Phishing is the one attack every organization experiences, which is why the statistics about it are so often stretched. This page keeps to the measured numbers: the Anti-Phishing Working Group’s counts of attacks, the FBI’s complaint and loss data, Verizon’s and IBM’s breach analyses, Sophos’s ransomware root causes, KnowBe4’s simulation data from 14.5 million users, and the insurers who pay for business email compromise. Each figure is linked to its source. We update the page as each report is published.
How to cite: link to this page or to the primary source beside each figure. Survey figures carry their sample size.
1. How much phishing there is
- 3.8 million phishing attacks were observed in 2025, up from 3.76 million in 2024. The second quarter’s 1,130,393 was the largest quarterly total since 2023; the fourth quarter recorded 853,244. (APWG Phishing Activity Trends Report, Q4 2025)
- Between 269,558 and 295,691 unique phishing websites were reported each month of the fourth quarter of 2025. (APWG Q4 2025)
- The FBI received 191,561 phishing and spoofing complaints in 2025, the most reported crime type, with losses that rose from $70 million to $215.8 million in a year. (FBI IC3 2025 Internet Crime Report)
- Microsoft screens 5 billion emails a day for malware and phishing. (Microsoft Digital Defense Report 2025)
- SMS-based fraud detections have grown 30 to 40% quarter over quarter. (APWG Q4 2025)
2. Who gets impersonated
- SaaS and webmail providers were the most frequently targeted sector in the fourth quarter of 2025. Social media accounted for 20.3% of attacks, telecom providers 18.7% (up from 5.9% the previous quarter), financial institutions 9.3%, retail 8.7%, payment services 7.6%, cryptocurrency 3.6%. (APWG Q4 2025)
- On social media, the finance sector was the primary target 35.5% of the time, followed by retail at 17.7% and federal agencies at 15.7%. (APWG Q4 2025)
- 69% of business email compromise attacks were launched from free webmail domains, down from 74% the quarter before. (APWG Q4 2025)
3. How often phishing becomes a breach
- Phishing was the initial attack vector in 17% of data breaches, at an average cost of $5.9 million per breach. (IBM Cost of a Data Breach Report 2026, 602 organizations)
- 62% of breaches involved the human element. Social engineering delivered to mobile devices succeeded 40% more often than email phishing. (Verizon 2026 Data Breach Investigations Report)
- Among organizations hit by ransomware, malicious email was the root cause in 26% of cases and phishing in 24%: half of all ransomware incidents began in an inbox. Compromised credentials added another 23%. (Sophos State of Ransomware 2026, 2,158 organizations)
- 79% of ransomware attacks started with an identity-based approach, and 97% of victims whose credentials were compromised had MFA enabled somewhere in the organization, just not where it mattered. (Sophos 2026)
- Credential abuse was the initial access vector in 13% of breaches and appeared somewhere in 39% of them. (Verizon 2026 DBIR)
- 44.2% of vendor email compromise messages that were read were engaged with by the recipient. (Verizon 2026 DBIR)
What this means for testing: a phishing test measures the click rate and the credential-entry rate for your own staff, against your own brand, before an attacker does.
4. Click rates before and after training
- 33.1% of employees worldwide interact with a simulated phishing email before any security awareness training. In North America the baseline is 37.1%. (KnowBe4 2025 Phishing by Industry Benchmarking Report, 67.7 million simulations across 14.5 million users at 62,400 organizations)
- The highest baseline rates were in healthcare and pharmaceuticals (41.9%), insurance (39.2%) and retail and wholesale (36.5%). (KnowBe4 2025)
- Small organizations (1 to 250 employees) started at 24.6%; organizations with 10,000 or more employees started at 40.5%. (KnowBe4 2025)
- After 90 days of training the click rate fell 40%; after twelve months it fell 86%, to roughly one in twenty-five. (KnowBe4 2025)
5. Business email compromise: the expensive kind
- Business email compromise cost $3.046 billion in reported US losses in 2025, up from $2.77 billion, the largest loss category aimed at businesses. 86% of BEC losses were moved by wire transfer or ACH. AI-enabled BEC alone cost more than $30 million. (FBI IC3 2025)
- The average amount requested in a wire transfer BEC attack was $50,297 in the fourth quarter of 2025, up 4.5% from $48,115. Gift cards remained the most common BEC scam type by count. (APWG Q4 2025)
- BEC was the most common cyber insurance claim at 31% of claims, with frequency up 15% and an average loss of $27,000. Funds transfer fraud was 27% of claims at an average of $141,000, and 52% of those frauds started with a compromised mailbox. Together they were 58% of all incidents. (Coalition 2026 Cyber Claims Report)
- 44% of small and medium-sized enterprises that were attacked lost money to payment diversion fraud. (Hiscox Cyber Readiness Report 2025, 5,750 businesses)
- Account takeover appeared in the FBI’s report for the first time: 4,700 complaints and $359.7 million in losses. (FBI IC3 2025)
- Coalition recovered $21.8 million in stolen funds for policyholders in 2025, an average of $202,000 per recovery, which is the argument for reporting a wire fraud within hours. (Coalition 2026)
6. Identity is the target
- More than 97% of identity attacks are password attacks. Identity-based attacks rose 32% in the first half of 2025. (Microsoft Digital Defense Report 2025)
- Phishing-resistant multi-factor authentication blocks over 99% of identity-based attacks. (Microsoft 2025)
- 67% of organizations report credential theft and misappropriated secrets increasing against their cloud infrastructure. (Thales 2026 Data Threat Report, 3,120 respondents)
- The average eCrime breakout time, from a first foothold (often a phished credential) to lateral movement, fell to 29 minutes in 2025. (CrowdStrike 2026 Global Threat Report)
7. What the numbers say to do
- Assume the click. With a 33% baseline, some employees will click every campaign. The controls that matter are the ones that make a click harmless: phishing-resistant MFA, conditional access, and an application that does not trust a session cookie forever. A web application penetration test checks the last one.
- Measure, then train. The 86% reduction after a year is real, but it starts from a baseline you have to measure. Our phishing testing engagement runs the campaign against your own domain and reports the click, credential-entry and report rates by department, with no names attached.
- Put a second channel on every payment change. BEC and funds transfer fraud are 58% of insurance claims and the average wire request is $50,297. A phone call to a known number is the control.
- Cover the mobile channel. Social engineering on phones succeeds 40% more often than email. Smishing and vishing belong in the test scope; see our explainers on smishing and vishing.
Sources
- APWG, Phishing Activity Trends Report, Q4 2025
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- Verizon, 2026 Data Breach Investigations Report
- IBM, Cost of a Data Breach Report 2026
- Sophos, The State of Ransomware 2026
- KnowBe4, 2025 Phishing by Industry Benchmarking Report
- Coalition, 2026 Cyber Claims Report
- Hiscox, Cyber Readiness Report 2025
- Microsoft, Digital Defense Report 2025
- Thales, 2026 Data Threat Report
- CrowdStrike, 2026 Global Threat Report
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →