024.

The broader scam dataset recorded 481,523 reports in 2025, down 2.3% from 2024.

Email remained the most frequently reported contact method to Scamwatch, generating 84,861 reports. Only 4,329 of those reports involved reported financial loss, showing why message volume and financial harm should be tracked separately.

Text-message scam reports dropped sharply from 77,365 in 2024 to 29,058 in 2025, but reported losses through the channel increased from A$14.0 million to A$17.9 million.

Phishing Statistics Philippines

The Philippine Statistics Authority provides one of the clearest population-level measurements available for the country.

Among the 24.28 million Filipinos aged 10 and over who reported experiencing a cybersecurity incident in the relevant national survey:

  • 57.1% experienced SMS fraud.
  • 7.8% experienced hacking.
  • 6.1% experienced phishing.
  • 1.1% experienced cyberbullying or cyber libel.

BARMM recorded the highest phishing share among regions at 17.3%, followed by Region I at 14.5%.

Only 1.9% of people who experienced any cybersecurity incident reported the incident to authorities, which is an important limitation when comparing police or government complaint counts with survey-based exposure.

CISA Phishing Statistics: What Does CISA Actually Report?

Searches for “CISA phishing statistics” often imply that CISA maintains a national phishing-volume counter. In the current 2025–2026 CISA material reviewed for this report, CISA is more useful as a source of defensive guidance than as a source for a comparable U.S. phishing attack total.

CISA, NSA, FBI, and MS-ISAC guidance focuses on breaking the phishing attack cycle through:

  • Phishing-resistant multi-factor authentication.
  • Email-gateway and firewall filtering.
  • Blocking known malicious domains, URLs, IP addresses, and risky attachment types.
  • Security-awareness training.
  • Rapid reporting and incident response after successful phishing.

CISA also recommends moving toward phishing-resistant authentication methods such as FIDO/WebAuthn where practical.

Best source for each U.S. questionUse FBI IC3 for U.S. complaint and financial-loss statistics, Verizon or Mandiant for breach and intrusion datasets, Microsoft or vendor telemetry for email volume, and CISA primarily for government defensive guidance and mitigations.

Why Major Phishing Statistics Disagree

The most important methodological lesson in phishing research is that apparently conflicting numbers can all be valid within their own datasets.

Source Finding Actual measurement
APWG 1.07M attacks in Q2 2026; +10.1% QoQ Reported phishing sites
Microsoft ~8.3B Q1 2026 Email-based phishing detections
Cofense One malicious email every 19 seconds Malicious email observed in Cofense’s ecosystem
Zscaler ~20% YoY decline Zscaler cloud phishing telemetry
FBI 191,561 complaints Victim reports submitted to IC3
Verizon About 15% of breaches in 2025 DBIR Confirmed breach population
Mandiant 14% email phishing Initial vector in investigated intrusions
KnowBe4 33.2% baseline PPP User behavior during simulated phishing

These numbers should not be averaged and should not be used to “correct” one another.

A defensible statement is:

APWG recorded 1.07 million reported phishing attacks in Q2 2026, up 10.1% quarter over quarter, while Zscaler observed phishing volume decline roughly 20% year over year in its own telemetry. The difference reflects separate populations and may also indicate movement from broad campaigns toward more targeted activity.

An indefensible statement would be:

Global phishing increased 10.1% in 2026.

Phishing Statistics You Should Stop Quoting Without Context

Are 3.4 Billion Phishing Emails Sent Every Day?

Do not present this as a current 2026 statistic.

The claim that 3.4 billion phishing emails are sent every day appears throughout phishing-statistics roundups, including current competitor pages. However, the number traces through older secondary estimates rather than a transparent 2025 or 2026 global phishing measurement.

For a current page, stronger replacements are:

  • Microsoft detected approximately 8.3 billion email-based phishing threats in Q1 2026.
  • APWG recorded 1,069,681 reported phishing attacks in Q2 2026.
  • Cofense observed an average of one malicious email every 19 seconds during 2025 in its telemetry.

Is It True That 90% of Cyberattacks Start With Phishing?

No current major breach dataset reviewed here supports that as a universal claim.

Mandiant’s latest comparable data found exploitation at 33% of initial infection vectors, stolen credentials at 16%, and email phishing at 14%.

Verizon’s 2026 DBIR reports that software vulnerability exploitation reached 31% of breaches and became its leading breach-entry method.

Phishing remains an important initial-access and credential-acquisition vector, but “90% of cyberattacks start with phishing” should not be used as a current universal statistic.

What Percentage of Phishing Attacks Are Successful?

There is no credible universal phishing success percentage.

The denominator changes dramatically depending on whether researchers measure:

  • Email opens.
  • Link clicks.
  • Credential submissions.
  • Malware execution.
  • Account takeover.
  • Fraudulent payments.
  • Confirmed breaches.
  • Simulated-phishing failures.

KnowBe4’s 33.2% baseline Phish-prone Percentage is a useful simulation benchmark, but it is not evidence that 33.2% of criminal phishing attacks succeed.

Do Users Really Click Phishing Links in 21 Seconds?

The widely repeated 21-second click statistic is based on older behavioral research. It may still be useful as historical context, but it should not be labeled as a measured 2026 result.

For current mobile behavior, Verizon’s 2026 DBIR provides a better dated signal: phishing-related click rates were 40% higher on mobile devices.

What the 2026 Phishing Data Actually Shows

The evidence does not support a simple narrative that every form of phishing is increasing at the same rate.

Instead, the 2025–2026 data points to a change in the composition of the threat:

  • Reported phishing sites remain extremely high, with more than one million recorded by APWG in Q2 alone.
  • Email telemetry remains enormous, with Microsoft detecting approximately 8.3 billion Q1 threats.
  • BEC is becoming more financially significant, with FBI losses exceeding $3 billion in 2025 and APWG observing strong Q2 2026 wire-fraud growth.
  • Mobile channels are gaining importance, with smishing up 40% QoQ and higher mobile click rates in Verizon data.
  • AI is becoming embedded in attacker workflows, although exact percentages depend heavily on the vendor dataset.
  • Credential theft increasingly overlaps with phishing, with stolen credentials now outranking email phishing in Mandiant’s initial-access data.
  • Brand impersonation remains concentrated around major technology identities, especially Microsoft.
  • Security-awareness training substantially changes simulation results, with KnowBe4’s baseline PPP falling from 33.2% to 4.2% after a year in its benchmark population.

The practical implication is that phishing is increasingly an identity and account-takeover problem, not merely an unwanted-email problem. Email filtering matters, but so do phishing-resistant MFA, session security, credential monitoring, payment verification, mobile security, user reporting, and the ability to detect compromised accounts after a lure succeeds.

Primary Sources Used in This Research

Frequently Asked Questions

What are the latest statistics on phishing attacks?

APWG recorded 1,069,681 reported phishing attacks in Q2 2026, up 10.1% from Q1, while Microsoft detected approximately 8.3 billion email-based phishing threats in Q1 2026. The figures are not directly comparable because APWG primarily counts reported phishing sites and Microsoft counts email detections.

How many phishing attacks happen worldwide?

There is no authoritative global total covering every phishing email, website, SMS message, phone call, social-media lure, and collaboration-platform attack. APWG, Microsoft, Zscaler, Cofense and other organizations measure different slices of the ecosystem, so their totals should remain separate.

Is it true that 90% of cyberattacks start with phishing?

No current major breach dataset reviewed for this research supports that as a universal statistic. Mandiant’s 2025 report found exploitation at 33% of initial infection vectors, stolen credentials at 16%, and email phishing at 14%. Verizon’s 2026 DBIR says vulnerability exploitation reached 31% of breaches and became its leading entry method.

What percentage of phishing attacks are successful?

There is no universal success rate because researchers measure different outcomes such as clicks, credential submissions, malware execution, account takeover and confirmed breaches. KnowBe4’s 33.2% baseline Phish-prone Percentage is a simulation benchmark and should not be presented as the success rate of criminal phishing.

Are 3.4 billion phishing emails sent every day?

The 3.4-billion-per-day claim is widely repeated but should not be presented as a verified 2026 global statistic. A better current metric is Microsoft’s approximately 8.3 billion email-based phishing detections during Q1 2026, with the important caveat that this represents Microsoft telemetry rather than every phishing email sent worldwide.

What are the latest FBI phishing statistics?

The FBI IC3 recorded 191,561 phishing/spoofing complaints in 2025. Business Email Compromise generated 24,768 complaints and approximately $3.047 billion in reported losses. Total IC3 losses across all cybercrime categories reached $20.877 billion and should not be described as phishing-only losses.

What are the latest CISA phishing statistics?

CISA is primarily a source of U.S. government defensive guidance rather than a comprehensive national phishing-volume dataset. For U.S. complaint and financial-loss numbers, FBI IC3 is the stronger statistical source. CISA guidance focuses on controls such as phishing-resistant MFA, email filtering, user training and incident response.

Is phishing increasing in 2026?

It depends on the measurement. APWG recorded a 10.1% quarter-over-quarter increase in reported phishing attacks in Q2 2026, while Zscaler reported an approximately 20% year-over-year decline in phishing volume within its own telemetry. Smishing, vishing, BEC wire attempts and several AI-enabled phishing indicators increased in current datasets.

How much money is lost to phishing?

There is no reliable single global loss figure covering every form of phishing. FBI IC3 reported $3.0466 billion in U.S. Business Email Compromise losses during 2025, while Canada’s CAFC reported C$67.9 million in spear-phishing losses and Australia’s combined national scam dataset reported A$97.6 million in phishing losses. These systems use different definitions and cannot be added into a global total.

Which brand is impersonated most in phishing attacks?

Microsoft was the most impersonated brand in Check Point Research’s Q2 2026 dataset, representing 23% of observed brand-phishing attempts. LinkedIn, Google, Apple and Amazon completed the top five, which collectively accounted for more than half of tracked attempts.

Is AI making phishing more common?

Multiple vendor datasets show increasing AI use, but there is no universal global percentage. KnowBe4’s 2026 research says 85.76% of attacks in its recent telemetry used AI in some form, up from 84% in 2025. FBI data separately recorded 22,364 AI-related cybercrime complaints and $893.35 million in reported losses during 2025.

Does security awareness training reduce phishing risk?

KnowBe4’s 2026 simulation benchmark recorded a global baseline Phish-prone Percentage of 33.2%, falling to 20.1% after approximately 90 days and 4.2% after one year of continuous training. These are simulated-phishing results rather than measured real-world breach rates.

Want vulnerability scanning that prioritizes for you?

ScanTitan continuously matches your site against the CVE/NVD database, then ranks findings by real-world exploitability — so you patch what matters first.

o

Information Security Manager · Dubai, UAE · 12+ years InfoSec experience

Obaida specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations. All ScanTitan content is reviewed against live scan findings before publication.

Share :

Facebook
LinkedIn

Continue reading